Founding offer 50% off all plans for the first 100 customers, and your renewal price is locked for life. 74 spots left Claim your spot
Turquoise abstract wavy W logo on a black background
Turquoise abstract wavy W logo on a black background
White WP PowerSuite logo on a black background
White WP PowerSuite logo on a black background

Summarize with AI:

On This Page
Last updated: 24/07/2026

Security Headers

Tell modern browsers to enforce sensible safety rules—like blocking sneaky scripts and iframe tricks—with strong defaults you can tighten further for HSTS or content policies.

Overview

A Pro Security module that sends browser security headers on front, login, admin, and REST. Strong defaults include X-Frame-Options (SAMEORIGIN), X-Content-Type-Options (nosniff), and Referrer-Policy. Optional HSTS (off by default) and CSP (off; report-only by default when enabled). Soft overlap with host/CDN header plugins—avoid conflicting duplicates. Not a WAF. Requires a valid WP PowerSuite license. Tighten HSTS/CSP carefully—they can break mixed content and embeds.

Solid black square
Solid black square
Who is this for?
  • Agencies hardening production sites
  • Teams needing compliance-friendly header baselines
  • Sites that want CSP report-only before enforce

Features

Sensible defaults
Frame options, nosniff, and referrer policy on by default.
Optional HSTS
Force HTTPS awareness when you are ready (subdomains optional).
Optional CSP
Start report-only, then tighten content policies.
Wide coverage
Headers on front, login, admin, and REST.
Configurable toggles
Enable only the policies your stack can support.

Use Cases

  • Production baseline
    Ship frame/nosniff/referrer defaults on every client site.
  • HSTS after HTTPS is solid
    Turn on HSTS once certificates and redirects are proven.
  • CSP rollout
    Report-only first; enforce when the console is clean.

Frequently Asked Questions

Related Modules

Turn off public "forgot password" self-service for everyone. Use only when you reset passwords another way (manual admin password, WP-CLI, or admin-sent...
Disabled
Allow or block visitors by IP address—ideal for office-only dashboards or shutting out known troublemakers. Rules apply site-wide, including wp-admin and login.
Disabled
Remove the dashboard screens that let anyone edit theme or plugin code from the browser—one less disaster if an account is compromised.
Disabled
Put your whole site behind one shared password—ideal for staging, client previews, or a soft launch before you go public.
Disabled
Keep a clear record of important dashboard activity—who logged in, what changed, and when—so you can investigate issues or stay audit-ready without...
Disabled
Bot protection with Cloudflare Turnstile on logins, forms, comments, and WooCommerce—low hassle for real people.
Disabled
Blocks risky default usernames during registration so bots have fewer easy targets.
Disabled
Always open your dashboard and login screen over a secure https:// link. Anyone using the old http:// address is sent to the...
Disabled
Automatically protects visible email addresses and mailto links from basic spam bots by safely encoding them while keeping them clickable for visitors.
Disabled
Two-factor login for selected roles—extra proof beyond the password.
Disabled
Founding Member Offer 74 of 100 spots left

Before you go, here's what you'd be leaving.

WP PowerSuite launched this month. The first 100 customers get 50% off and keep that renewal price permanently. When the offer closes on 31 August 2026, prices return to $79 / $239 / $399 and stay there.

  • 154 modules, all included on every plan
  • Renewal price locked for life
  • 14-day refund, one email, no questions
See founding pricing
26 founding members so far 22 days left