
HTTP Headers Security & Risk Analysis
wordpress.org/plugins/http-headersHTTP Headers adds CORS & security HTTP headers to your website.
Is HTTP Headers Safe to Use in 2026?
Generally Safe
Score 91/100HTTP Headers has a strong security track record. Known vulnerabilities have been patched promptly.
The 'http-headers' plugin exhibits a mixed security posture. While it demonstrates good practices by having no unprotected entry points, all SQL queries use prepared statements, and a significant number of nonce and capability checks are implemented, there are significant concerns regarding output escaping and historical vulnerability patterns. The static analysis reveals that only 18% of outputs are properly escaped, leaving a substantial portion vulnerable to cross-site scripting (XSS) attacks. Furthermore, two out of three analyzed taint flows involve unsanitized paths, indicating potential vulnerabilities that could be exploited if they lead to sensitive operations. The plugin's history of four medium-severity vulnerabilities, including SSRF, XSS, Code Injection, and SQL Injection, is a major red flag. Although none are currently unpatched, the recurring nature of these severe vulnerability types suggests underlying architectural weaknesses or persistent coding errors that could resurface or manifest in new forms. The plugin's strengths lie in its controlled attack surface and secure database interactions, but the weak output sanitization and historical vulnerability profile necessitate caution.
Key Concerns
- Low percentage of properly escaped output
- Taint flows with unsanitized paths detected
- History of medium severity vulnerabilities (4 total)
- Common vulnerability types include XSS, Code Injection, SQLi, SSRF
HTTP Headers Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
HTTP Headers <= 1.18.11 - Server-Side Request Forgery
HTTP Headers <= 1.18.11 - Authenticated (Administrator+) Stored Cross-Site Scripting
HTTP Headers <= 1.18.10 - Authenticated(Administrator+) Remote Code Execution
HTTP Headers <= 1.18.8 - Authenticated(Administrator+) SQL Injection
HTTP Headers Code Analysis
Output Escaping
Data Flow Analysis
HTTP Headers Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
HTTP Headers Maintenance & Trust
Maintenance Signals
Community Trust
HTTP Headers Alternatives
Strict Security Headers
strict-security-headers
Easily enable modern security headers for your website with the Strict Security Headers plugin, with no configuration required.
Content Security Policy Manager
csp-manager
Plugin for configuring Content Security Policy headers for your site. Allows different CSP headers for admin, logged inn frontend and regular visitors
GNU Terry Pratchett
gnu-terry-pratchett
Add an X-Clacks-Overhead header with “GNU Terry Pratchett” to all non-admin pages.
HTTP Security Header
security-header
Add and manage essential HTTP security headers with ease. Protect your WordPress site from XSS, clickjacking, and other common vulnerabilities.
Security Headers
firstpage-sg-security-headers
Security headers are directives used by web applications to configure security defenses.
HTTP Headers Developer Profile
1 plugin · 50K total installs
How We Detect HTTP Headers
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/http-headers/css/admin.css/wp-content/plugins/http-headers/css/front.css/wp-content/plugins/http-headers/js/admin.js/wp-content/plugins/http-headers/js/front.js/wp-content/plugins/http-headers/js/admin.js/wp-content/plugins/http-headers/js/front.jshttp-headers/css/admin.css?ver=http-headers/css/front.css?ver=http-headers/js/admin.js?ver=http-headers/js/front.js?ver=HTML / DOM Fingerprints
http-headers-menu<!-- http_headers_start --><!-- http_headers_end -->data-hh-noncehttpHeaders/wp-json/http-headers/v1/settings