Store launch: promo code LAUNCH20 - 20% off everything until the end of September

Headers Shield

Security headers in one click - with three hardened presets.

WordPress 6.0+PHP 7.4+License: 1 site, 1 year
Download free free forever, no feature timers
1 500 ₽ / $19
Buy Pro

Instant delivery: license key + download right after payment.

Version 1.0.0 · updates delivered automatically

About

Browsers expect security headers - and Lighthouse audits penalise their absence. Headers Shield adds them in one click: pick a preset and see the active configuration right on the settings screen.

Six headers are available individually: X-Frame-Options (SAMEORIGIN/DENY), X-Content-Type-Options: nosniff, Referrer-Policy (seven values), X-XSS-Protection, Permissions-Policy (custom directives) and X-Permitted-Cross-Domain-Policies. Nothing is sent until you enable it.

Pro adds HSTS (max-age, includeSubDomains, preload), a Content-Security-Policy builder with Report-Only/Enforce modes and a built-in violation report collector.

What it does

  • Six security headers, individually switchable
  • Three presets: Minimal, Standard, Strict
  • Live view of the active configuration
  • Pro: HSTS + CSP builder + violation reports

Free vs Pro

FreePro
Security headers66
Presets33
HSTS-Yes
CSP builder + violation log-Yes

FAQ

Will it break my site?

Presets start permissive; headers apply only after you enable them, and the active set is always visible.

Does it work with caching plugins?

Yes - headers are sent on every response, independent of page cache.

Do I need a Pro license to start?

No. The free edition covers the six core headers; Pro adds HSTS and CSP tooling.

Installation & uninstall

Free version

  1. Download the zip archive with the "Download free" button above.
  2. In your WordPress admin: Plugins → Add New → Upload Plugin.
  3. Pick the downloaded zip, click "Install Now", then "Activate".
  4. The plugin's menu appears in wp-admin — configure it to your liking.

Pro version

  1. After payment, download the Pro archive from your order page (the link is also emailed).
  2. Install Pro like any plugin: Plugins → Add New → Upload Plugin → Activate.
  3. The free version must be installed and active — Pro sits on top as a companion.
  4. Enter the license key on the plugin's Pro settings page.

Uninstall

  1. Plugins → find the plugin in the list → click "Deactivate".
  2. Then click "Delete" — the plugin and all its data (tables, settings, logs) are removed completely.
  3. The Pro companion uninstalls the same way, independently; the free version keeps working.

Every plugin we ship passes a clean-uninstall test: after "Delete" no tables or leftover settings remain in the database.

Reviews

No reviews yet — be the first.

Write a review

Reviews are published after moderation.