Security Headers
Security headers are instructions your server sends with every page, telling the member's browser how to behave. They cost nothing, break nothing, and they keep working even when a plugin or theme misbehaves, because the browser, not your PHP, does the enforcing.
The Hardening module offers five. All are recommended on.
X-Content-Type-Options
Browsers sometimes second-guess the Content-Type your server declares. A file uploaded as an image gets "helpfully" executed as a script. The nosniff value ends the guessing: the browser must treat content as the type your server said it was. On a membership site where members upload avatars or files, this is the cheapest upload protection you'll ever install.
X-Frame-Options
Controls whether other sites can display your pages inside an iframe. The classic attack is clickjacking: your login page loads in a transparent frame on the attacker's site, invisible buttons float over it, and a member who thinks they're clicking something else is actually typing credentials into your form, for the attacker's benefit.
SAMEORIGIN allows your own pages to frame each other (some plugins need that) and blocks everyone else. Your login page can no longer be framed by external sites.
Referrer-Policy
When a member clicks an outbound link, the browser tells the destination site which page they came from. If that URL carried a query string, a token, a member-specific parameter, it just left your site attached to a stranger's analytics.
strict-origin-when-cross-origin sends the full URL only when navigation stays on your domain. External destinations learn your domain name and nothing more.
Permissions-Policy
Declares which browser features your pages are allowed to use: camera, microphone, geolocation, payment. The value the module sends denies all of them.
That sounds restrictive until you think about who it constrains. Your own pages don't use the camera. But a compromised third-party script, an analytics snippet gone rogue, an iframe you embedded years ago, might try to switch one on quietly. This header makes the attempt fail before any permission prompt reaches your member.
X-XSS-Protection: the header that disables
This one confuses everyone, including the plugin's own card description, which says it "enables the legacy filter." It doesn't. The module sends X-XSS-Protection: 0, which turns the filter off.
The old browser XSS auditor was a clever idea that aged badly: researchers showed the filter itself could be exploited to craft attacks. The browsers that shipped it have deprecated it, and the modern replacement is a Content-Security-Policy, which is a separate project. Until every browser forgets the old filter exists, sending the explicit zero is the correct goodbye. Trust the tooltip, not the card description; the code sends zero.
Verifying they're sent
Any of these checkers will show your headers: securityheaders.com, or your browser's devtools network panel on any page of your site. Look for the five names above in the response headers, and remember caching layers (Cloudflare, page caches) can delay their appearance by a few minutes.