WordPress Security

9-Point WordPress Security Headers Checklist: What to Verify First

Executive summary: Security headers represent one of the simplest yet most frequently overlooked browser-based defenses for small business WordPress sites. In the past 30 days, just 0.5% of 80,573...

Security grade distribution chart — Scan-Insights-Security Headers


Key Findings

  • Only 0.5% of graded scans passed all required security header checks.
  • Commonly missed headers included Content Security Policy (CSP) and X-Frame-Options.
  • Properly configured headers offer browser-enforced mitigation against XSS, clickjacking, and related attacks.
  • Adding the top four recommended headers can significantly reduce exposure to automated threats.

What We Measured

Our analysis is based on 80,573 security header scans of 80,507 unique small business WordPress sites, using ThreatSpot's graded security header checks. These scans evaluate for the presence and correct configuration of industry-standard HTTP response headers known to mitigate client-side web threats. Benchmarks reference OWASP guidance and current browser standards.

What this does not mean:
Passing header checks does not guarantee a site is fully secure, nor does failing indicate known exploitation. Results reflect measured configuration gaps, not confirmed compromise.


The Complete WordPress Security Headers Checklist

1. Content Security Policy (CSP)

Definition:
A Content Security Policy (CSP) header controls which sources browsers trust for loading scripts, styles, and other assets. CSP helps prevent cross-site scripting (XSS) and content injection.

How to check:
Look for a Content-Security-Policy header in HTTP responses. Tools: browser developer tools (Network tab) or website security scans.

How to fix:
Start with a conservative CSP in report-only mode; iterate before enforcing. Many WordPress plugins or host dashboards allow for this setting.
Remediation time: 30-60 minutes for a basic policy.

Priority: Critical


2. X-Frame-Options

Definition:
X-Frame-Options tells browsers not to load your pages in an embedded frame or iframe, defending against clickjacking.

How to check:
Check for X-Frame-Options: SAMEORIGIN or DENY in your header response.

How to fix:
Add via server configuration or a security plugin.
Remediation time: 5-10 minutes.

Priority: Critical


3. X-Content-Type-Options

Definition:
This header instructs browsers not to "sniff" files as something else, reducing the risk from unexpected script execution and drive-by downloads.

How to check:
Presence of X-Content-Type-Options: nosniff in headers.

How to fix:
Add via web server or plugin.
Remediation time: 5 minutes.

Priority: Critical


4. Referrer-Policy

Definition:
Referrer-Policy limits which details about the referer are shared across requests, protecting user privacy.

How to check:
Confirm the Referrer-Policy header, with strict-origin-when-cross-origin aligned with industry best practice.

How to fix:
Set the policy server-side or by plugin.
Remediation time: 5 minutes.

Priority: High


Most common security failures chart — Scan-Insights-Security Headers


5. HTTP Strict Transport Security (HSTS)

Definition:
HTTP Strict Transport Security (HSTS) forces browsers to only use HTTPS, helping prevent SSL downgrade (stripping) attacks.

How to check:
Presence of Strict-Transport-Security header.

How to fix:
Ensure all resources are HTTPS before setting:

  • Strict-Transport-Security: max-age=...; includeSubDomains; preload
  • Test thoroughly before widespread deployment.
    Remediation time: 10 minutes.

Priority: Critical


6. SSL/TLS Configuration

Definition:
A complete SSL/TLS configuration includes correct certificate installation, modern protocols (TLS 1.2 or newer), strong cipher suites, and HSTS.

What we measured:
Most scans found gaps beyond HTTPS presence; for example, missing HSTS or support for legacy SSL protocols.

How to check:
Use SSL analysis tools (like Qualys SSL Labs) or a scanner.

How to fix:

  • Upgrade to TLS 1.2+ only
  • Enable strong ciphers
  • Set HSTS
  • Rotate any expired or weak certificates
    If managed hosting, request these from your provider. Remediation time: 15-45 minutes.

Priority: Critical


Definition:
These flags protect session cookies from being transmitted in insecure contexts or accessed by JavaScript.

How to check:
Inspect cookies in browser dev tools: verify "Secure", "HttpOnly", and "SameSite" attributes.

How to fix:
Update WordPress or plugin config to include these flags.
Remediation time: 5-10 minutes.

Priority: High


8. Server Banner and Version Disclosure

Definition:
Headers such as Server: and X-Powered-By: can reveal software versions, increasing likelihood of targeted automated exploit attempts.

What we measured:
22% of recent scans identified server version information disclosed in headers.

How to check:
Look for these headers in HTTP responses.

How to fix:
Configure web server to remove or generalize supported headers.
Remediation time: 10 minutes.

Priority: High


9. Permissions-Policy (Optional)

Definition:
Permissions-Policy (previously Feature Policy) restricts certain browser features (camera, geolocation) for privacy and compliance.

How to check:
Presence of the Permissions-Policy header.

How to fix:
Set a minimal policy, e.g.: Permissions-Policy: geolocation=(), camera=()
Remediation time: 5 minutes.

Priority: Medium



Quick Reference Table

Priority Action Estimated Time Impact
Critical Enable HSTS & SSL hardening 30 min Defends against sslstrip and protocol downgrade
Critical Add X-Content-Type-Options 5 min Mitigates drive-by and MIME sniffer attacks
High Enforce secure cookie flags 10 min Reduces risk of session hijacking
High Remove version disclosure 10 min Lowers targeted exploit exposure

Why It Matters

Security header adoption remains a persistent gap despite broad availability and the low implementation barrier. For small-business WordPress sites, browser-enforced protections add a critical layer that does not rely on plugins or code changes and can block a wide spectrum of opportunistic and automated threats.


  • Use a reputable scan (such as ThreatSpot's security scanner) to baseline current header posture.
  • Address missing headers and tighten existing policies.
  • Request SSL/TLS and HSTS hardening from your managed host if direct access is unavailable.
  • Revisit settings after major WordPress or plugin updates, as these can affect header outputs.
  • Review effects in both report-only and enforcement modes for policies like CSP.

Frequently Asked Questions

What are security headers, and why are they important?

Security headers are HTTP response fields that instruct browsers to enforce specific security controls. They can block a range of browser-based threats—sometimes before application defenses are engaged.


How do security headers relate to security plugins?

Headers provide protection at the protocol and browser layer. Plugins can help install or configure them, but ultimately the defenses activate client-side (in the browser), independent of plugin logic.


Will adding security headers affect SEO or site performance?

There is no significant impact on site speed or SEO ranking; search engines recommend using security headers. Careful CSP testing is advised to avoid blocking valid content.


What’s the difference between HTTPS and a robust SSL configuration?

HTTPS ensures encrypted transit. For full SSL hardening, additional steps are required: HSTS enforcement, modern protocol use, and strong ciphers to resist known downgrade and interception techniques.


Does hiding server or version headers fully secure my site?

No. Masking version information reduces automated targeting but is not a substitute for regular patching and comprehensive header hardening.


Sources


What this does not mean:
Scan-based header ratings reflect configuration status only, not actual data exposure or current exploitation. Addressing these gaps significantly reduces—but does not eliminate—web-facing risk. Regular monitoring is recommended.

Back to blog
Share:

More on this topic

Want a quick security check?

Run a free scan and get your security grade in minutes.

Run Free Scan