30+
September 14, 2026
November 15, 2017
WordPress tells everyone which version you are running. It prints a meta tag in
your page source:
<meta name="generator" content="WordPress 6.9" />
and it appends the same version to every stylesheet and script URL:
style.css?ver=6.9
Anyone can read it, including automated scanners looking for sites running a
version with a known vulnerability. This plugin removes all three.
Each one is a separate switch. All three are on from the moment you activate it.
Scanners fingerprint sites by version, then try exploits for that version. Hiding
it will not patch anything, so keep WordPress updated regardless. What it does is
stop your site appearing in the results when someone searches for every site
running a specific vulnerable release.
Removing the version from asset URLs has a second effect: proxies and CDNs cache
those files more predictably when the URL stops changing on every core update.
One screen, three checkboxes, under Settings then Generator Remover. Nothing is
written to your theme and no files are edited. Deactivate the plugin and
WordPress puts everything back immediately.
To install manually instead, upload the plugin folder to
/wp-content/plugins/ and activate it from the Plugins screen.
Activate the plugin. All three options are on by default, so the generator meta
tag and the version strings on your CSS and JavaScript files are removed straight
away. To check, view the source of your home page and search for “generator”.
Go to Settings, then Generator Remover, and untick the two version options. Leave
“Hide WP Generator Version Meta” ticked and save.
It removes one signal that automated scanners use to pick targets. It does not
patch anything. Treat it as one small step, and keep WordPress, your theme and
your plugins updated.
No. It usually improves it, because the URL stops changing every time WordPress
updates. If you use a cache plugin that adds its own version or cache-busting
string, that keeps working.
The generator tag is not a ranking factor, so removing it changes nothing on its
own. Shorter, stable asset URLs are marginally friendlier to caches, which helps
page speed.
Some themes and plugins print their own version tags. This plugin removes the
ones WordPress core adds. If you still see a version after activating it, it is
coming from your theme or another plugin.
Yes. Settings are per site, so each site in the network has its own.