Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Trash 3.0.33 Minor update available for module trash (3.0.33). EOL Warning: Drupal 11.0 has reached end of life and no longer receives security updates. Usage Milestone: Focal Point Module focal_point crossed 1,000 active installs. Release: UI Patterns (SDC in Drupal UI) 2.0.20 Minor update available for module ui_patterns (2.0.20). Release: Trash 3.1.0-rc1 First release candidate for module trash (3.1.0-rc1). Release: Country 2.2.0 Minor update available for module country (2.2.0). Release: Splidebox 2.0.13 Minor update available for module splidebox (2.0.13). Usage Milestone: Ultimate Cron Module ultimate_cron crossed 1,000 active installs. Usage Milestone: Easy Breadcrumb Module easy_breadcrumb crossed 1,000 active installs. Usage Milestone: Config Filter Module config_filter crossed 1,000 active installs.

HTTP Response Headers

2,339 sites Security covered Drupal 10–11
View on drupal.org

This module allows administrators to set custom HTTP response headers for specific pages, content types, or user roles. It provides flexibility in controlling headers based on various visibility rules and can be extended to support other modules.

What is the HTTP Response Headers module?

This module allows to set HTTP response headers (both standard and non-standard) on pages by various visibility rule settings. Currently the headers can be set by path, content type and user role.

Key Features

  1. Configure list of allowed headers
  2. Ability to configure HTTP headers per content type.
  3. Ability to configure HTTP headers per page.
  4. Ability to configure HTTP headers per user role.
  5. Ability to configure HTTP headers per response status.
  6. The module is using conditions plugins and can be extended. This potentially should also work with Groups module and other modules which provide condition plugins.

Features in Drupal 7 version may vary from Drupal 10 version.

About HTTP security headers

  1. Test your HTTP response headers (securityheaders.io)
  2. HTTP Security
  3. Content Security Policy Level 2
  4. HTTP Security Response Headers Cheat Sheet
  5. What are HTTP security headers?

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Jul 2026
Latest release
1 month ago
Releases (12 mo)
1 ▲ from 0
Maintenance
Active

Releases

Version Type Core Release date
3.0.10 Stable 10–11 Jul 15, 2026