On This Page
On This Page
Security Headers
Overview
A Pro Security module that sends browser security headers on front, login, admin, and REST. Strong defaults include X-Frame-Options (SAMEORIGIN), X-Content-Type-Options (nosniff), and Referrer-Policy. Optional HSTS (off by default) and CSP (off; report-only by default when enabled). Soft overlap with host/CDN header plugins—avoid conflicting duplicates. Not a WAF. Requires a valid WP PowerSuite license. Tighten HSTS/CSP carefully—they can break mixed content and embeds.

- Agencies hardening production sites
- Teams needing compliance-friendly header baselines
- Sites that want CSP report-only before enforce
Features
Sensible defaults
Optional HSTS
Optional CSP
Wide coverage
Configurable toggles
Use Cases
- Production baselineShip frame/nosniff/referrer defaults on every client site.
- HSTS after HTTPS is solidTurn on HSTS once certificates and redirects are proven.
- CSP rolloutReport-only first; enforce when the console is clean.
Frequently Asked Questions
What does Security Headers do in WP PowerSuite?
It tells modern browsers to enforce sensible safety rules—like blocking sneaky scripts and iframe tricks—with strong defaults you can tighten for HSTS or content policies.
How do I enable Security Headers in WP PowerSuite?
Activate a WP PowerSuite license, enable the module, review defaults, then optionally enable HSTS/CSP carefully.
Who should use Security Headers?
Sites that want browser-enforced hardening without a separate headers plugin.
Is this a firewall?
No. It sets browser security policies—not a WAF or malware scanner.
Is Security Headers a free or Pro module in WP PowerSuite?
It is a Pro module and requires a valid WP PowerSuite license.

