HTTP Security Header Security & Risk Analysis

wordpress.org/plugins/security-header

Add and manage essential HTTP security headers with ease. Protect your WordPress site from XSS, clickjacking, and other common vulnerabilities.

800 active installs v3.1 PHP 7.0+ WP 5.0+ Updated Dec 30, 2025
clickjackingcontent-security-policyhttp-security-headersecurity-headerswordpress-security
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is HTTP Security Header Safe to Use in 2026?

Generally Safe

Score 100/100

HTTP Security Header has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The security-header plugin v3.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events indicates a minimal attack surface, which is further reinforced by zero unprotected entry points. The code signals are also reassuring, with no dangerous functions identified, all SQL queries using prepared statements, and a very high percentage of output properly escaped. The presence of nonce and capability checks, although limited in number, demonstrates an awareness of security best practices. The plugin also has a clean vulnerability history, with no known CVEs, unpatched vulnerabilities, or past common vulnerability types. This suggests a well-maintained and secure codebase. While the absence of taint analysis flows could be due to the nature of the plugin's functionality or limitations of the analysis tool, the overall picture is one of robustness and low risk.

Key Concerns

  • Low attack surface, no dangerous functions
  • 100% SQL queries using prepared statements
  • 95% of outputs properly escaped
  • No known CVEs or unpatched vulnerabilities
  • Zero taint analysis flows
Vulnerabilities
None known

HTTP Security Header Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

HTTP Security Header Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
36 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped38 total outputs
Attack Surface

HTTP Security Header Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuinspiredmonks-security-admin-dashboard.php:16
actionadmin_initinspiredmonks-security-admin-dashboard.php:97
actionadmin_initinspiredmonks-security-admin-dashboard.php:149
actionplugins_loadedsecurity-header.php:16
actionadmin_enqueue_scriptssecurity-header.php:29
actionadmin_noticessecurity-header.php:30
actionsend_headerssecurity-header.php:33
actionplugins_loadedsecurity-header.php:36
Maintenance & Trust

HTTP Security Header Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 30, 2025
PHP min version7.0
Downloads4K

Community Trust

Rating100/100
Number of ratings3
Active installs800
Developer Profile

HTTP Security Header Developer Profile

MOHIT GOYAL

2 plugins · 800 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HTTP Security Header

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/security-header/assets/admin-dashboard-style.css
Version Parameters
security-header/assets/admin-dashboard-style.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about HTTP Security Header