Strict Security Headers Security & Risk Analysis

wordpress.org/plugins/strict-security-headers

Easily enable modern security headers for your website with the Strict Security Headers plugin, with no configuration required.

10 active installs v0.1.0 PHP + WP 5.5+ Updated Unknown
headershttp-headerssecuritysecurity-headers
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Strict Security Headers Safe to Use in 2026?

Generally Safe

Score 100/100

Strict Security Headers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'strict-security-headers' v0.1.0 plugin exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any detected entry points, dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or taint flows indicates meticulous development practices. The plugin appears to be designed with security as a primary concern, and the lack of any known vulnerabilities further reinforces this positive assessment. Its vulnerability history is clean, with no recorded CVEs, suggesting a stable and secure codebase. The plugin's strengths lie in its minimal attack surface and its apparent adherence to secure coding principles, with no identified weaknesses in the analyzed areas. The only area of potential concern, albeit minor given the other strong signals, is the complete absence of capability checks and nonce checks, which could be a point of hardening if the plugin were to evolve to handle more sensitive operations or user interactions.

Vulnerabilities
None known

Strict Security Headers Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Strict Security Headers Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Strict Security Headers Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Strict Security Headers Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedUnknown
PHP min version
Downloads753

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Strict Security Headers Developer Profile

Justin Kopepasah

7 plugins · 90 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Strict Security Headers

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/strict-security-headers/build/csp.js/wp-content/plugins/strict-security-headers/build/csp.css/wp-content/plugins/strict-security-headers/build/sts.js/wp-content/plugins/strict-security-headers/build/sts.css/wp-content/plugins/strict-security-headers/build/permissions.js/wp-content/plugins/strict-security-headers/build/permissions.css/wp-content/plugins/strict-security-headers/build/referrer.js/wp-content/plugins/strict-security-headers/build/referrer.css+4 more
Script Paths
/wp-content/plugins/strict-security-headers/build/csp.js/wp-content/plugins/strict-security-headers/build/sts.js/wp-content/plugins/strict-security-headers/build/permissions.js/wp-content/plugins/strict-security-headers/build/referrer.js/wp-content/plugins/strict-security-headers/build/xcontenttypeoptions.js/wp-content/plugins/strict-security-headers/build/xframeoptions.js
Version Parameters
strict-security-headers/build/csp.js?ver=strict-security-headers/build/csp.css?ver=strict-security-headers/build/sts.js?ver=strict-security-headers/build/sts.css?ver=strict-security-headers/build/permissions.js?ver=strict-security-headers/build/permissions.css?ver=strict-security-headers/build/referrer.js?ver=strict-security-headers/build/referrer.css?ver=strict-security-headers/build/xcontenttypeoptions.js?ver=strict-security-headers/build/xcontenttypeoptions.css?ver=strict-security-headers/build/xframeoptions.js?ver=strict-security-headers/build/xframeoptions.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Strict Security Headers