Security Headers
by SimonRWaters · Uncategorized
Plug-in to ease the setting of TLS headers for HSTS and similar
48 health vs 56 average across 16,376 Uncategorized plugins
High removal-risk signals
63/100Maintenance and integrity signals that tend to precede a WordPress.org removal. Not an official status, a heads-up to act.
- Long abandoned. No update in 7+ years — the top precursor to removal once a vulnerability is found.
- Compatibility drift. Tested only up to WordPress 5.1.24, well behind 6.8.
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Under-optimized
Biggest win: Update recency
To rank higher: Last updated 2740 days ago — ship an update; wp.org decays a listing's search weight after ~180 days.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,424 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
369
now · peak 449
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
No release in a yearHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
0
releases in the last 12 months
11.4y ago
latest release · v0.3
1
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 97% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “3K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2017-02-13 · 1,432 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ krsi786.3y ago
Just a quick warning: if you enable this plugin, the Tawk.to widget is no longer displayed in Chrome, Firefox and Safari. Edge is not affected (yet?).
Read on wp.org ↗ - ★★★★★ flch7.5y ago
Works great and makes security much easier. Thanks for this great plugin!
Read on wp.org ↗ - ★★★★★ tone_milazzo8.2y ago
My topic can’t be empty so I’m writing this to fill it.
Read on wp.org ↗ - ★★★★★ bozon9.2y ago
Works really well! Tested with [link removed] For the future releases it would be good to include Content-Security-Policy and the forthcoming Expect-CT options. This topic was modified 9 years, 1 month ago by bdbrown. Reason: Links not permitted in reviews
Read on wp.org ↗ - ★★★★★ WebBever9.3y ago
Easy to use, works like a charm!
Read on wp.org ↗ - ★★★★★ tjdurden10.1y ago
Thanks for this. Very easy to install and configure.
Read on wp.org ↗ - ★★★★★ Turn On Social10.1y ago
Would be ideal if X-Frame-Options was also integrated
Read on wp.org ↗ - ★★★★★ capturefour11.0y ago
For all you peeps that are doing SEO and have https sites running, this is a must..
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 1.1 Fix missing close anchor which breaks recent WordPress 1.1
- — Version 1.0 Add support for wp-login.php page Add support for Expect-CT header 1.0
- — Version 0.9 Removed unnecessary whitespace in HSTS header (thanks Thomas) Added Referrer-Policy header Corrected plugins name from “HTTP Headers” to “Security Header” (thanks Jamie) Removed trailing semi-colon from X-XSS-Protection 0.9
- — Version 0.8 Add headers to admin section of WordPress Added option to set the X-Frame-Options headers to main site Added HSTS Preload header (thanks to Jamie) 0.8
- — Version 0.7 Add report-uri Fix handling of non-numeric blank strings for HPKP max-age 0.7
- — Version 0.6 HPKP support Check for TLS before emitting HSTS or HPKP headers 0.6
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 7.2.16 · WP 5.3
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-05-15 4K+ → 3K+ down after 430 days in tier
- 2025-03-11 5K+ → 4K+ down after 296 days in tier
- 2024-05-19 6K+ → 5K+ down after 393 days in tier
- 2023-04-22 7K+ → 6K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
HSTS Ready 3K+ installs · 4.2★ · 2 shared tags A -
LH HSTS 600+ installs · 3.9★ · 2 shared tags D -
Simple HTTPS 400+ installs · 4.0★ · 2 shared tags C - H HTTPS Mixed Content Detector 60+ installs · 4.3★ · 2 shared tags D
-
HTTPS Domain Alias 40+ installs · 4.2★ · 2 shared tags D -
Hostinger Tools 3M+ installs · 3.6★ · 1 shared tag B
Embed this report card
Drop a live Pulse card for Security Headers into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/security-headers" width="480" height="300" style="border:0" loading="lazy" title="Security Headers — Plugin Pulse"></iframe> Security Headers: 3K+ active installs, 5.0★ (8 reviews). Plugin Pulse (WP Mayor), as of 2026-08-28. https://plugins.wpmayor.com/plugin/security-headers