Security

Website Security Headers Explained Simply

What HTTP security headers are (HSTS, X-Frame-Options, Content-Security-Policy, Referrer-Policy and more), how they protect your website and visitors, and how to add them safely.

Website Security Headers Explained Simply
On this page
  1. The most useful headers
  2. How to add them
  3. Be careful with CSP and HSTS
  4. How to check your headers
  5. Headers are one layer, not the whole wall
Key takeaways
  • Security headers tell browsers to behave more safely with your site.
  • HSTS, nosniff, frame protection, Referrer-Policy and Permissions-Policy are quick wins.
  • Roll out CSP and HSTS carefully, and keep the security basics as the main defence.

Security headers are instructions your server sends to browsers along with each page, telling them how to behave more safely: always use HTTPS, don't let other sites frame this page, don't guess file types, and so on. They're a quick, low-cost layer of protection.

The most useful headers

HeaderWhat it does
Strict-Transport-Security (HSTS)Tells browsers to always use HTTPS for your site
X-Content-Type-Options: nosniffStops browsers guessing file types, blocking some attacks
X-Frame-Options / frame-ancestorsPrevents other sites from embedding your pages (clickjacking)
Referrer-PolicyControls how much of your URL is shared when visitors click links to other sites
Permissions-PolicyDisables browser features you don't use (camera, microphone, location)
Content-Security-Policy (CSP)Restricts where scripts, styles and images can load from

How to add them

  • Hosting or server configuration: many hosts let you add headers in the control panel or configuration files
  • Security plugins can add common headers on WordPress
  • CDNs and static hosts often support header rules (this website sets its headers in its hosting configuration)

Be careful with CSP and HSTS

  • CSP can break analytics, chat widgets, embeds and payment scripts if it's too strict. Start in report-only mode and add allowed sources gradually.
  • HSTS should only be enabled once HTTPS works everywhere on your domain and subdomains, because browsers will refuse plain HTTP afterwards.

How to check your headers

Free online security header scanners show which headers your site sends and suggest improvements. Browser developer tools (Network tab) also show response headers.

Headers are one layer, not the whole wall

Updates, strong passwords, backups and a firewall matter more. Use headers alongside the basics in the WordPress security checklist. For hacked sites, see malware removal.

Need help with your website?

I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.

Found this useful? Share it:
Contact

Let's build your next website

Available for freelance projects, agency white-label work and long-term maintenance. Feel free to pass this along to your team or company.

Your details are emailed to me, then WhatsApp opens so we can chat right away.

Chat now