headers-security-advanced-hsts-wp
Headers Security Advanced & HSTS WP
Best all-in-one WordPress security plugin, uses HTTP & HSTS response headers to avoid vulnerabilities: XSS, injection, clickjacking. Force HTTP/HTTPS.
Proof Health
Open evidenceCommercial opportunities need traceable source links before they are treated as build-worthy.
76.9% of this page's analysis has direct source links.
0 rows here require auditable proof before promotion.
0 rows have source counts but still need direct links.
Related Opportunities
4 marketsSource Evidence
Open evidence explorerA security plugin update applied overly strict CSP headers that broke external resources and login forms across multiple sites before follow-up fixes.
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alertsHeaders Security updates caused site breakage and blocked forms, analytics, cookie banners, and even generated incomplete .htaccess rules that could take a site down.
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alertsInstalling the security headers plugin broke the website and uninstalling it did not immediately restore the site.
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alertsA security headers update blocked MainWP dashboard access across many sites until the developer provided direct support.
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alertsA security plugin update made the user's Ecwid product page blank until the plugin was disabled, indicating checkout or storefront breakage.
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alertsActivating version 5.2.4 caused blank blog pages and 502 errors for members until the vendor helped resolve it quickly.
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alertsAn update added overly restrictive security policies that blocked login-related actions until version 5.2.1 reverted the problematic behavior.
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alertsAfter configuring security headers, the login button stopped working and the user could not access the WordPress admin area.
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alertsA Headers Security update blocked or limited Google Analytics tracking until a later update and settings regeneration fixed it.
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alertsA security headers update blocked Vimeo videos across the user's websites, prompting plugin removal until follow-up releases fixed the policy issue.
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alertsCompetitor Context
2 shownRepeated Themes
0 shownNo repeated plugin-level themes have been generated yet.
Collected Signals
20 shown from 61 collectedThe security headers plugin emitted several configured headers twice, including CSP-related values, with no vendor reply yet.
Evidence: your plugin emits a subset of its headers twice.A headers plugin update flushes rewrite rules in a way that makes Polylang static pages resolve as empty archive pages until settings are resaved.
Evidence: static pages start resolving to empty archive pages until: Polylang → Settings → URL modifications → SaveA paid user asks what exactly to paste into the CSP settings to keep the security header in report-only mode.
Evidence: What exactly should I paste into the CSP Header Contents box tso that the CSP is in report-only modeA reviewer says the security headers plugin adds unnecessary headers and appears to slow page loads compared with a manual htaccess setup.
Evidence: Adds a lot of unnecessary headers that accomplish nothing. And it seems to slow page load.The security headers plugin appears to break mobile accordions and the mobile menu, forcing the user to deactivate it despite valuing its function.
Evidence: I have deactivated HSAH so things look fine, but I miss the plugin’s valuable function.After the latest WordPress update, the security headers plugin reportedly stopped working.
Evidence: header sécurity is not wioorking any more since lat update wp this nightHeaders Security Advanced triggers Wordfence modified-file warnings across many sites, and users report no response from the plugin channels.
Evidence: I have the same issue on 84 different sites.After configuring security headers, the login button stopped working and the user could not access the WordPress admin area.
Evidence: i’m unable to access the admin areaThe reviewer gives a brief positive review of the security headers plugin.
Evidence: Fantastic Plugin!A user asks why duplicate security headers appear in browser tools, and support explains how to hide duplicates when the host also sets them.
Evidence: this is not a security issue but it’s a common scenarioA security headers plugin blocks common cookie banner tools like CookieYes and Cookiebot, and the user asks for action or a whitelist option after no support reply.
Evidence: make an option to whitelist these sorts of other plugins/codesThe user likes the plugin but says one site's security header grade dropped from A+ to C because some .htaccess rules do not persist.
Evidence: Only one site stays for a bit on A+ grade but dropped down to C grade.The reviewer already liked Headers Security Advanced and praises support for helping when a problem arose.
Evidence: the help I received from Andrea Ferro when a problem arose was also fantasticThe reviewer praises the security headers plugin for adding important protection easily and says support answered questions quickly.
Evidence: bring important security to websites by just installing it !The reviewer praises the security headers plugin as well done and says the developer answers questions quickly.
Evidence: It’s well done and Andrea is super helpful and fast with questions!Enabling stricter HSTS/CSP headers hides Cloudflare Turnstile on login pages and later affects Elementor, revealing onboarding gaps around allowlist configuration.
Evidence: When HSTS is activated, the turnstyle does not show. Only when deactivating the plugin (via FTP) I can loginThe plugin's content security policy appeared to prevent Ezoic ads from displaying until settings or an update were applied.
Evidence: Ezoic ads are not displaying properly. The support team from Ezoic told me it’s a problem with the “content-security-policy header”.Installing the security headers plugin broke the website and uninstalling it did not immediately restore the site.
Evidence: We installed this plugin and then our website was broken. We uninstalled the plugin again but the website is still broken.Activating version 5.2.4 caused blank blog pages and 502 errors for members until the vendor helped resolve it quickly.
Evidence: my blog pages turn blank and members receive a 502 Bad Gateway error upon loginThe reviewer praises the security headers plugin for replacing repeated htaccess edits and improving their security score with strong support.
Evidence: I was tired of changing htaccess every time and still didn’t get a good score for my security header. At last I found this plugin and it works great!