HeaderGenie Security Headers sends HTTP security headers from PHP, so they work on Apache, Nginx, and hosts that ignore .htaccess.
You can:
X-Content-Type-Options, X-Frame-Options, Referrer-Policy, DNS prefetch control, and HSTS on HTTPSThe scanner and headers work with no account and do not contact HeaderGenie servers.
A separate HeaderGenie Pro plugin, sold at headergenie.com, adds Content-Security-Policy, extra headers, and cloud monitoring. That plugin is not included here and is not required.
This plugin does not guarantee legal or compliance outcomes. It helps you set and review security headers.
This plugin does not contact HeaderGenie servers and does not require an account. A scan requests your own public site URL from the WordPress server so it can read response headers. No analytics, license checks, or third-party tracking run in this plugin.