Headless
Adds features to use WordPress as a headless CMS: extra fields and prepared block content on the REST API, custom routes for menus and site settings, a preview that points at your frontend instead of the WordPress…
Solid choice
Headless is a solid plugin choice in 2026, with a few things worth checking first. It runs on 10+ sites and was last updated 1 week ago, and scores 66/100 on our health check.
- Actively developed — last update 1 week ago
- Tested with the latest WordPress (7.1)
- Small user base (10+ active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Headless stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| block | >100 |
| developer | >100 |
| gutenberg | >100 |
| utils | #19 |
Version adoption
Share of active sites per release.
About Headless
From the official readme · v3.0.5Description
Adds features to use WordPress as a headless CMS: extra fields and prepared block
content on the REST API, custom routes for menus and site settings, a preview that
points at your frontend instead of the WordPress theme, and cache revalidation for
frontends that support it.
Configuration
The plugin is configured with constants in wp-config.php:
HEADLESS_HEAD_BASE_URL— base URL of your frontend. Preview and revalidation requests go here.HEADLESS_SECRET_TOKEN— shared token sent to the frontend’s/api/previewand/api/revalidateendpoints.HEADLESS_API_KEY_HEADER_KEYandHEADLESS_API_KEY_HEADER_VALUE— require this HTTP header on requests that use the plugin’s REST additions.
Who can read the responses
The plugin’s REST additions activate on requests carrying ?headless=true. That
query parameter is a routing flag, not authentication — anyone can set it. Unless
you configure HEADLESS_API_KEY_HEADER_KEY and HEADLESS_API_KEY_HEADER_VALUE, the
/headless/v1/menus and /headless/v1/settings routes and the added post fields are
readable by anyone who can reach your REST API. Configure the API key if that is not
what you want.
HEADLESS_SECRET_TOKEN is a single shared secret, and the admin pages hand it to the
browser so the editor can open a preview. Every user who can edit posts — Contributor
upwards — can therefore read it and use it against your frontend’s preview and
revalidation endpoints directly. Treat it as a secret shared with your whole editorial
team, and give the frontend its own rate limiting.
Arbitrary section
- BREAKING CHANGE 1.7.0: core/block for block references has changed
Installation
- Upload
headless.zipto the/wp-content/plugins/directory - Extract the Plugin to a
headlessFolder - Activate the plugin through the ‘Plugins’ menu in WordPress
Frequently asked questions
Application passwords stopped being available after updating
Earlier versions forced application passwords on unconditionally. WordPress itself only offers them over HTTPS or in a local environment, because the password travels in an Authorization header on every request. The plugin no longer overrides that. If you knowingly want them on a plain-HTTP site, opt back in: add_filter( 'headless_application_passwords_available', '__return_true' ); The better fix is a TLS certificate.
Comment responses no longer contain author_user.nickname
nickname defaults to the account’s login name, and the comments endpoint is public, so the field was handing out usernames. It is now only included for requests by a user who may list users. display_name is unchanged and is what you want for rendering.
Queries on meta keys starting with an underscore return everything
WordPress treats a leading underscore as protected meta. hl_meta_keys, hl_meta_exists and hl_meta_not_exists now ignore protected keys for requests that may not edit posts — otherwise a like comparison lets anyone read a protected value one character at a time by watching which posts come back. Authenticated requests that may edit posts are unaffected. To decide per key yourself: add_filter( 'headless_meta_key_is_queryable', function( $queryable, $key ) { return $key === '_my_public_key' ? true : $queryable; }, 10, 2 );
hl_post_type no longer accepts every post type
Only post types that are public and exposed in the REST API are accepted, and any resolves to that same set. Post types WordPress would not show in the REST API are no longer passed into the query.
Changelog
3.0.5
Bug Fixes
* keep the blocks of password-protected posts out of the REST response (c944d50)
* resolve only published patterns in headless_blocks (57f4123)
* stop filling the featured media fields from the post itself (66a9c3f)
3.0.4
- leave the application password SSL check to WordPress (8f5701b)
- repair the single menu route (b735870)
- require a nonce for the revalidation endpoints (4e6bd21)
- stop protected post meta from being queried anonymously (5f9f8ee)
- stop publishing comment authors’ login names (1c73947)
3.0.4
- leave the application password SSL check to WordPress (8f5701b)
- repair the single menu route (b735870)
- require a nonce for the revalidation endpoints (4e6bd21)
- stop protected post meta from being queried anonymously (5f9f8ee)
- stop publishing comment authors’ login names (1c73947)
3.0.4
- leave the application password SSL check to WordPress (8f5701b)
- repair the single menu route (b735870)
- require a nonce for the revalidation endpoints (4e6bd21)
- stop protected post meta from being queried anonymously (5f9f8ee)
- stop publishing comment authors’ login names (1c73947)
3.0.4
- leave the application password SSL check to WordPress (8f5701b)
- repair the single menu route (b735870)
- require a nonce for the revalidation endpoints (4e6bd21)
- stop protected post meta from being queried anonymously (5f9f8ee)
- stop publishing comment authors’ login names (1c73947)
3.0.4
- leave the application password SSL check to WordPress (8f5701b)
- repair the single menu route (b735870)
- require a nonce for the revalidation endpoints (4e6bd21)
- stop protected post meta from being queried anonymously (5f9f8ee)
- stop publishing comment authors’ login names (1c73947)
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Headless alternatives
All block plugins →FAQ
Headless: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 10, 2026
Is Headless free?
Yes. Headless is free to download and use from the official WordPress.org plugin directory.
Is Headless safe to use in 2026?
Headless is a solid plugin choice in 2026, with a few things worth checking first. It runs on 10+ sites and was last updated 1 week ago, and scores 66/100 on our health check.
How many websites use Headless?
Headless is active on 10+ WordPress websites and has been downloaded 3,313 times since it launched in May 2022. It was downloaded 196 times in the last 30 days.
Does Headless work with WordPress 7.1?
Yes. The developer has tested Headless up to WordPress 7.1.3, the latest release. It requires WordPress 5.0 or newer.
What PHP version does Headless need?
Headless requires PHP 8.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Headless last updated?
The latest version, 3.0.5, was released on October 2, 2026 (1 week ago).
Who makes Headless?
Headless is developed and maintained by Palasthotel GmbH.
What are the best alternatives to Headless?
The most popular alternatives to Headless are Spectra Legacy (1M+ installs), Breadcrumb NavXT (800K+ installs) and PDF Embedder (300K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card