{"id":353941,"date":"2026-08-14T06:09:17","date_gmt":"2026-08-14T06:09:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/essential-headers\/"},"modified":"2026-08-14T06:08:50","modified_gmt":"2026-08-14T06:08:50","slug":"essentialheaders","status":"publish","type":"plugin","link":"https:\/\/ps.wordpress.org\/plugins\/essentialheaders\/","author":20815504,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1","requires":"6.3","requires_php":"7.4","requires_plugins":null,"header_name":"EssentialHeaders","header_author":"Alex Hedstr\u00f6m","header_description":"Adds the essential HTTP security headers WordPress leaves out\u2014CSP, HSTS, frame options, and more\u2014on every front-end response.","assets_banners_color":"2e7894","last_updated":"2026-08-14 06:08:50","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/essentialheaders.com","header_author_uri":"https:\/\/alexhedstrom.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":39,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"alexhedstrom","date":"2026-08-14 06:08:50"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3646718,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3646718,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3646718,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3646718,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[19966,31093,2846,34310,600],"plugin_category":[54],"plugin_contributors":[259029],"plugin_business_model":[],"class_list":["post-353941","plugin","type-plugin","status-publish","hentry","plugin_tags-csp","plugin_tags-hardening","plugin_tags-headers","plugin_tags-hsts","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-alexhedstrom","plugin_committers-alexhedstrom"],"banners":{"banner":"https:\/\/ps.w.org\/essentialheaders\/assets\/banner-772x250.png?rev=3646718","banner_2x":"https:\/\/ps.w.org\/essentialheaders\/assets\/banner-1544x500.png?rev=3646718","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/essentialheaders\/assets\/icon-128x128.png?rev=3646718","icon_2x":"https:\/\/ps.w.org\/essentialheaders\/assets\/icon-256x256.png?rev=3646718","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>EssentialHeaders is a focused WordPress plugin that attaches the HTTP security headers browsers expect, so protection is not left to chance or buried in server config.<\/p>\n\n<p>Under Settings \u2192 EssentialHeaders you get three tabs:<\/p>\n\n<ul>\n<li>Headers \u2014 overview of which headers are enabled and will be sent<\/li>\n<li>Settings \u2014 toggles and editable values for each header<\/li>\n<li>About \u2014 plugin info<\/li>\n<\/ul>\n\n<p>Headers covered:<\/p>\n\n<ul>\n<li>Content-Security-Policy (CSP)<\/li>\n<li>Strict-Transport-Security (HSTS)<\/li>\n<li>X-Frame-Options<\/li>\n<li>X-Content-Type-Options<\/li>\n<li>Referrer-Policy<\/li>\n<li>Permissions-Policy<\/li>\n<\/ul>\n\n<p>Safer headers ship enabled with sensible defaults. CSP starts off so you can adopt it deliberately. Headers apply to public site responses (pages, feeds, and the login screen)\u2014not wp-admin, AJAX, REST, GraphQL, JSON API, or XML-RPC. HSTS is only sent over HTTPS. Default HSTS uses max-age only; add includeSubDomains yourself when every subdomain is ready.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>essentialheaders<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory.<\/li>\n<li>Activate the plugin through the Plugins menu in WordPress.<\/li>\n<li>Open Settings \u2192 EssentialHeaders to review and configure headers.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20break%20my%20site%3F\"><h3>Will this break my site?<\/h3><\/dt>\n<dd><p>The default set is conservative. Content-Security-Policy is off by default because a strict CSP can block scripts or styles your theme needs. Enable CSP when you are ready to tune it.<\/p><\/dd>\n<dt id=\"does%20hsts%20work%20on%20http%3F\"><h3>Does HSTS work on HTTP?<\/h3><\/dt>\n<dd><p>No. Strict-Transport-Security is only sent when the visitor reaches the site over HTTPS.<\/p><\/dd>\n<dt id=\"does%20the%20login%20screen%20get%20these%20headers%3F\"><h3>Does the login screen get these headers?<\/h3><\/dt>\n<dd><p>Yes. The login screen is treated as a public response. wp-admin, AJAX, REST, GraphQL, JSON API, and XML-RPC are excluded so dashboards and APIs are not broken by a strict CSP.<\/p><\/dd>\n<dt id=\"does%20this%20change%20site%20content%3F\"><h3>Does this change site content?<\/h3><\/dt>\n<dd><p>No. The plugin only stores its own options and adds HTTP response headers on public responses.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Adds the essential HTTP security headers WordPress leaves out\u2014on every public site response.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ps.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/353941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ps.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ps.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ps.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=353941"}],"author":[{"embeddable":true,"href":"https:\/\/ps.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/alexhedstrom"}],"wp:attachment":[{"href":"https:\/\/ps.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=353941"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ps.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=353941"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ps.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=353941"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ps.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=353941"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ps.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=353941"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ps.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=353941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}