
WP Secure HTTP Headers Security & Risk Analysis
wordpress.org/plugins/wp-secure-http-headersLicense: GPLv2 or later WordPress plugin to add secure headers to your website.
Is WP Secure HTTP Headers Safe to Use in 2026?
Generally Safe
Score 85/100WP Secure HTTP Headers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-secure-http-headers" v1.1 plugin exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The plugin has no identified attack surface points like AJAX handlers, REST API routes, shortcodes, or cron events, which are common entry points for attackers. Furthermore, the code analysis reveals no dangerous functions used, all SQL queries are properly prepared, and output is consistently escaped. The absence of file operations, external HTTP requests, and crucially, any missing nonce or capability checks, indicates a highly defensive coding approach. The taint analysis confirms this by showing zero flows with unsanitized paths. The plugin's vulnerability history is equally spotless, with no recorded CVEs of any severity, suggesting a history of secure development and maintenance. The lack of any vulnerability patterns further reinforces its secure reputation. While the absence of many typical security checks like nonces and capability checks is notable, in this context, it appears to be a reflection of the plugin's design to have no user-facing or administrative functionalities that would typically require such protections. This plugin's current state suggests it is highly secure and poses minimal risk.
WP Secure HTTP Headers Security Vulnerabilities
WP Secure HTTP Headers Code Analysis
WP Secure HTTP Headers Attack Surface
WordPress Hooks 1
Maintenance & Trust
WP Secure HTTP Headers Maintenance & Trust
Maintenance Signals
Community Trust
WP Secure HTTP Headers Alternatives
HTTP Headers
http-headers
HTTP Headers adds CORS & security HTTP headers to your website.
Eazy HTTP Headers
eazy-http-headers
Provides settings to activate three HTTP header settings for X-Frame-Options, X-XSS Protection & X-Content-Type-Options.
SeaSP Community Edition
sea-sp-community-edition
SeaSP Community Edition is an automated Content Security Policy Manager. SeaSP allows you to create, configure, manage, and deploy a Content Security …
Strict Security Headers
strict-security-headers
Easily enable modern security headers for your website with the Strict Security Headers plugin, with no configuration required.
WP Remove Authors Sitemap from Yoast SEO
wp-remove-authors-sitemap-from-yoast-seo
License: GPLv2 or later WordPress plugin to remove authors from the Yoast SEO Sitemap
WP Secure HTTP Headers Developer Profile
18 plugins · 1K total installs
How We Detect WP Secure HTTP Headers
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
wp-secure-http-headers/style.css?ver=wp-secure-http-headers/script.js?ver=