Remove WordPress Version and Extra Links From the Head

Removing the WordPress version and other leftover links from the head is a small cleanup most sites can do safely. By default WordPress prints a <meta name="generator"> tag with the exact version, a Really Simple Discovery (RSD) link for old XML-RPC clients and a ?p=123 shortlink, and it repeats the shortlink in an HTTP Link header.

None of these help visitors or search engines today. This snippet removes them from the HTML head, the HTTP headers and your RSS feeds.

The snippet

<?php
// <meta name="generator"> in the head, and the generator tag in feeds.
remove_action( 'wp_head', 'wp_generator' );
add_filter( 'the_generator', '__return_empty_string' );

// Really Simple Discovery link, only used by old XML-RPC clients.
remove_action( 'wp_head', 'rsd_link' );

// ?p=123 shortlink in the head and in the HTTP Link header.
remove_action( 'wp_head', 'wp_shortlink_wp_head', 10 );
remove_action( 'template_redirect', 'wp_shortlink_header', 11 );

Add it with Scripts Organizer

Scripts Organizer ships this snippet in its One-Click Import library. To add it by hand:

  • In wp-admin go to Scripts Organizer → Code Blocks → Add New and give the block a title.
  • Script location: PHP.
  • Trigger location: Everywhere. The head is printed on the front end, and feeds need the same filter.
  • Action hook: leave it empty. WordPress registers these callbacks in default-filters.php before any plugin loads, so remove_action() already has something to remove while Scripts Organizer loads Everywhere code.
  • Paste the snippet into the PHP editor, enable the block and publish it.

The same code also works unchanged in a small plugin or an mu-plugin file in wp-content/mu-plugins/.

How it works

  • remove_action() only works with the same hook and priority the callback was added with. The three wp_head callbacks use priority 10; wp_shortlink_header is added to template_redirect at 11, so the snippet passes 11.
  • Removing wp_generator covers the HTML head only. Feeds print their own generator tag through the_generator(), so filtering the_generator to an empty string removes the version there too.
  • Older copies of this snippet also removed wlwmanifest_link. WordPress stopped printing the Windows Live Writer manifest in version 6.3, so that line did nothing and is gone.

Customise it

To go further, these lines remove the REST API discovery links and the oEmbed discovery links. The REST API keeps working; only the <link> tags and the Link header go. Keep the oEmbed links if other sites embed your posts.

remove_action( 'wp_head', 'rest_output_link_wp_head', 10 );
remove_action( 'template_redirect', 'rest_output_link_header', 11 );
remove_action( 'wp_head', 'wp_oembed_add_discovery_links', 4 );
remove_action( 'wp_head', 'wp_oembed_add_discovery_links' );

Emoji scripts and block styles are separate cleanups: see Disable Emojis in WP and Remove the Gutenberg Block Library CSS from WordPress.

Gotchas

  • Hiding the version is not a security fix. Scanners also read it from ?ver= on core assets and from files like readme.html. Keeping WordPress updated is what protects you.
  • Some themes print their own generator or pingback tags in header.php; those need a child theme edit.
  • Clear page caches after enabling the snippet, or cached pages keep the old head.

In the Scripts Organizer library Import it with one click from Scripts Organizer.

// newsletter

Three tested WordPress snippets a week

Blocks, security, performance, Tailwind, PHP and React. Copy, paste, ship. You’ll also get DPlugins product updates. No spam, and you can unsubscribe anytime.

// newsletter

Three tested WordPress snippets a week

Blocks, security, performance, Tailwind, PHP and React. Copy, paste, ship. You'll also get DPlugins product updates. No spam, and you can unsubscribe anytime.