Removing the WordPress version and other leftover links from the head is a small cleanup most sites can do safely. By default WordPress prints a <meta name="generator"> tag with the exact version, a Really Simple Discovery (RSD) link for old XML-RPC clients and a ?p=123 shortlink, and it repeats the shortlink in an HTTP Link header.
None of these help visitors or search engines today. This snippet removes them from the HTML head, the HTTP headers and your RSS feeds.
The snippet
<?php
// <meta name="generator"> in the head, and the generator tag in feeds.
remove_action( 'wp_head', 'wp_generator' );
add_filter( 'the_generator', '__return_empty_string' );
// Really Simple Discovery link, only used by old XML-RPC clients.
remove_action( 'wp_head', 'rsd_link' );
// ?p=123 shortlink in the head and in the HTTP Link header.
remove_action( 'wp_head', 'wp_shortlink_wp_head', 10 );
remove_action( 'template_redirect', 'wp_shortlink_header', 11 );
Add it with Scripts Organizer
Scripts Organizer ships this snippet in its One-Click Import library. To add it by hand:
- In wp-admin go to Scripts Organizer → Code Blocks → Add New and give the block a title.
- Script location: PHP.
- Trigger location: Everywhere. The head is printed on the front end, and feeds need the same filter.
- Action hook: leave it empty. WordPress registers these callbacks in
default-filters.phpbefore any plugin loads, soremove_action()already has something to remove while Scripts Organizer loads Everywhere code. - Paste the snippet into the PHP editor, enable the block and publish it.
The same code also works unchanged in a small plugin or an mu-plugin file in wp-content/mu-plugins/.
How it works
remove_action()only works with the same hook and priority the callback was added with. The threewp_headcallbacks use priority 10;wp_shortlink_headeris added totemplate_redirectat 11, so the snippet passes 11.- Removing
wp_generatorcovers the HTML head only. Feeds print their own generator tag throughthe_generator(), so filteringthe_generatorto an empty string removes the version there too. - Older copies of this snippet also removed
wlwmanifest_link. WordPress stopped printing the Windows Live Writer manifest in version 6.3, so that line did nothing and is gone.
Customise it
To go further, these lines remove the REST API discovery links and the oEmbed discovery links. The REST API keeps working; only the <link> tags and the Link header go. Keep the oEmbed links if other sites embed your posts.
remove_action( 'wp_head', 'rest_output_link_wp_head', 10 );
remove_action( 'template_redirect', 'rest_output_link_header', 11 );
remove_action( 'wp_head', 'wp_oembed_add_discovery_links', 4 );
remove_action( 'wp_head', 'wp_oembed_add_discovery_links' );
Emoji scripts and block styles are separate cleanups: see Disable Emojis in WP and Remove the Gutenberg Block Library CSS from WordPress.
Gotchas
- Hiding the version is not a security fix. Scanners also read it from
?ver=on core assets and from files likereadme.html. Keeping WordPress updated is what protects you. - Some themes print their own generator or pingback tags in header.php; those need a child theme edit.
- Clear page caches after enabling the snippet, or cached pages keep the old head.
In the Scripts Organizer library Import it with one click from Scripts Organizer.