360 Orbit Header Security

360 Orbit Header Security

Details
View on WordPress

Header Security brings your website up to date with current HTTP security headers:

  • Strict-Transport-Security (HSTS)
  • X-Frame-Options and CSP frame-ancestors (clickjacking protection, even without a full CSP)
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policy
  • Cross-Origin-Opener-Policy / Cross-Origin-Resource-Policy
  • Cookie hardening: adds missing Secure and SameSite attributes to all cookies the website sends

Each header can be switched on and off individually, and its values are fully configurable. A quickstart button enables the recommended settings with a single click.

Free vs. Pro

The free version fully covers all of the basic headers listed above for the frontend.

Header Security Pro adds:

  • Content Security Policy (CSP), including a report-only mode for a low-risk start.
  • Learning mode: collects everything the CSP would block for a configurable period and only switches to enforcing once no finding is left unreviewed.
  • A scanner that automatically detects the external services your site needs (scripts, styles, images, fonts, iframes) and presents them for approval, including bulk approve/block.
  • Separate header configuration for the backend (wp-admin); WordPress’s own services are allowed automatically.
  • Automatic update notifications directly in the WordPress backend.

Details

Plugin code:
360-orbit-header-security
Plugin version:
1.0.23
Author:
Outdated:
No
WP version:
6.4 or higher
PHP version:
8.1 or higher
Test up to WP version:
7.1.2
Total installations:
0
Last updated:
2026-10-06
Rating:
Times rated:
0
clickjacking
hsts
http-headers
security
security-headers