{"id":375157,"date":"2026-09-27T10:52:48","date_gmt":"2026-09-27T10:52:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/header-genie\/"},"modified":"2026-09-27T11:16:53","modified_gmt":"2026-09-27T11:16:53","slug":"headergenie-security-headers","status":"publish","type":"plugin","link":"https:\/\/bel.wordpress.org\/plugins\/headergenie-security-headers\/","author":23572318,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.28","stable_tag":"1.2.28","tested":"7.1.2","requires":"6.3","requires_php":"8.0","requires_plugins":null,"header_name":"HeaderGenie Security Headers","header_author":"HeaderGenie","header_description":"Add security headers to any WordPress site. Scan what your site sends and enable safe defaults.","assets_banners_color":"002e99","last_updated":"2026-09-27 11:16:53","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/headergenie.com","header_author_uri":"https:\/\/profiles.wordpress.org\/headergenie","rating":0,"author_block_rating":0,"active_installs":0,"downloads":54,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.2.28":{"tag":"1.2.28","author":"headergenie","date":"2026-09-27 11:16:53","revision":3715381}},"upgrade_notice":{"1.2.28":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.27":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.26":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.25":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.24":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.23":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.22":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.21":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.20":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.19":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.18":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.17":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.16":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.15":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.14":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.13":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.12":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.11":"<p>Renamed to HeaderGenie Security Headers for the WordPress.org listing.<\/p>","1.2.10":"<p>Shared release with Pro, plus scanner and header hardening.<\/p>","1.2.9":"<p>Shared release with Pro, plus scanner and header hardening.<\/p>","1.2.8":"<p>Shared release with Pro, plus scanner and header hardening.<\/p>","1.2.7":"<p>Shared release with Pro, plus scanner and header hardening.<\/p>","1.2.5":"<p>Shared release with Pro, plus scanner and header hardening.<\/p>","1.2.3":"<p>Shared release with Pro, plus scanner and header hardening.<\/p>","1.2.1":"<p>Shared release with Pro, plus scanner and header hardening.<\/p>","1.2.0":"<p>WordPress.org release with scanner and core security headers.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3715355,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3715367,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3715367,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3715367,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.2.28"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[2846,34310,1908,6464,600],"plugin_category":[54],"plugin_contributors":[282952],"plugin_business_model":[],"class_list":["post-375157","plugin","type-plugin","status-publish","hentry","plugin_tags-headers","plugin_tags-hsts","plugin_tags-https","plugin_tags-scanner","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-headergenie","plugin_committers-headergenie"],"banners":{"banner":"https:\/\/ps.w.org\/headergenie-security-headers\/assets\/banner-772x250.png?rev=3715367","banner_2x":"https:\/\/ps.w.org\/headergenie-security-headers\/assets\/banner-1544x500.png?rev=3715367","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/headergenie-security-headers\/assets\/icon-128x128.png?rev=3715355","icon_2x":"https:\/\/ps.w.org\/headergenie-security-headers\/assets\/icon-256x256.png?rev=3715367","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>HeaderGenie Security Headers sends HTTP security headers from PHP, so they work on Apache, Nginx, and hosts that ignore <code>.htaccess<\/code>.<\/p>\n\n<p>You can:<\/p>\n\n<ul>\n<li>Scan the public site and see which security headers are present, weak, or missing<\/li>\n<li>Enable safe defaults such as <code>X-Content-Type-Options<\/code>, <code>X-Frame-Options<\/code>, <code>Referrer-Policy<\/code>, DNS prefetch control, and HSTS on HTTPS<\/li>\n<li>Manage those headers from <strong>HeaderGenie<\/strong> in wp-admin<\/li>\n<\/ul>\n\n<p>The scanner and headers work with no account and do not contact HeaderGenie servers.<\/p>\n\n<p>A separate HeaderGenie Pro plugin, sold at <a href=\"https:\/\/headergenie.com\">headergenie.com<\/a>, adds Content-Security-Policy, extra headers, and cloud monitoring. That plugin is not included here and is not required.<\/p>\n\n<p>This plugin does not guarantee legal or compliance outcomes. It helps you set and review security headers.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>This plugin does not contact HeaderGenie servers and does not require an account. A scan requests your own public site URL from the WordPress server so it can read response headers. No analytics, license checks, or third-party tracking run in this plugin.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>headergenie-security-headers<\/code> folder to <code>\/wp-content\/plugins\/<\/code> or install from <strong>Plugins \u2192 Add Plugin<\/strong>.<\/li>\n<li>Activate <strong>HeaderGenie Security Headers<\/strong>.<\/li>\n<li>Open <strong>HeaderGenie<\/strong> in the admin menu.<\/li>\n<li>Run a scan, then enable the headers you want.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20need%20an%20account%3F\"><h3>Does this plugin need an account?<\/h3><\/dt>\n<dd><p>No. Scanning and the included security headers work locally.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20change%20.htaccess%3F\"><h3>Does the plugin change .htaccess?<\/h3><\/dt>\n<dd><p>No. Headers are sent from PHP on front-end and login responses.<\/p><\/dd>\n<dt id=\"will%20this%20break%20my%20site%3F\"><h3>Will this break my site?<\/h3><\/dt>\n<dd><p>The included headers are conservative. They are not applied to wp-admin, AJAX, REST, or XML-RPC.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20phone%20home%3F\"><h3>Does this plugin phone home?<\/h3><\/dt>\n<dd><p>No. It only requests your own public site URL when you run a scan. Local development can set <code>HEADER_GENIE_SCAN_URL<\/code> in <code>wp-config.php<\/code> if the public URL is not reachable from PHP. It does not contact HeaderGenie servers.<\/p><\/dd>\n<dt id=\"what%20is%20headergenie%20pro%3F\"><h3>What is HeaderGenie Pro?<\/h3><\/dt>\n<dd><p>A separate plugin from headergenie.com. It is optional and is not part of this download.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.28<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Directory banner and icon.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.27<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.26<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.25<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.24<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.23<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.22<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.21<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.20<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.19<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.18<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.17<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.16<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.15<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.14<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.13<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.12<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.11<\/h4>\n\n<ul>\n<li>WordPress.org display name and slug: HeaderGenie Security Headers.<\/li>\n<li>Shared release number with Pro.<\/li>\n<\/ul>\n\n<h4>1.2.10<\/h4>\n\n<ul>\n<li>Shared release number with Pro.<\/li>\n<li>Harden header value allowlists, scanner loopback, and admin HTML escaping.<\/li>\n<\/ul>\n\n<h4>1.2.9<\/h4>\n\n<ul>\n<li>Shared release number with Pro.<\/li>\n<li>Harden header value allowlists, scanner loopback, and admin HTML escaping.<\/li>\n<\/ul>\n\n<h4>1.2.8<\/h4>\n\n<ul>\n<li>Shared release number with Pro.<\/li>\n<li>Harden header value allowlists, scanner loopback, and admin HTML escaping.<\/li>\n<\/ul>\n\n<h4>1.2.7<\/h4>\n\n<ul>\n<li>Shared release number with Pro.<\/li>\n<li>Harden header value allowlists, scanner loopback, and admin HTML escaping.<\/li>\n<\/ul>\n\n<h4>1.2.5<\/h4>\n\n<ul>\n<li>Shared release number with Pro.<\/li>\n<li>Harden header value allowlists, scanner loopback, and admin HTML escaping.<\/li>\n<\/ul>\n\n<h4>1.2.3<\/h4>\n\n<ul>\n<li>Shared release number with Pro.<\/li>\n<li>Harden header value allowlists, scanner loopback, and admin HTML escaping.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Shared release number with Pro.<\/li>\n<li>Harden header value allowlists, scanner loopback, and admin HTML escaping.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>First WordPress.org release: scanner and safe default headers only.<\/li>\n<\/ul>","raw_excerpt":"Add HTTP security headers from WordPress. Scan what your site sends and enable safe defaults.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/bel.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/375157","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bel.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/bel.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/bel.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=375157"}],"author":[{"embeddable":true,"href":"https:\/\/bel.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/headergenie"}],"wp:attachment":[{"href":"https:\/\/bel.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=375157"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/bel.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=375157"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/bel.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=375157"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/bel.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=375157"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/bel.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=375157"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/bel.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=375157"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}