Website Security Headers Explained Simply
What HTTP security headers are (HSTS, X-Frame-Options, Content-Security-Policy, Referrer-Policy and more), how they protect your website and visitors, and how to add them safely.

On this page
- Security headers tell browsers to behave more safely with your site.
- HSTS, nosniff, frame protection, Referrer-Policy and Permissions-Policy are quick wins.
- Roll out CSP and HSTS carefully, and keep the security basics as the main defence.
Security headers are instructions your server sends to browsers along with each page, telling them how to behave more safely: always use HTTPS, don't let other sites frame this page, don't guess file types, and so on. They're a quick, low-cost layer of protection.
The most useful headers
| Header | What it does |
|---|---|
| Strict-Transport-Security (HSTS) | Tells browsers to always use HTTPS for your site |
| X-Content-Type-Options: nosniff | Stops browsers guessing file types, blocking some attacks |
| X-Frame-Options / frame-ancestors | Prevents other sites from embedding your pages (clickjacking) |
| Referrer-Policy | Controls how much of your URL is shared when visitors click links to other sites |
| Permissions-Policy | Disables browser features you don't use (camera, microphone, location) |
| Content-Security-Policy (CSP) | Restricts where scripts, styles and images can load from |
How to add them
- Hosting or server configuration: many hosts let you add headers in the control panel or configuration files
- Security plugins can add common headers on WordPress
- CDNs and static hosts often support header rules (this website sets its headers in its hosting configuration)
Be careful with CSP and HSTS
- CSP can break analytics, chat widgets, embeds and payment scripts if it's too strict. Start in report-only mode and add allowed sources gradually.
- HSTS should only be enabled once HTTPS works everywhere on your domain and subdomains, because browsers will refuse plain HTTP afterwards.
How to check your headers
Free online security header scanners show which headers your site sends and suggest improvements. Browser developer tools (Network tab) also show response headers.
Headers are one layer, not the whole wall
Updates, strong passwords, backups and a firewall matter more. Use headers alongside the basics in the WordPress security checklist. For hacked sites, see malware removal.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.


