Title: HeaderShield
Author: Vishwa
Published: <strong>Ẹrẹ́nà 20, 2026</strong>
Last modified: Ẹrẹ́nà 20, 2026

---

Ṣàwárí àwọn plugin

![](https://ps.w.org/headershield/assets/banner-772x250.png?rev=3487110)

![](https://ps.w.org/headershield/assets/icon.svg?rev=3487110)

# HeaderShield

 Láti ọwọ́ [Vishwa](https://profiles.wordpress.org/sbvi1122/)

[Ṣe ìgbàsílẹ̀](https://downloads.wordpress.org/plugin/headershield.1.0.14.zip)

[Àkọ́kọ́wò Láaye](https://yor.wordpress.org/plugins/headershield/?preview=1)

 * [Àwọn àlàyé](https://yor.wordpress.org/plugins/headershield/#description)
 * [Àwọn àgbéyẹ̀wò](https://yor.wordpress.org/plugins/headershield/#reviews)
 *  [Ìgbéwọlẹ̀](https://yor.wordpress.org/plugins/headershield/#installation)
 * [Ìdàgbàsókè](https://yor.wordpress.org/plugins/headershield/#developers)

 [Ìrànlọ́wọ́](https://wordpress.org/support/plugin/headershield/)

## Àpèjúwe

HeaderShield adds a conservative set of security headers that improve browser protection
without breaking most sites. It also provides optional strict cross-origin protections
for sites that are ready for them.

Default headers include:

 * X-Frame-Options
 * X-Content-Type-Options
 * X-XSS-Protection (legacy)
 * Referrer-Policy
 * Permissions-Policy
 * Content-Security-Policy (upgrade-insecure-requests)
 * Strict-Transport-Security (HTTPS only)

Strict Mode can additionally enable COEP, COOP, and CORP for stronger isolation,
but may break third‑party scripts or embeds. Use with care and test on staging first.

#### Source code for third-party assets

The admin UI uses SlimSelect for the multi-select dropdown. Human-readable source
is included in the plugin:

 * JavaScript: `assets/js/slimselect.js` (minified build: `assets/js/slimselect.
   min.js`)
 * CSS: `assets/css/slimselect.css` (minified build: `assets/css/slimselect.min.
   css`)

Upstream project: https://github.com/brianvoe/slim-select (MIT). This plugin does
not use a custom build process; the included files are from the published release.

## Ìgbéwọlẹ̀

 1. Upload the `headershield` plugin folder to `/wp-content/plugins/`, or install via**
    Plugins  Add New** and search for HeaderShield.
 2. Activate the plugin through the **Plugins** menu in WordPress.
 3. Go to **Security Headers** in the admin sidebar to configure settings.

#### Optional: use as must-use plugin

You can also copy the main plugin file into `/wp-content/mu-plugins/` so it is always
active and cannot be disabled from the Plugins screen.

## FAQ

### Will this break my site?

The default headers are conservative and should be safe for most sites. Strict Mode
may break embeds, analytics, fonts, or CDNs, so test on staging first.

### Does this affect SEO?

No. These headers improve browser security and do not affect SEO.

## Àwọn àgbéyẹ̀wò

Kò sí àwọn àgbéyẹ̀wò fún plugin yìí.

## Àwọn Olùkópa & Olùgbéejáde

“HeaderShield” jẹ́ ètò ìṣàmúlò orísun ṣíṣí sílẹ̀. Àwọn ènìyàn wọ̀nyí ti ṣe ìkópa
sí plugin yìí.

Àwọn Olùkópa

 *   [ Vishwa ](https://profiles.wordpress.org/sbvi1122/)
 *   [ vishvega ](https://profiles.wordpress.org/vishvega/)

[Túmọ̀ “HeaderShield” sí èdè rẹ.](https://translate.wordpress.org/projects/wp-plugins/headershield)

### Ṣe o nífẹ̀ẹ́ sí ìdàgbàsókè?

[Ṣàwárí koodu](https://plugins.trac.wordpress.org/browser/headershield/), ṣàyẹ̀wò
[ibi ìpamọ́ SVN](https://plugins.svn.wordpress.org/headershield/), tàbí ṣe àgbékalẹ̀
sí [àkọsílẹ̀ ìdàgbàsókè](https://plugins.trac.wordpress.org/log/headershield/) nípasẹ̀
[RSS](https://plugins.trac.wordpress.org/log/headershield/?limit=100&mode=stop_on_copy&format=rss).

## Àkọsílẹ̀ àwọn àyípadà

#### 1.0.14

 * Initial public release.

## Àkójọpọ̀ Meta

 *  Ẹ̀yà **1.0.14**
 *  Ìgbàgbọ́hùn tó kẹ́yìn **oṣù 6 sẹ́yìn**
 *  Àwọn ìgbéwọlẹ̀ tó ṣiṣẹ́ **Tó kéré sí 10**
 *  Ẹ̀yà WordPress ** 5.0 tàbí ju bẹ́ẹ̀ lọ **
 *  Dánwò dé **6.9.7**
 *  Ẹ̀yà PHP ** 7.4 tàbí ju bẹ́ẹ̀ lọ **
 *  Èdè
 * [English (US)](https://wordpress.org/plugins/headershield/)
 * Àwọn àmì
 * [csp](https://yor.wordpress.org/plugins/tags/csp/)[hardening](https://yor.wordpress.org/plugins/tags/hardening/)
   [headers](https://yor.wordpress.org/plugins/tags/headers/)[hsts](https://yor.wordpress.org/plugins/tags/hsts/)
   [security](https://yor.wordpress.org/plugins/tags/security/)
 *  [Ìwòye Tó Péye](https://yor.wordpress.org/plugins/headershield/advanced/)

## Àwọn ìbò

Kò sí ìwádìí tí a tíì fi ránṣẹ́.

[Your review](https://wordpress.org/support/plugin/headershield/reviews/#new-post)

[Wo gbogbo àwọn àgbéyẹ̀wò](https://wordpress.org/support/plugin/headershield/reviews/)

## Àwọn Olùkópa

 *   [ Vishwa ](https://profiles.wordpress.org/sbvi1122/)
 *   [ vishvega ](https://profiles.wordpress.org/vishvega/)

## Ìrànlọ́wọ́

Nǹkan wà tí o fẹ́ sọ? Ṣé o nílò ìrànlọ́wọ́?

 [Wo àpéjọ ìrànlọ́wọ́](https://wordpress.org/support/plugin/headershield/)

## Ṣe ìtọrẹ

Ṣé o fẹ́ ṣe àtìlẹ́yìn fún ìlọsíwájú plugin yìí?

 [ Ṣe ìtọrẹ sí plugin yìí ](https://wordpress.org/support/plugin/headershield/)