Erasing the WordPress Fingerprint

Ask any page on a default WordPress site what it's running and it will tell you, several times per page, for free. A meta generator tag with the exact version. Version numbers on every stylesheet URL. An RSD link advertising the XML-RPC endpoint. A shortlink exposing post IDs. A manifest for an editor Microsoft discontinued in 2017.

None of these is a hole by itself. Together they're a dossier: platform, version, entry points. When a vulnerability drops for WordPress 6.7.2, attackers don't test every site on the internet; they scan for sites wearing the version on their sleeve. Fingerprint removal makes your site a worse target: not invisible, just not worth the first pass when thousands of easier sites are queued behind you.

Where the version leaks, and which toggle covers each

  • The generator meta tag in your page head: remove_version_head.
  • Feed generator tags in RSS and Atom output: remove_version_rss.
  • The ?ver= query string on every enqueued script and stylesheet: remove_script_versions.

All three matter, because the version leaks from all three places at once. Removing the meta tag while scripts advertise ?ver=6.7.2 leaves the dossier mostly intact. Note that remove_script_versions strips your own WordPress version from asset URLs; individually versioned plugin assets (a cache-busting ?ver=1.4.2 from a plugin) keep theirs, which is fine, that's the plugin's version, not your WordPress version.

Three more toggles remove head links that served tools nobody uses:

  • RSD link: told editing clients where XML-RPC lived. If you're not blogging from MarsEdit, you're not using it.
  • WLW manifest: served Windows Live Writer, dead since 2017. Pure leftover.
  • Shortlink: exposes ?p=123 for every page, which is a map of your post IDs. Content scrapers love incrementing through post IDs; removing the public signpost makes their crawl lazier, and your content structure stays yours.

oEmbed, the embed advertiser

oEmbed lets other sites generate embed previews of your content, and WordPress advertises the capability in two ways: a discovery link in the head (remove_oembed_discovery) and a JavaScript file loaded on every page for embedding others' content (remove_oembed_js). For a membership site, the discovery link is an engraved invitation to scrape structured data about your paid content. Remove it.

The JavaScript file is more nuanced: if you regularly paste YouTube or tweet URLs into the editor and enjoy them turning into players, that's oEmbed doing it, and remove_oembed_js may take those embeds with it. Test before enabling, or keep pasting raw embed codes.

What this isn't

Fingerprint removal is a layer, not a lock. A determined scanner has other ways to guess WordPress (file paths, login page styling, header ordering). The honest claim is smaller: these toggles remove the free, automated identification that every script kiddie's toolkit relies on, and they cost you nothing. Keep WordPress updated regardless; that's the actual lock. Obscurity just makes you a less convenient target while the lock does its job.