
The short answer: security headers are small instructions your site sends the browser with every page (“do not let anyone put me inside another site”, “do not guess the type of this file”). They cost three lines in .htaccess, do not change how the site looks, and close known kinds of attack. Three can be switched on by almost any site without risk, and others need care.
The headers, one by one
| Header | What it does | Risk in switching it on |
| X-Content-Type-Options: nosniff | Stops the browser “guessing” a file’s type and running as a program one that presented itself as an image. | Hardly any. |
| X-Frame-Options: SAMEORIGIN | Stops other sites showing yours inside a frame (a click-tricking technique). | Breaks embeds of your own site on another domain of yours, if you have any. |
| Referrer-Policy | Controls how much of the originating address is sent to the sites the visitor goes on to. | Low. Some statistics tools may see less. |
| Permissions-Policy | Says which browser features (camera, microphone, location) the page may use. | Low, if you do not use them. |
| Strict-Transport-Security (HSTS) | Forces the browser to always use https. | High if switched on early. It has its own article: HSTS explained. |
| Content-Security-Policy | A list of where the page may load scripts, images and styles from. The strongest defence against injected scripts. | High. A rule that is too tight breaks the site: forms, maps, statistics, videos. |
How to add the three safe ones
|
|
|
|
Content-Security-Policy: start in report-only mode. Instead of enforcing it, use the Content-Security-Policy-Report-Only header. It blocks nothing; it just records, in the browser console, what it would block. Move to the enforcing version only when the list is clean. A WordPress with many plugins has so many script sources that a fair rule takes work.
|
| If the site goes through Cloudflare, some of these headers can also be set there. Pick one place only, so you do not have two rules disagreeing. And if your WordPress already has a security plugin that adds them, check before duplicating. |
|
Added a line and the site stopped opening? Tell us the domain and the line: we will help you undo it. Open a support ticket |
|
SEE ALSO How to redirect HTTP to HTTPS with .htaccess .htaccess for PHP projects: friendly URLs and redirects The Cloudflare options worth having, and the ones that cause trouble |
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $6.60/mo (3-year plan, with coupon) See plans |
- 0 Users Found This Useful











