Free tool · Security
WordPress Security Header Checker
The WordPress security header checker reviews the instructions your website sends to a visitor's browser. See which protections are visible and where your hosting or website configuration needs a closer look.
Free WordPress security header check
Free to use without an account. View the result here and choose whether to receive it by email.
What the tool covers
Review browser protection settings
Public response headers for HTTPS enforcement, content policy, framing protection, content-type handling and referrer privacy.
HTTPS and transport policy
The check records whether the inspected response uses HTTPS and whether it includes a positive HSTS duration telling browsers to keep using secure connections.
Embedding restrictions
Recognised framing instructions are checked to see whether the response restricts other sites from embedding the page. Custom allowed-source lists need a closer review.
Content security policy
The report identifies an enforcing Content-Security-Policy header. Its presence remains unverified as a protection because the actual policy needs site-specific review.
Content handling and referrers
Browser instructions for content-type handling and referrer information are reviewed for recognised values, with unclear settings kept separate from confirmed checks.
Understand the limits
Header presence alone does not prove a policy is effective. Different pages and response types can send different policies.
Understanding your result
Review the configuration behind each header result
A header result describes the response our server received. Use it to identify a setting to review with your host or developer, rather than copying a policy that has not been tested on your site.
A passed check has a defined scope
The recognised setting was present in the checked response. Repeat the check on relevant pages after changing hosting, security plugins or a content delivery network, as those services can alter headers.
Missing protection needs an owner
Ask which service controls the final response before adding a new header. Your host or developer can inspect the existing configuration and apply one consistent policy at the appropriate layer.
An unverified policy needs testing
Review custom policies alongside the scripts, fonts, embedded content and payment services your site uses. Check essential journeys on staging before enforcing tighter restrictions for visitors.
Understand what a security header does
Alongside a page, the server sends instructions called HTTP headers. Some tell browsers to use HTTPS or limit where scripts can load from. Others control whether another website can embed your pages. The checker reads those instructions from the public response.
Review missing or incomplete protections
A missing header is a configuration finding to investigate. Your host, a security plugin or a content delivery network can control the final response. Identify which service manages a policy before adding another copy, as conflicting settings can break features or weaken the intended protection.
Test policy changes before publishing
A content security policy controls resources such as scripts, fonts and images. Building one for your actual site requires testing forms, page builders and checkout. Ask your host or developer to prepare the policy on staging and check the browser console before applying it to visitors.
Questions about this tool
What are WordPress security headers?
They are HTTP response instructions that tell browsers how to handle parts of your site securely. They can be set by your host, a proxy service or website software.
Does a missing header mean my site has been hacked?
No. It identifies a browser protection that was not visible in the checked response. It does not establish that anyone has exploited the site.
Can I copy a content security policy from another site?
A policy must allow the resources your own site needs. Copying another site's policy can block legitimate scripts, forms or payment services. Test a tailored policy before enforcing it.
Does this checker examine every WordPress page?
No. It reviews the response reached from the address you submit. Repeat the check for relevant public pages when their headers differ.
Can I send the header report to my developer?
You can receive the report through the optional email form and forward it to your developer. Include the address checked so they can reproduce the response.
Free website widget
Add this tool to your website
Let visitors use the WordPress Security Header Checker on your own page, including the option to email their results. Copy the code into an Elementor HTML widget or a WordPress Custom HTML block, then preview the published page.
Get the embed code
The widget fits the width of its container. Increase the height value if you want more of the report visible at once; longer results can be scrolled inside the widget.
BugShield hosts and runs the tool. Results and email addresses stay inside the widget and are not shared with the page embedding it. If your editor removes the code or your site blocks external widgets, ask your website administrator to allow frames from bugshield.co.uk.
Need help with the next step?
A BugShield developer can review the findings and help you decide what your WordPress site needs.
Explore WordPress support