HeaderGenie Security Headers

HeaderGenie Security Headers

Details
View on WordPress

HeaderGenie Security Headers sends HTTP security headers from PHP, so they work on Apache, Nginx, and hosts that ignore .htaccess.

You can:

  • Scan the public site and see which security headers are present, weak, or missing
  • Enable safe defaults such as X-Content-Type-Options, X-Frame-Options, Referrer-Policy, DNS prefetch control, and HSTS on HTTPS
  • Manage those headers from HeaderGenie in wp-admin

The scanner and headers work with no account and do not contact HeaderGenie servers.

A separate HeaderGenie Pro plugin, sold at headergenie.com, adds Content-Security-Policy, extra headers, and cloud monitoring. That plugin is not included here and is not required.

This plugin does not guarantee legal or compliance outcomes. It helps you set and review security headers.

Privacy

This plugin does not contact HeaderGenie servers and does not require an account. A scan requests your own public site URL from the WordPress server so it can read response headers. No analytics, license checks, or third-party tracking run in this plugin.

Details

Plugin code:
headergenie-security-headers
Plugin version:
1.2.28
Outdated:
No
WP version:
6.3 or higher
PHP version:
8.0 or higher
Test up to WP version:
7.1.2
Total installations:
0
Last updated:
2026-09-27
Rating:
Times rated:
0
headers
hsts
https
scanner
security