WordPress plugin
Available
Essential Headers
Put the HTTP security headers WordPress leaves out.
PinPoint Essential Headers attaches the HTTP security headers browsers expect—CSP, HSTS, frame protection, and more—so protection is not left to chance or buried in server config.
The problem. A fresh WordPress install rarely sends CSP, HSTS, frame guards, or referrer rules. Scanners flag it, and browsers get no instructions.
What it does. A Settings → Essential Headers screen with clear toggles for CSP, HSTS, X-Frame-Options, nosniff, Referrer-Policy, and Permissions-Policy on every public response.
Best for. Site owners who want scanner-friendly security headers without editing server config or taking on a full firewall suite.
What you get
CSP, HSTS, frame options, nosniff, referrer, and permissions policies
WordPress-native toggles—no server config files required
Safe defaults with CSP off until you are ready to tune it
Headers on public responses, including the login screen
HSTS only sent over HTTPS
Scanner-friendly response hardening without a firewall suite