Free · no licence

Scan, then fix the basics.

The free plugin is the first half of the grade. You find what is missing, then send the headers scanners expect, without a key.

01

Open HeaderGenie

After you upload the zip and activate the plugin, HeaderGenie appears in the WordPress sidebar. That is the whole admin UI: Scanner, Headers, CSP, Monitoring, Compatibility, License.

WordPress admin with HeaderGenie in the sidebar
HeaderGenie lives in the WordPress sidebar. One screen, six tabs.
02

Run the scanner first

Scan before you change anything. The plugin checks public pages — the same surface SecurityHeaders.com sees. A failing first scan is the F you are about to leave behind. On a finished site the score reads 100%.

03

Turn on the free defaults

On the Headers tab, enable the conservative set: X-Content-Type-Options, frame controls, Referrer-Policy, and HSTS on HTTPS. These do not need a HeaderGenie account. Permissions-Policy and the isolation headers wait for Pro.

HeaderGenie Headers tab with safe defaults enabled
Turn on the free defaults: nosniff, frame controls, Referrer-Policy, and HSTS on HTTPS.
04

Scan again

The easy findings should clear. What remains is usually Content-Security-Policy — the header that actually moves a scan from “better” to A+. That is the Pro half of the walkthrough.

HeaderGenie Scanner listing present security headers
After the headers are on, the scanner lists each one as present — nosniff, SAMEORIGIN, Referrer-Policy, and the rest.

Continue to CSPDownload Free

Scan and fix the basics · Header Genie