Security headers without the security headache.

Make your WordPress site harder to attack.

HeaderGenie helps you find missing security protections, configure them from WordPress, and keep an eye on what your site is actually sending.

  • No server configuration.
  • No .htaccess wrestling.
  • No security-header guesswork.

Free forever for the basics. Pro when you need more.

Header Genie illustration

You may have secured your WordPress site.

But have you secured what happens inside your visitors' browsers?

Security headers give browsers explicit instructions about how your website's content should be handled. HeaderGenie makes those controls accessible without requiring you to become a security engineer.

Start with the basics. For free.

Install HeaderGenie and immediately start improving your site's security posture.

  • Scan your headers

    See what your site is currently sending.

  • Fix common gaps

    Configure important protections directly from WordPress.

  • No licence required

    The core security features are free.

  • No server configuration

    HeaderGenie works from WordPress rather than requiring you to edit Apache or Nginx configuration.

Download HeaderGenie FreeSee the F to A+ walkthrough

The hard part is CSP.

Content Security Policy is powerful. It's also notoriously easy to get wrong. One change can stop a script, font, video, analytics service or third-party integration from loading.

HeaderGenie Pro makes CSP manageable.

  1. Build

    Policies based on the resources your site actually uses.

  2. Test

    Report-Only mode first, so you see breakage before visitors do.

  3. Enforce

    See violations, make adjustments, then turn the policy on. Without playing security-header roulette.

Explore ProCSP to A+

Your website changes. Your security configuration needs to keep up.

You install a plugin. Add a marketing tool. Embed a video. Change your theme. Move to a CDN. Your site's resource requirements change.

HeaderGenie Pro gives you:

Monitoring

See live headers and CSP reports.

Compatibility checks

Get recommendations based on your site's actual resources.

CSP auto-add

Add the hosts your public pages actually use, instead of writing the policy by hand.

SRI and nonces

Lock third-party files to a hash and stamp WordPress scripts so CSP can stay tight.

Don't just hope your security headers are working.

Check them here. HeaderGenie reads the public homepage and grades the same six headers SecurityHeaders.com scores. Then confirm on SecurityHeaders.com or Mozilla Observatory if you want a second opinion.

Start free. Go Pro when the site needs more control.

FREE

£0

Headers included, no licence required

  • Header scanner
  • X-Content-Type-Options
  • X-Frame-Options
  • Referrer-Policy
  • Strict-Transport-Security
  • Permissions-Policy
  • X-DNS-Prefetch-Control
  • Cross-Origin-Opener-Policy
  • Cross-Origin-Embedder-Policy
  • Cross-Origin-Resource-Policy
  • Manual CSP

Get Free

PRO

£79 / year

Quick set-up with guided configuration and monitoring

  • Everything in Free
  • CSP auto-add from scans
  • Script nonces
  • Subresource Integrity
  • Report-only then enforce
  • CSP reports
  • Compatibility checks
  • Monitoring
  • One WordPress site per licence

That's £6.59/month when paid annually.

Get Pro

Header Genie — WordPress security headers, F to A+
Sponsor
SponsoredKunjungi sekarang
Promo