Headers Shield
Security headers in one click - with three hardened presets.
Instant delivery: license key + download right after payment.
Version 1.0.0 · updates delivered automatically
About
Browsers expect security headers - and Lighthouse audits penalise their absence. Headers Shield adds them in one click: pick a preset and see the active configuration right on the settings screen.
Six headers are available individually: X-Frame-Options (SAMEORIGIN/DENY), X-Content-Type-Options: nosniff, Referrer-Policy (seven values), X-XSS-Protection, Permissions-Policy (custom directives) and X-Permitted-Cross-Domain-Policies. Nothing is sent until you enable it.
Pro adds HSTS (max-age, includeSubDomains, preload), a Content-Security-Policy builder with Report-Only/Enforce modes and a built-in violation report collector.
What it does
- Six security headers, individually switchable
- Three presets: Minimal, Standard, Strict
- Live view of the active configuration
- Pro: HSTS + CSP builder + violation reports
Free vs Pro
| Free | Pro | |
|---|---|---|
| Security headers | 6 | 6 |
| Presets | 3 | 3 |
| HSTS | - | Yes |
| CSP builder + violation log | - | Yes |
FAQ
Will it break my site?
Presets start permissive; headers apply only after you enable them, and the active set is always visible.
Does it work with caching plugins?
Yes - headers are sent on every response, independent of page cache.
Do I need a Pro license to start?
No. The free edition covers the six core headers; Pro adds HSTS and CSP tooling.
Installation & uninstall
Free version
- Download the zip archive with the "Download free" button above.
- In your WordPress admin: Plugins → Add New → Upload Plugin.
- Pick the downloaded zip, click "Install Now", then "Activate".
- The plugin's menu appears in wp-admin — configure it to your liking.
Pro version
- After payment, download the Pro archive from your order page (the link is also emailed).
- Install Pro like any plugin: Plugins → Add New → Upload Plugin → Activate.
- The free version must be installed and active — Pro sits on top as a companion.
- Enter the license key on the plugin's Pro settings page.
Uninstall
- Plugins → find the plugin in the list → click "Deactivate".
- Then click "Delete" — the plugin and all its data (tables, settings, logs) are removed completely.
- The Pro companion uninstalls the same way, independently; the free version keeps working.
Every plugin we ship passes a clean-uninstall test: after "Delete" no tables or leftover settings remain in the database.
Reviews
No reviews yet — be the first.