Fix It Easy Security Headers
Configure core HTTP security headers for your WordPress site in a few clicks.
Plugin info
Maintenance & Compatibility
Maintenance score
Maintained • Last updated 129 days ago
Is Fix It Easy Security Headers abandoned?
Likely maintained (last update 129 days ago).
Compatibility
Similar & Alternatives
Explore plugins with similar tags, and compare key metrics like downloads, ratings, updates, support, and WP/PHP compatibility.
Description
WP Fix It Easy Security Headers adds a simple page under Tools Security Headers where you can toggle common HTTP security headers:
- Strict-Transport-Security (HSTS)
- Content-Security-Policy (CSP)
- X-Frame-Options
- X-Content-Type-Options
- Referrer-Policy
- Permissions-Policy
On activation, all headers are enabled by default and you’re redirected to the settings screen.
For convenience, the page and the Plugins screen include a “Check Headers” button that opens SecurityHeaders.com with your site’s URL prefilled (built dynamically from home_url()).
Notes on CSP
This plugin ships with a permissive default CSP intended to “work everywhere” out of the box (allows most external sources and inline code). For stronger protection, you should harden the directives for your specific site.
Key Features
- One-click toggles for popular headers
- Dynamic “Check Headers” scan link
- Uses the WordPress Settings API (nonce + capability checks)
- Output escaping and sanitization following PHPCS
Installation
- Upload the plugin folder to
/wp-content/plugins/fix-it-easy-security-headers/or install via Plugins Add New. - Activate the plugin.
- You’ll be redirected to Tools Security Headers. Review and adjust toggles as needed.
- (Optional) Click Check Headers to verify your headers on SecurityHeaders.com.
Frequently Asked Questions
Go to Tools Security Headers.
All header options are enabled and you’re redirected once to the settings page.
Most headers are safe defaults. The provided CSP is intentionally permissive; it shouldn’t block assets. For strict CSPs, tailor directives to your stack and test.
Yes. The “Check Headers” URL is derived from home_url(). Activation redirect is skipped for network/bulk activations.
The page prints only this plugin’s scoped settings messages to avoid duplicate notices.
Yes. You can modify the $csp string in security_headers_add_headers() to fit your site’s needs.
Review feed
Changelog
1.1
- Initial release.
- Header toggles for HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.
- Activation enables all options and redirects to settings.
- Dynamic SecurityHeaders.com scan link.
