Title: SERIOUS ISSUE
Last modified: September 5, 2026

---

# SERIOUS ISSUE

 *  [GIORGOS DIMOPOULOS](https://wordpress.org/support/users/giorgos_d2/)
 * (@giorgos_d2)
 * [4 days, 5 hours ago](https://wordpress.org/support/topic/serious-issue-6/)
 * Even though it runs normally on newest version of plugin on my website and even
   though it had an A grade rating in [https://securityheaders.com](https://securityheaders.com),
   it dropped to D grade without me messing with anything, what’s wrong? i cant 
   understand , it became again suddenly grade A , only Content-Security-Policy 
   is in red , I didn’t mess anything up.
    -  This topic was modified 4 days, 4 hours ago by [GIORGOS DIMOPOULOS](https://wordpress.org/support/users/giorgos_d2/).

Viewing 1 replies (of 1 total)

 *  Plugin Author [Andrea Ferro](https://wordpress.org/support/users/unicorn03/)
 * (@unicorn03)
 * [3 days, 4 hours ago](https://wordpress.org/support/topic/serious-issue-6/#post-19012694)
 * Hi Giorgos,
 * Thanks for reporting this. The fluctuation you i describe is a known issue with
   version 5.3.4: headers were sent only through PHP, so a page served straight 
   from your cache (which never runs PHP) had no headers, while a freshly generated
   page did. Scanners hitting one or the other explain the A / D swing you saw.
 * Version 5.3.5, released yesterday, fixes this: on Apache and LiteSpeed the plugin
   writes the headers to your .htaccess again, so cached and static responses carry
   them too. Please update and let me know if the grade stays stable.
 * If you already have 5.3.5 installed, go to Settings > Headers Security Advanced&
   HSTS WP and click Save changes: that forces the .htaccess block to be written.
 * Content-Security-Policy is intentionally sent via PHP only on the front-end, 
   never written to .htaccess, so a strict or nonce-based policy does not reach 
   wp-admin or get frozen into a cached file. If the CSP shows as missing in the
   scan, tell me which cache plugin you use and I’ll look into it.
 * Andrea

Viewing 1 replies (of 1 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fserious-issue-6%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/headers-security-advanced-hsts-wp/assets/icon.svg?rev=3102785)
 * [Headers Security Advanced & HSTS WP](https://wordpress.org/plugins/headers-security-advanced-hsts-wp/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/headers-security-advanced-hsts-wp/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/headers-security-advanced-hsts-wp/)
 * [Active Topics](https://wordpress.org/support/plugin/headers-security-advanced-hsts-wp/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/headers-security-advanced-hsts-wp/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/headers-security-advanced-hsts-wp/reviews/)

 * 1 reply
 * 2 participants
 * Last reply from: [Andrea Ferro](https://wordpress.org/support/users/unicorn03/)
 * Last activity: [3 days, 4 hours ago](https://wordpress.org/support/topic/serious-issue-6/#post-19012694)
 * Status: not resolved