Plugin Pulse
← Pulse

GD Security Headers

by Milan Petrovic · Security

Also makes 13 other plugins · 10.9K+ installs across the portfolio →

Configure various security-related HTTP headers, including CSP, XSS, Referrer Policy and more.

⚠ Few reviews
How scoring works →
82 Health · B
Maintenance 97/100
Rating quality 73/100
Support 70/100

82 health vs 64 average across 997 Security plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

90 / 100

Excellent listing optimization

Biggest win: Rating quality

Update recency 100/100
WP compatibility 100/100
Rating quality 59/100
Listing tuning 100/100

To rank higher: Too few reviews to rank on quality — nudge happy users to leave one.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive

+43% vs prior 30d
35Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

923

now · peak 2.1K

89930d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

GD Security Headers · #5871 you Content Security Pol · #4830 Security Header Gene · #9033 Auto SRI · #8767

Rating trend

Star average over time · dips mark rough releases

4Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

899per 1k installs · Aug 26

Release cadence

Occasionally updated
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

1

releases in the last 12 months

4mo ago

latest release · v1.9

13

tagged releases on record

Recent releases

1.9 · 4mo ago1.8 · 2.2y ago1.7.1 · 2.8y ago1.7 · 3.0y ago1.6.1 · 4.3y ago1.6 · 4.6y ago1.5 · 5.4y ago1.4 · 5.9y ago1.3 · 6.3y ago1.2 · 6.7y ago1.1.1 · 7.0y ago1.1 · 7.3y ago1.0 · 7.4y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 62% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v1.9 62%
v1.8 29%
Older / other versions 9.1%

Estimated active installs

The public count shows “1K+”. Our estimate pins where the real number sits.

tracked estimate
1K–2K ≈1.6K

Refined from the date this plugin crossed into its current band.

Install history · since 2021-01-24 · 1,421 observations

1KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.

Details

Version
1.9
Last updated
4mo ago
Added
2019-03-28 · 7 yrs old
Requires WP
5.5
Tested up to
7.0.4
Requires PHP
7.4

Recent reviews

All reviews on wp.org ↗
  1. nichu42
    2.2y ago

    It’s the best plug-in for setting security headers that I found so far. Easy set-up, good explanations.But what really stands out is the local reporting feature! Thank you very much!

    Read on wp.org ↗
  2. tszesty
    3.5y ago

    Easy to install and relatively easy to configure.I only want to set CSP rules and it lets me do that easily, having the shortcuts for common rules such as Google Analytics etc is useful.The report-only features is clear and easy to use when starting to add rules and you need to gather a list of them.If had had one feature request it would be for the plugin to show an estimated header size.. I sometimes trip header size limits on a server when I need to add a lot of rules. If it coudl detect the server limit and warn if getting close – that’d be nice.All in all good plugin. Really dont know why some people only gave it 1 star, I can only assume they made mistakes configuring it.

    Read on wp.org ↗
  3. nadeistos
    4.3y ago

    A+ on headers scan, thank you for your work 🙂

    Read on wp.org ↗
  4. Anonymous User
    4.6y ago

    Thank you!

    Read on wp.org ↗
  5. mesmer7
    5.0y ago

    There are a lot mistakes in the generated Content-Security-Policy statement. It fails to insert the blob and data directives. It adds a semicolon and double quote at the end of the line that shouldn’t be there. The only thing this plugin is really good for is the report page.

    Read on wp.org ↗
  6. advertino
    5.2y ago

    The Content-Security-Policy directive ‘script-src’ contains ‘script-src’ as a source expression. Did you want to add it as a directive and forget a semicolon? The Content-Security-Policy directive name ‘widget.gleamjs.io’ contains one or more invalid characters. Only ASCII alphanumeric characters or dashes ‘-‘ are allowed in directive names. The Content-Security-Policy directive name ‘www.googletagservices.com’ contains one or more invalid characters. Only ASCII alphanumeric characters or dashes ‘-‘ are allowed in directive names. etc etc etc

    Read on wp.org ↗
  7. ozwest
    5.5y ago

    Thank you for creating this plugin, I have been looking for something like that. It comes with so many options that you can configure, so you really can address each need a website has.

    Read on wp.org ↗
  8. ranggie4
    6.9y ago

    For someone who is not a developer, GD Security Headers (GPSH) plugin is truly a gift to WP users. It turns “Rocket Science” into just “Science 101”; still needs a bit of knowledge of what you’re doing but this makes it so much easier to tweak security headers. Particularly, that option to only generate reports first for “Content-Security-Policy” before going live is how great plugins should be designed. Also love the fact that if enabled, the GPSH can write directly to the .htaccess file, and if a user prefers otherwise, they can also choose to disable that option to manually add by way of the ‘Generated Headers’ button. Now, I do have some feedbacks though but please bear in mind again I’m no developer. As such, the things I write might make some of the senior WP users chuckle but I’m just sharing what I think I understand. 1. GPSH writes to the .htaccess file that resides in the same folder where all WP files are kept, meaning if the WP installation is kept inside another folder i.e. /public_html/WP/, the /public_html/WP/.htaccess file will be written to instead of /public_html/.htaccess. Don’t know if it changes anything but just thought I should share that some folks do move their WP installation to another folder. 2. Even though ‘Add: X-XSS-Protection’ has been enabled, a check on Mozilla Observatory came back with the error: “X-XSS-Protection header cannot be recognized”. However, just want to add that it did come out ok when checked on Security Headers. 3. According to Security Headers, there also seems to be a new header called “Feature-Policy”. Is this something that’s already in GPSH? I can’t find it. Also, First! 🙂 This topic was modified 6 years, 9 months ago by ranggie4. This topic was modified 6 years, 9 months ago by Jan Dembowski. Reason: Deleted all links to other sites This topic was modified 6 years, 9 months ago by ranggie4. Reason: Removed links and replaced with text

    Read on wp.org ↗

Known vulnerabilities

via Wordfence Intelligence

3 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-07-08 CVE-2026-57403 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8 Patched in 1.9
  2. 2023-10-29 CVE-2023-46821 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.7 Patched in 1.7.1
  3. 2023-08-17 CVE-2023-40330 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.6.1 Patched in 1.7

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 21 languages, 0 at 90% or more · development strings

Croatian 7%
Danish 7%
Dutch 7%
Finnish 7%
French (France) 7%
German 7%
German (Austria) 7%
German (Switzerland) 7%
Hindi 7%
Italian 7%
Japanese 7%
Norwegian (Bokmål) 7%
Persian 7%
Polish 7%
Portuguese (Brazil) 7%
Portuguese (Portugal) 7%
Russian 7%
Serbian 7%
Spanish (Spain) 7%
Swedish 7%
Ukrainian 7%

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-01-23 2K+ → 1K+ down after 1000 days in tier
  2. 2023-04-29 1K+ → 2K+ up

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for GD Security Headers into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/gd-security-headers" width="480" height="300" style="border:0" loading="lazy" title="GD Security Headers — Plugin Pulse"></iframe>
Preview card ↗

GD Security Headers: 1K+ active installs, 4.0★ (8 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/gd-security-headers