Recommended Free Tools
To remove WordPress’s core version generator tag, add remove_action( 'wp_head', 'wp_generator' ); in a small site-specific plugin or a child theme. This removes the generator output from the page head without editing WordPress core files.
That change hides only one source of version information. WordPress can also expose generator data in feeds, while themes, plugins, and asset URLs may reveal versions separately. Verify the public outputs that matter for your site after making the change.
What the WordPress version tag is—and what removing it does
WordPress attaches its wp_generator() function to the wp_head action. The function can print a generator value containing the WordPress version. WordPress documents the function and a hook-based removal example in its developer reference: wp_generator() – Function.
Removing that action suppresses the core generator output in the HTML head. It does not prove that every response from the site is version-free. The related get_the_generator() reference documents generator output for HTML, XHTML, Atom, RSS2, and RDF formats.
#1 Best Overall
Method 1: remove the core head generator with a hook
Put the code in a site-specific plugin
A small plugin is usually the most update-resistant location because it is independent of the active theme.
<?php
/**
* Plugin Name: Site-specific WordPress adjustments
*/
remove_action( 'wp_head', 'wp_generator' );
- Create a PHP file, such as
site-adjustments.php, inwp-content/plugins/. - Paste the code into that file and save it as plain text with a
.phpextension. - In the WordPress dashboard, open Plugins → Installed Plugins and activate the plugin.
- Clear any page cache or CDN cache before checking the result.
Use a child theme when that is already your maintenance workflow
Add the same line to the child theme’s functions.php. Do not edit the parent theme or WordPress core: a theme or core update can overwrite those files. The code must load before the theme calls wp_head(), which is the normal case for an active child theme.
Rank #2
remove_action( 'wp_head', 'wp_generator' );
Method 2: use a plugin for broader controls
If you want settings for more than the head tag, a plugin may also remove version strings appended to stylesheet and script URLs. For example, the WordPress.org listing for Remove WordPress Version – Hide Generator Meta Tag describes separate controls for the generator meta tag and script/style URL versions.
Review the plugin’s current maintenance, compatibility, and scope before installing it. Its listing notes that themes and other plugins can emit their own tags and that some script-module URLs are not covered. The WordPress.org meta generator plugin directory contains alternatives, but directory ratings, active-install counts, and compatibility indicators change over time and do not establish security effectiveness.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →| Approach | Typical coverage | Advantages | Trade-offs |
|---|---|---|---|
| Core hook in a site plugin | Core generator output attached to wp_head |
Minimal code and no theme dependency | Does not address feeds, asset URLs, or output added by extensions |
| Core hook in a child theme | Core generator output attached to wp_head |
Convenient if the child theme is already maintained | Changing themes removes the customization |
| Settings-based plugin | May include the head tag and script/style URL versions | Broader configurable coverage | Adds a dependency; compatibility and module-URL limitations must be checked |
How to verify what is still exposed
Check the rendered page source
- Open a public page in a private browser window.
- Choose View Page Source, then search for
generatorandWordPress. - Confirm that the core generator meta element is absent after caches are cleared.
Inspect stylesheet and script URLs
Search the source for ?ver= on .css and .js URLs. A version string there can be added by WordPress, a theme, or a plugin and is a separate issue from the head generator tag.
Check feeds and other formats in scope
If your site publishes RSS, Atom, or RDF feeds, inspect those responses as well. WordPress’s generator documentation covers those formats, so removing the wp_head action alone is not a complete feed check.
Rank #4
Identify the component that added a remaining value
- A generator element that remains in page source may come from a theme or plugin.
- An asset query string may be generated by an enqueue routine, theme, plugin, or optimization layer.
- A feed value may be produced by a format-specific generator path rather than the HTML head.
What version hiding does—and does not—secure
Removing visible version signals is a limited fingerprinting reduction. It does not patch WordPress, themes, or plugins, and it does not guarantee that a visitor or scanner cannot identify the software or its version by other means. The plugin listing itself recommends keeping all components updated: Remove WordPress Version – Hide Generator Meta Tag.
- Apply WordPress, theme, and plugin security updates promptly.
- Remove unused themes and plugins and use reputable, maintained extensions.
- Keep backups and test updates on a staging site when possible.
- Treat version concealment as an optional hardening measure, not a vulnerability fix.
Troubleshooting
The tag is still visible
- Confirm the site-specific plugin or child theme is active.
- Ensure the line runs before the page’s
wp_head()call. - Purge page, object, proxy, and CDN caches.
- Check whether a theme or another plugin prints its own generator element.
Assets still contain version strings
The hook above targets the core head generator only. Removing ?ver= values requires separate handling, such as a compatible plugin setting or code that changes the relevant enqueue behavior. Test carefully because those URLs can be part of the site’s cache-busting strategy.
Best Value
The change disappeared after an update
If the code was placed in a parent theme or core file, move it to a site-specific plugin or child theme and reapply the change there.
Recommended choice
For the narrow goal of removing WordPress’s core head generator tag, use the documented remove_action() hook in a site-specific plugin. Choose a settings-based plugin only when you need its additional controls and have checked its current compatibility. In either case, inspect page source, assets, and any feeds that your site exposes, then continue treating software updates as the primary security control.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

