Plugin Pulse
← Pulse

HTTP Headers

by Dimitar Ivanov · Security

HTTP Headers adds CORS & security HTTP headers to your website.

How scoring works →
85 Health · A
Maintenance 96/100
Rating quality 82/100
Support 70/100

85 health vs 64 average across 997 Security plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

82 / 100

Well optimized

Biggest win: Support resolution

Update recency 100/100
WP compatibility 100/100
Rating quality 84/100
Listing tuning 100/100
Support resolution 0/100

To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

-3% vs prior 30d
175Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

6.2K

now · peak 41.8K

6.2K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

HTTP Headers · #787 you Content Security Pol · #4827 HTTP Security Header · #5715 GNU Terry Pratchett · #6675

Rating trend

Star average over time · dips mark rough releases

4.3Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

123per 1k installs · Aug 26

Release cadence

Occasionally updated
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

3

releases in the last 12 months

4mo ago

latest release · v1.19.5

59

tagged releases on record

Recent releases

1.19.5 · 4mo ago1.19.4 · 4mo ago1.19.3 · 4mo ago1.19.2 · 1.7y ago1.19.1 · 2.0y ago1.19.0 · 3.1y ago1.18.11 · 3.2y ago1.18.10 · 3.2y ago1.18.9 · 3.3y ago1.18.8 · 3.4y ago1.18.7 · 3.6y ago1.18.6 · 3.6y ago1.18.4 · 5.3y ago1.18.3 · 5.3y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 92% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v1.19 92%
v1.18 7.4%
Older / other versions 0.8%

Estimated active installs

The public count shows “50K+”. Our estimate pins where the real number sits.

tracked estimate
50K–60K ≈59K

Refined from the date this plugin crossed into its current band.

Install history · since 2016-12-19 · 1,453 observations

50KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.

Details

Version
1.19.5
Last updated
4mo ago
Added
2016-05-10 · 10 yrs old
Requires WP
3.2
Tested up to
6.9.7
Requires PHP
5.3

Recent reviews

All reviews on wp.org ↗
  1. ysc711
    12mo ago

    Never use this plugin as the security settings make my main site and all sub-domain sites down and even after uninstallation / removal of everything and start to install a new WP, it doesn’t work anymore

    Read on wp.org ↗
  2. fairshareitservices
    1.3y ago

    worked exactly as promised except 2

    Read on wp.org ↗
  3. sunb1
    1.4y ago

    Went through a bunch of options of adding security headers to my sites and settled on this plugin. Would be 5 stars if two things get fixed/added. 1st is that it would be great to have a save button at the top also so you don’t have to scroll so much to the bottom to save options (especially on CSP screen). And the 2nd would be that the boxes where we are able to input sites etc, sometimes you have to paste numerous websites in that field and it is ridiculously annoying to try to scroll through, see whats already there or copy and paste outside in notepad for example and then paste it back in. Would be great if that field could be expanded or just bigger.

    Read on wp.org ↗
  4. RipRapRob
    1.9y ago

    When used with Elementor, you can’t edit the pages. Had to uninstall, since I don’t know what else it will break.

    Read on wp.org ↗
  5. swampscrapper
    2.3y ago

    I am finding this a very effective tool to help clients reach security compliance. There is one glitch I believe, however, is with the x-content-type-options. Once you enable this the only option is “nosniff”. And once enabled, there is no way to reset it. And unfortunately i believe this setting is creating errors on my site. I can’t even seem to find the line for it in my .htaccess file. Any recommendations?

    Read on wp.org ↗
  6. Jonathan Jewell
    2.3y ago

    I have felt this has been excellent since the first time I used it, and absolutely no issues with it for what it is, except that there are a couple of headers that either need to be ‘marked deprecated’ or just removed. My immediate spot of these are the, Features header, P3P header and the Expect-CT (which is still around, but Mozilla recommend not using). There may be others. There are a bunch of things that I might suggest as improvements, but this is to move the tool forward a bit. For instance: It would be great if it could display the highlighted state of the current Apache/Nginx code and the status of the security (as per securityheaders.com form) alongside/under it, so you could see the evolution of the security header set up arrangements as you add/remove them. Could be useful to have some in-built documentation on these things (particularly with the P3P header, those little summary items were impossible to figure out without going back and forth, but for other things like cache-control, or accept-expose-headers, some labelling could help). That said, for advanced users anyway, so perhaps less important. Further to that, it might be useful to have an indication of what OWASP, Scott Helme, and Mozilla recommend and/or warnings for ones that are problematic for security or high risk with labels on them. There are a few things that have odd formatting, so it is not obvious how to transpose the information for the reporting one over from how the header is laid out, since there are different ones for this. In this you have the report header that is normally used (as per report-uri site from Scott Helme) but it does not fit there. However, it has a group called ‘csp-element’ or something similar that might be clearer as to its use elsewhere). There is also the display of custom headers that are all grouped into one thing, and not spread out in a useful way if you want to review them. Odd grouping in a couple of places, so custom headers I might have given its own block for instance, and to have two items in one and even one in one grouping is a bit pointless. On another note, it is a shame that there is not a tool that is so effective that does this kind of thing for WordPress and just outputs the BIND9 detail for DNS resource records. A combination of this and that, with the ability to adjust PHP and Apache settings would be the most amazing tool ever. For what this does, however, is sets the foundations for a great security setup.

    Read on wp.org ↗
  7. robertorefresh
    2.4y ago

    Simply and useful

    Read on wp.org ↗
  8. j0s6h
    2.4y ago

    Great tool. Novices, beware, the myriad of settings is a bit daunting at first so you need to dive into the subtleties of Header settings, specifically the ones that address security settings for your site. A good resource for the broad variety of settings for Content Security Policy as well as other important Header settings such as X-Frame-Options, X-Content-Type-Options, Strict-Transport-Security, Referrer-Policy and Permissions Policy can be found at cheatsheetseries owasp org. Take your time working out which settings work best for your site. Getting a good rating at securityheaders com will reward you for your efforts. While the tool respects your initial .htaccess content it’s a good idea to backup your .htaccess before saving and applying the plugins settings.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 1.19.5 Release Date – 27th April, 2026 Fixed: Global updated_option Nonce Redirect Bug 1.19.5
  2. Version 1.19.4 Release Date – 25th April, 2026 Security vulnerabilities addressed Coding best practices applied 1.19.4
  3. Version 1.19.3 Release Date – 25th April, 2026 Security vulnerabilities addressed Coding best practices applied 1.19.3
  4. Version 1.19.2 Release Date – 22nd December, 2024 Added “script-src-elem” directive to “Content-Security-Policy” header Added “script-src-attr” directive to “Content-Security-Policy” header Added “style-src-elem” directive to “Content- 1.19.2
  5. Version 1.19.1 Release Date – 2nd September, 2023 Added “clientHints” directive to “Clear-Site-Data” header Added “credentialless” directive to “Cross-Origin-Embedder-Policy” header 1.19.1
  6. Version 1.19.0 Release Date – 7th July, 2023 Fixed: SSRF vulnerability by an Admin user Fixed: XSS vulnerability by an Admin user 1.19.0

Known vulnerabilities

via Wordfence Intelligence

7 disclosed vulnerabilities on record for this plugin, 2 still affect the current version.

  1. 2026-04-21 CVE-2026-4132 External Control of File Name or Path Affects <= 1.19.2 No patch available
  2. 2026-04-21 CVE-2026-2717 Improper Neutralization of CRLF Sequences ('CRLF Injection') Affects <= 1.19.2 No patch available
  3. 2026-04-21 CVE-2026-1379 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.19.4 Patched in 1.19.5
  4. 2023-07-13 CVE-2023-37978 Server-Side Request Forgery (SSRF) Affects <= 1.18.11 Patched in 1.19.0
  5. 2023-07-10 CVE-2023-37874 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.18.11 Patched in 1.19.0
  6. 2023-06-19 CVE-2023-1208 Improper Control of Generation of Code ('Code Injection') Affects <= 1.18.10 Patched in 1.18.11
  7. 2023-04-24 CVE-2023-1207 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.18.8 Patched in 1.18.9

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 11 languages, 4 at 90% or more

Spanish (Chile) 100%
Spanish (Spain) 100%
Spanish (Mexico) 99%
Russian 96%
French (France) 88%
Italian 39%
Dutch 33%
German (Formal) 29%
Ukrainian 24%
Dutch (Belgium) 10%
German 8%

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2025-01-09 40K+ → 50K+ up after 1 days in tier
  2. 2025-01-08 50K+ → 40K+ down after 2 days in tier
  3. 2025-01-06 40K+ → 50K+ up after 1 days in tier
  4. 2025-01-05 50K+ → 40K+ down after 1 days in tier
  5. 2025-01-04 40K+ → 50K+ up after 1 days in tier
  6. 2025-01-03 50K+ → 40K+ down after 5 days in tier
  7. 2024-12-29 40K+ → 50K+ up after 3 days in tier
  8. 2024-12-26 50K+ → 40K+ down after 2 days in tier

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for HTTP Headers into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/http-headers" width="480" height="300" style="border:0" loading="lazy" title="HTTP Headers — Plugin Pulse"></iframe>
Preview card ↗

HTTP Headers: 50K+ active installs, 4.3★ (70 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/http-headers