WPIntell

headers-security-advanced-hsts-wp

Headers Security Advanced & HSTS WP

Best all-in-one WordPress security plugin, uses HTTP & HSTS response headers to avoid vulnerabilities: XSS, injection, clickjacking. Force HTTP/HTTPS.

90.0K
1.4M
4.9
2
22
12

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

113 / 147 rows with source links

76.9% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

34 rows with no attached evidence

0 rows have source counts but still need direct links.

Download Momentum

180 days
8.3K 11.8K -30.1% 182.5K

Related Opportunities

4 markets

Source Evidence

Open evidence explorer
complaint support · high severity · relevance 0.86
Breaking update

A security plugin update applied overly strict CSP headers that broke external resources and login forms across multiple sites before follow-up fixes.

Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
After updating the plugin today, my site’s login form stopped working because the Google reCAPTCHA field was always empty.
complaint support · high severity · relevance 0.82
Important: If You Experienced Issues with v5.1.3-5.1.6, Please Update to v5.2.1

Headers Security updates caused site breakage and blocked forms, analytics, cookie banners, and even generated incomplete .htaccess rules that could take a site down.

Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
The latest update has completely disabled the site.
complaint support · high severity · relevance 0.8
After installed this plugin our website is broken!

Installing the security headers plugin broke the website and uninstalling it did not immediately restore the site.

Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
We installed this plugin and then our website was broken. We uninstalled the plugin again but the website is still broken.
complaint support · high severity · relevance 0.78
Trouble logging in via MainWP

A security headers update blocked MainWP dashboard access across many sites until the developer provided direct support.

Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
After updating all my sites, the problem logging in via MainWP persists.
complaint support · high severity · relevance 0.78
Last Update breaks Ecwid shopping cart

A security plugin update made the user's Ecwid product page blank until the plugin was disabled, indicating checkout or storefront breakage.

Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
the page with my ecwid products is simply blank. But when i deactivate your plugin – they show up
mixed support · high severity · relevance 0.76
Issue with v5.2.4 – Blog Pages Blank / 502

Activating version 5.2.4 caused blank blog pages and 502 errors for members until the vendor helped resolve it quickly.

Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
my blog pages turn blank and members receive a 502 Bad Gateway error upon login
mixed support · high severity · relevance 0.75
Error with the latest update: Unable to log in as user/administrator

An update added overly restrictive security policies that blocked login-related actions until version 5.2.1 reverted the problematic behavior.

Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Removed overly restrictive security policies that were causing compatibility issues
complaint support · high severity · relevance 0.75
After configuration . backoffice login is not working

After configuring security headers, the login button stopped working and the user could not access the WordPress admin area.

Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
i’m unable to access the admin area
complaint support · high severity · relevance 0.74
ISSUE WITH GOOGLE ANALYTICS

A Headers Security update blocked or limited Google Analytics tracking until a later update and settings regeneration fixed it.

Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
google analytics stopped showing traffic from mobile phones
complaint support · high severity · relevance 0.73
Plugin stops loading vimeo url

A security headers update blocked Vimeo videos across the user's websites, prompting plugin removal until follow-up releases fixed the policy issue.

Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Suddenly all the video’s on my website were blocked.

Competitor Context

2 shown
HTTP Security Header praise owner · intel 45.4 · weakness 22.3
praise owner
2 collected complaint signal(s) missing feature support 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security headers lockouts, bot/spam defenses, risky access changes, and incident alerts
WP Anti-Clickjack praise owner · intel 33.5 · weakness 18.9
praise owner
1 source link Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts

Repeated Themes

0 shown

No repeated plugin-level themes have been generated yet.

Collected Signals

20 shown from 61 collected
complaint Duplicate headers (bis) support · 2026-06-21T20:09:27+00:00 · medium severity · clickjacking

The security headers plugin emitted several configured headers twice, including CSP-related values, with no vendor reply yet.

Evidence: your plugin emits a subset of its headers twice.
bugs security security headers output trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Polylang compatibility issue support · 2026-05-19T08:38:55+00:00 · medium severity · clickjacking

A headers plugin update flushes rewrite rules in a way that makes Polylang static pages resolve as empty archive pages until settings are resaved.

Evidence: static pages start resolving to empty archive pages until: Polylang → Settings → URL modifications → Save
compatibility bugs multilingual rewrite rules trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
question Headers Security Advanced & HSTS plugin report only settings support · 2026-05-05T11:37:34+00:00 · low severity · clickjacking

A paid user asks what exactly to paste into the CSP settings to keep the security header in report-only mode.

Evidence: What exactly should I paste into the CSP Header Contents box tso that the CSP is in report-only mode
setup security csp report-only setup trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Adds too much and slows the pageload (2 stars) review · 2026-04-14T04:30:21+00:00 · medium severity · clickjacking

A reviewer says the security headers plugin adds unnecessary headers and appears to slow page loads compared with a manual htaccess setup.

Evidence: Adds a lot of unnecessary headers that accomplish nothing. And it seems to slow page load.
performance security headers output trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Plugin disables accordion and mobile menu function support · 2026-02-11T18:44:45+00:00 · medium severity · clickjacking

The security headers plugin appears to break mobile accordions and the mobile menu, forcing the user to deactivate it despite valuing its function.

Evidence: I have deactivated HSAH so things look fine, but I miss the plugin’s valuable function.
bugs compatibility quality mobile menu interactions trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint not working anymore since last update wordpress this nignt support · 2026-02-04T05:27:02+00:00 · medium severity · clickjacking

After the latest WordPress update, the security headers plugin reportedly stopped working.

Evidence: header sécurity is not wioorking any more since lat update wp this night
compatibility security security headers trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Wordfence Scan Results: Modified plugin file headers-security-advanced-hsts-wp.p support · 2026-01-26T16:33:42+00:00 · medium severity · clickjacking

Headers Security Advanced triggers Wordfence modified-file warnings across many sites, and users report no response from the plugin channels.

Evidence: I have the same issue on 84 different sites.
security support modified file warning trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint After configuration . backoffice login is not working support · 2026-01-13T18:35:07+00:00 · high severity · clickjacking

After configuring security headers, the login button stopped working and the user could not access the WordPress admin area.

Evidence: i’m unable to access the admin area
bugs security setup admin login trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Fantastic! (5 stars) review · 2026-01-09T18:46:53+00:00 · low severity · clickjacking

The reviewer gives a brief positive review of the security headers plugin.

Evidence: Fantastic Plugin!
quality trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
question Duplicate headers support · 2026-01-06T17:31:43+00:00 · low severity · clickjacking

A user asks why duplicate security headers appear in browser tools, and support explains how to hide duplicates when the host also sets them.

Evidence: this is not a security issue but it’s a common scenario
setup security support security headers setup trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Blocking commonly used cookie banner programs support · 2025-12-22T17:42:07+00:00 · medium severity · clickjacking

A security headers plugin blocks common cookie banner tools like CookieYes and Cookiebot, and the user asks for action or a whitelist option after no support reply.

Evidence: make an option to whitelist these sorts of other plugins/codes
compatibility missing feature support cookie banner allowlist trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed First went to A+ now grade C. support · 2025-12-08T10:06:36+00:00 · medium severity · clickjacking

The user likes the plugin but says one site's security header grade dropped from A+ to C because some .htaccess rules do not persist.

Evidence: Only one site stays for a bit on A+ grade but dropped down to C grade.
setup security easy security header configuration trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Awesome (5 stars) review · 2025-11-28T18:51:02+00:00 · low severity · clickjacking

The reviewer already liked Headers Security Advanced and praises support for helping when a problem arose.

Evidence: the help I received from Andrea Ferro when a problem arose was also fantastic
support quality security headers support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Great plugin and support (5 stars) review · 2025-11-28T16:20:57+00:00 · low severity · clickjacking

The reviewer praises the security headers plugin for adding important protection easily and says support answered questions quickly.

Evidence: bring important security to websites by just installing it !
easy performance support security headers trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Great plugin and even better developer! (5 stars) review · 2025-11-25T19:06:43+00:00 · low severity · clickjacking

The reviewer praises the security headers plugin as well done and says the developer answers questions quickly.

Evidence: It’s well done and Andrea is super helpful and fast with questions!
quality support security headers trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Cannot login with HSTS activated as Turnstyle is not showing support · 2025-11-23T09:33:24+00:00 · high severity · clickjacking

Enabling stricter HSTS/CSP headers hides Cloudflare Turnstile on login pages and later affects Elementor, revealing onboarding gaps around allowlist configuration.

Evidence: When HSTS is activated, the turnstyle does not show. Only when deactivating the plugin (via FTP) I can login
compatibility setup security support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Ezoic ads are not displaying properly support · 2025-11-21T03:30:20+00:00 · medium severity · clickjacking

The plugin's content security policy appeared to prevent Ezoic ads from displaying until settings or an update were applied.

Evidence: Ezoic ads are not displaying properly. The support team from Ezoic told me it’s a problem with the “content-security-policy header”.
compatibility setup security content security policy trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint After installed this plugin our website is broken! support · 2025-11-20T11:56:02+00:00 · high severity · clickjacking

Installing the security headers plugin broke the website and uninstalling it did not immediately restore the site.

Evidence: We installed this plugin and then our website was broken. We uninstalled the plugin again but the website is still broken.
bugs security compatibility site security headers trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Issue with v5.2.4 – Blog Pages Blank / 502 support · 2025-11-20T09:50:55+00:00 · high severity · clickjacking

Activating version 5.2.4 caused blank blog pages and 502 errors for members until the vendor helped resolve it quickly.

Evidence: my blog pages turn blank and members receive a 502 Bad Gateway error upon login
bugs easy support quality trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Great plugin, a must have (5 stars) review · 2025-11-19T09:56:19+00:00 · low severity · clickjacking

The reviewer praises the security headers plugin for replacing repeated htaccess edits and improving their security score with strong support.

Evidence: I was tired of changing htaccess every time and still didn’t get a good score for my security header. At last I found this plugin and it works great!
easy quality support security headers trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test HSTS lockouts, bot/spam defenses, risky access changes, and incident alerts