Monitoring
See live headers and CSP reports.
HeaderGenie helps you find missing security protections, configure them from WordPress, and keep an eye on what your site is actually sending.
Free forever for the basics. Pro when you need more.

But have you secured what happens inside your visitors' browsers?
Security headers give browsers explicit instructions about how your website's content should be handled. HeaderGenie makes those controls accessible without requiring you to become a security engineer.
Install HeaderGenie and immediately start improving your site's security posture.
See what your site is currently sending.
Configure important protections directly from WordPress.
The core security features are free.
HeaderGenie works from WordPress rather than requiring you to edit Apache or Nginx configuration.
Content Security Policy is powerful. It's also notoriously easy to get wrong. One change can stop a script, font, video, analytics service or third-party integration from loading.
HeaderGenie Pro makes CSP manageable.
Policies based on the resources your site actually uses.
Report-Only mode first, so you see breakage before visitors do.
See violations, make adjustments, then turn the policy on. Without playing security-header roulette.
You install a plugin. Add a marketing tool. Embed a video. Change your theme. Move to a CDN. Your site's resource requirements change.
HeaderGenie Pro gives you:
See live headers and CSP reports.
Get recommendations based on your site's actual resources.
Add the hosts your public pages actually use, instead of writing the policy by hand.
Lock third-party files to a hash and stamp WordPress scripts so CSP can stay tight.
Check them here. HeaderGenie reads the public homepage and grades the same six headers SecurityHeaders.com scores. Then confirm on SecurityHeaders.com or Mozilla Observatory if you want a second opinion.
£0
Headers included, no licence required
£79 / year
Quick set-up with guided configuration and monitoring
That's £6.59/month when paid annually.