WPIntell

Market

headers security

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

42 / 42 rows with source links

100.0% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

0 rows with no attached evidence

0 rows have source counts but still need direct links.

complaint Breaking update

A security plugin update applied overly strict CSP headers that broke external resources and login forms across multiple sites before follow-up fixes.

Headers Security Advanced & HSTS WP · After updating the plugin today, my site’s login form stopped working because the Google reCAPTCHA field was always empty.
complaint Important: If You Experienced Issues with v5.1.3-5.1.6, Please Update to v5.2.1

Headers Security updates caused site breakage and blocked forms, analytics, cookie banners, and even generated incomplete .htaccess rules that could take a site down.

Headers Security Advanced & HSTS WP · The latest update has completely disabled the site.
complaint After installed this plugin our website is broken!

Installing the security headers plugin broke the website and uninstalling it did not immediately restore the site.

Headers Security Advanced & HSTS WP · We installed this plugin and then our website was broken. We uninstalled the plugin again but the website is still broken.
complaint Trouble logging in via MainWP

A security headers update blocked MainWP dashboard access across many sites until the developer provided direct support.

Headers Security Advanced & HSTS WP · After updating all my sites, the problem logging in via MainWP persists.
complaint Last Update breaks Ecwid shopping cart

A security plugin update made the user's Ecwid product page blank until the plugin was disabled, indicating checkout or storefront breakage.

Headers Security Advanced & HSTS WP · the page with my ecwid products is simply blank. But when i deactivate your plugin – they show up
mixed Issue with v5.2.4 – Blog Pages Blank / 502

Activating version 5.2.4 caused blank blog pages and 502 errors for members until the vendor helped resolve it quickly.

Headers Security Advanced & HSTS WP · my blog pages turn blank and members receive a 502 Bad Gateway error upon login
mixed Error with the latest update: Unable to log in as user/administrator

An update added overly restrictive security policies that blocked login-related actions until version 5.2.1 reverted the problematic behavior.

Headers Security Advanced & HSTS WP · Removed overly restrictive security policies that were causing compatibility issues
complaint After configuration . backoffice login is not working

After configuring security headers, the login button stopped working and the user could not access the WordPress admin area.

Headers Security Advanced & HSTS WP · i’m unable to access the admin area
complaint ISSUE WITH GOOGLE ANALYTICS

A Headers Security update blocked or limited Google Analytics tracking until a later update and settings regeneration fixed it.

Headers Security Advanced & HSTS WP · google analytics stopped showing traffic from mobile phones
complaint Plugin stops loading vimeo url

A security headers update blocked Vimeo videos across the user's websites, prompting plugin removal until follow-up releases fixed the policy issue.

Headers Security Advanced & HSTS WP · Suddenly all the video’s on my website were blocked.
praise Nicely configurable – excellent performance

Nicely configurable – excellent performance: users show security, bugs, performance pain that may indicate a product gap.

Headers Security Advanced & HSTS WP · Nicely configurable – excellent performance I was using Really Simple Security, but the free version kept reporting header errors.
complaint when adding list of website on the microphone

The user reports Permissions-Policy quote handling breaks .htaccess, and the developer confirms and fixes a bug that caused Apache 500 errors.

Headers Security Advanced & HSTS WP · This created a syntax conflict in Apache, which misinterpreted the internal quotes as string delimiters, generating a 500 error.
praise Very good but documentation nonexistent and can cause problems

Very good but documentation nonexistent and can cause problems: users show security, bugs, performance pain that may indicate a product gap.

Headers Security Advanced & HSTS WP · Very good but documentation nonexistent and can cause problems It works really well and is really easy to use, but it can be difficult to figure out the right CSP rules, and the plugin provides zero guidance.
mixed Cannot login with HSTS activated as Turnstyle is not showing

Enabling stricter HSTS/CSP headers hides Cloudflare Turnstile on login pages and later affects Elementor, revealing onboarding gaps around allowlist configuration.

Headers Security Advanced & HSTS WP · When HSTS is activated, the turnstyle does not show. Only when deactivating the plugin (via FTP) I can login
praise FINALLY a solution to the «HSTS headers not implemented» warning

FINALLY a solution to the «HSTS headers not implemented» warning: users show security, missing feature, support pain that may indicate a product gap.

Headers Security Advanced & HSTS WP · FINALLY a solution to the «HSTS headers not implemented» warning Since Andrea has implemented settings to avoid duplicate header entries being listed I am utterly happy with this unobtrusive but veruy helpful plugin.
praise Just install plugin and then save default options already set by plugin

Just install plugin and then save default options already set by plugin: users show security, missing feature, setup pain that may indicate a product gap.

Headers Security Advanced & HSTS WP · Just install plugin and then save default options already set by plugin I went to securityheaders and scanned my site.
complaint Fatal Error hsts_plugin_get_headers()

Headers Security Advanced threw a fatal type error when headers were null, and support later fixed it after missed topic notifications.

Headers Security Advanced & HSTS WP · Argument #1 ($headers) must be of type array, null given
praise just works. beautiful

just works. beautiful: users show security, setup pain that may indicate a product gap.

Headers Security Advanced & HSTS WP · just works.
praise Simple. Works great!

Simple. Works great!: users show security, setup pain that may indicate a product gap.

Headers Security Advanced & HSTS WP · Simple.
praise Amazing, wow => a must have plugin

Amazing, wow => a must have plugin: users show security, setup pain that may indicate a product gap.

Headers Security Advanced & HSTS WP · Amazing, wow => a must have plugin This plugin is very easy to install/configure and does perfectly the job.
praise Aboslute fantastic tool

Aboslute fantastic tool: users show security, missing feature pain that may indicate a product gap.

Headers Security Advanced & HSTS WP · Aboslute fantastic tool Many thanks for offering this tool for free and giving people the option to handle these security settings without having to go to htaccess.
complaint Blocking commonly used cookie banner programs

A security headers plugin blocks common cookie banner tools like CookieYes and Cookiebot, and the user asks for action or a whitelist option after no support reply.

Headers Security Advanced & HSTS WP · make an option to whitelist these sorts of other plugins/codes
complaint version 5.1.6, an issue with Cookiebot appears.

Headers Security Advanced updates blocked Cookiebot’s privacy trigger and repeated fixes still did not resolve the user’s conflict.

Headers Security Advanced & HSTS WP · After updating the plugin to version 5.1.6, an issue with Cookiebot appears.
complaint CSP breaks Flatsome Theme Customizer — how to apply CSP only on the frontend?

A strict CSP from the plugin broke the Flatsome Customizer, and the vendor said they were working on controls to limit or relax CSP in admin areas.

Headers Security Advanced & HSTS WP · the public version of the plugin applies the CSP header globally, so it also affects the admin area and the Customizer
complaint Plugin disables accordion and mobile menu function

The security headers plugin appears to break mobile accordions and the mobile menu, forcing the user to deactivate it despite valuing its function.

Headers Security Advanced & HSTS WP · I have deactivated HSAH so things look fine, but I miss the plugin’s valuable function.
complaint Wordfence Scan Results: Modified plugin file headers-security-advanced-hsts-wp.p

Headers Security Advanced triggers Wordfence modified-file warnings across many sites, and users report no response from the plugin channels.

Headers Security Advanced & HSTS WP · I have the same issue on 84 different sites.
complaint Polylang compatibility issue

A headers plugin update flushes rewrite rules in a way that makes Polylang static pages resolve as empty archive pages until settings are resaved.

Headers Security Advanced & HSTS WP · static pages start resolving to empty archive pages until: Polylang → Settings → URL modifications → Save
complaint Duplicate headers (bis)

The security headers plugin emitted several configured headers twice, including CSP-related values, with no vendor reply yet.

Headers Security Advanced & HSTS WP · your plugin emits a subset of its headers twice.
complaint not working anymore since last update wordpress this nignt

After the latest WordPress update, the security headers plugin reportedly stopped working.

Headers Security Advanced & HSTS WP · header sécurity is not wioorking any more since lat update wp this night
complaint Last update cause error with plugin GN Publisher

The update caused admin-side conflicts with GN Publisher and profile logout behavior that made the user think the site was hacked.

Headers Security Advanced & HSTS WP · I thought I had been hacked, but by disabling your plugin that had just been updated, everything went back to normal.
complaint Ezoic ads are not displaying properly

The plugin's content security policy appeared to prevent Ezoic ads from displaying until settings or an update were applied.

Headers Security Advanced & HSTS WP · Ezoic ads are not displaying properly. The support team from Ezoic told me it’s a problem with the “content-security-policy header”.
neutral Report-Only CSP

A user asks for CSP Report-Only support so they can test security policies separately from active enforcement.

Headers Security Advanced & HSTS WP · This plugin doesn’t seem to support report-only. Am I wrong, or when will it be supported?
question Content Security Policy Failed

The user asks how to fix missing CSP directives such as object-src and script-src in the security headers plugin.

Headers Security Advanced & HSTS WP · Missing object-src allows the injection of plugins with can execute JS.
complaint Adds too much and slows the pageload

A reviewer says the security headers plugin adds unnecessary headers and appears to slow page loads compared with a manual htaccess setup.

Headers Security Advanced & HSTS WP · Adds a lot of unnecessary headers that accomplish nothing. And it seems to slow page load.
praise easy and on the right spot

easy and on the right spot: users show bugs, missing feature, support pain that may indicate a product gap.

Headers Security Advanced & HSTS WP · easy and on the right spot Manually settings secure headers can be a hassle if you don’t know where to start from, or if you have some errors in your code.
mixed First went to A+ now grade C.

The user likes the plugin but says one site's security header grade dropped from A+ to C because some .htaccess rules do not persist.

Headers Security Advanced & HSTS WP · Only one site stays for a bit on A+ grade but dropped down to C grade.
complaint Additional Characters

A security headers update added unexpected characters around CSP policy values, causing browser warnings until the vendor corrected the release package.

Headers Security Advanced & HSTS WP · In this latest updated I noticed that the plugin added addtional characters to some of the policies, specifically ‘self’, ‘none’ ‘unsafe-inline’ and ‘unsafe-eval’.
praise 10/10 recommend

10/10 recommend: users show setup pain that may indicate a product gap.

Headers Security Advanced & HSTS WP · 10/10 recommend Amazing plugin, just install it already.
praise Awesome plugin & support!

Awesome plugin & support!: users show support pain that may indicate a product gap.

Headers Security Advanced & HSTS WP · Awesome plugin & support!
praise Awesome

Awesome: users show pricing pain that may indicate a product gap.

Headers Security Advanced & HSTS WP · Awesome I lover it because it is totally free and it doesn’t have an expensive pro version.