BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Headless icon
Actively maintained Tested with WP 7.1

Headless

Adds features to use WordPress as a headless CMS: extra fields and prepared block content on the REST API, custom routes for menus and site settings, a preview that points at your frontend instead of the WordPress…

Active installs10+10+ tier
Downloads · 30d196▲ +94.1% vs prev. 30d
Rating—0 reviews
Health score66/100Good
All-time downloads3.3KSince May 2022
Support resolved—No recent threads
RequiresWP 5.0PHP 8.0+
Downloads · 7d83▲ +36.1% week over week
Our verdict

Solid choice

Headless is a solid plugin choice in 2026, with a few things worth checking first. It runs on 10+ sites and was last updated 1 week ago, and scores 66/100 on our health check.

  • Actively developed — last update 1 week ago
  • Tested with the latest WordPress (7.1)
  • Small user base (10+ active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

132639Jul 12Aug 25Oct 9
Yesterday4
Daily average (1y)3
Peak day53Oct 3, 2026
Last 12 months1.2K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Headless stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
block >100 10,000 Best block plugins →
developer >100 10,000 Best developer plugins →
gutenberg >100 7,896 Best gutenberg plugins →
utils #19 170 Best utils plugins →

Version adoption

Share of active sites per release.

  • 3.0100.0%

About Headless

From the official readme · v3.0.5

Description

Adds features to use WordPress as a headless CMS: extra fields and prepared block
content on the REST API, custom routes for menus and site settings, a preview that
points at your frontend instead of the WordPress theme, and cache revalidation for
frontends that support it.

Configuration

The plugin is configured with constants in wp-config.php:

  • HEADLESS_HEAD_BASE_URL — base URL of your frontend. Preview and revalidation requests go here.
  • HEADLESS_SECRET_TOKEN — shared token sent to the frontend’s /api/preview and /api/revalidate endpoints.
  • HEADLESS_API_KEY_HEADER_KEY and HEADLESS_API_KEY_HEADER_VALUE — require this HTTP header on requests that use the plugin’s REST additions.

Who can read the responses

The plugin’s REST additions activate on requests carrying ?headless=true. That
query parameter is a routing flag, not authentication
— anyone can set it. Unless
you configure HEADLESS_API_KEY_HEADER_KEY and HEADLESS_API_KEY_HEADER_VALUE, the
/headless/v1/menus and /headless/v1/settings routes and the added post fields are
readable by anyone who can reach your REST API. Configure the API key if that is not
what you want.

HEADLESS_SECRET_TOKEN is a single shared secret, and the admin pages hand it to the

browser so the editor can open a preview. Every user who can edit posts — Contributor
upwards — can therefore read it and use it against your frontend’s preview and
revalidation endpoints directly. Treat it as a secret shared with your whole editorial
team, and give the frontend its own rate limiting.

Arbitrary section

  • BREAKING CHANGE 1.7.0: core/block for block references has changed

Installation

  1. Upload headless.zip to the /wp-content/plugins/ directory
  2. Extract the Plugin to a headless Folder
  3. Activate the plugin through the ‘Plugins’ menu in WordPress

Frequently asked questions

Application passwords stopped being available after updating

Earlier versions forced application passwords on unconditionally. WordPress itself only offers them over HTTPS or in a local environment, because the password travels in an Authorization header on every request. The plugin no longer overrides that. If you knowingly want them on a plain-HTTP site, opt back in: add_filter( 'headless_application_passwords_available', '__return_true' ); The better fix is a TLS certificate.

Comment responses no longer contain author_user.nickname

nickname defaults to the account’s login name, and the comments endpoint is public, so the field was handing out usernames. It is now only included for requests by a user who may list users. display_name is unchanged and is what you want for rendering.

Queries on meta keys starting with an underscore return everything

WordPress treats a leading underscore as protected meta. hl_meta_keys, hl_meta_exists and hl_meta_not_exists now ignore protected keys for requests that may not edit posts — otherwise a like comparison lets anyone read a protected value one character at a time by watching which posts come back. Authenticated requests that may edit posts are unaffected. To decide per key yourself: add_filter( 'headless_meta_key_is_queryable', function( $queryable, $key ) { return $key === '_my_public_key' ? true : $queryable; }, 10, 2 );

hl_post_type no longer accepts every post type

Only post types that are public and exposed in the REST API are accepted, and any resolves to that same set. Post types WordPress would not show in the REST API are no longer passed into the query.

Changelog

3.0.5

Bug Fixes
* keep the blocks of password-protected posts out of the REST response (c944d50)
* resolve only published patterns in headless_blocks (57f4123)
* stop filling the featured media fields from the post itself (66a9c3f)

3.0.4

  • leave the application password SSL check to WordPress (8f5701b)
  • repair the single menu route (b735870)
  • require a nonce for the revalidation endpoints (4e6bd21)
  • stop protected post meta from being queried anonymously (5f9f8ee)
  • stop publishing comment authors’ login names (1c73947)

3.0.4

  • leave the application password SSL check to WordPress (8f5701b)
  • repair the single menu route (b735870)
  • require a nonce for the revalidation endpoints (4e6bd21)
  • stop protected post meta from being queried anonymously (5f9f8ee)
  • stop publishing comment authors’ login names (1c73947)

3.0.4

  • leave the application password SSL check to WordPress (8f5701b)
  • repair the single menu route (b735870)
  • require a nonce for the revalidation endpoints (4e6bd21)
  • stop protected post meta from being queried anonymously (5f9f8ee)
  • stop publishing comment authors’ login names (1c73947)

3.0.4

  • leave the application password SSL check to WordPress (8f5701b)
  • repair the single menu route (b735870)
  • require a nonce for the revalidation endpoints (4e6bd21)
  • stop protected post meta from being queried anonymously (5f9f8ee)
  • stop publishing comment authors’ login names (1c73947)

3.0.4

  • leave the application password SSL check to WordPress (8f5701b)
  • repair the single menu route (b735870)
  • require a nonce for the revalidation endpoints (4e6bd21)
  • stop protected post meta from being queried anonymously (5f9f8ee)
  • stop publishing comment authors’ login names (1c73947)

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Headless alternatives

All block plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Spectra Legacy – Gutenberg Blocks Spectra Legacy – Gutenberg Blocks Gutenberg blocks for existing Spectra websites. Maintained, stable, and fully supported —… by Brainstorm Force 1M+ ★★★★★★★★★★ 4.7 (1.9K) 24 hours ago 88
2 Breadcrumb NavXT Breadcrumb NavXT Adds breadcrumb navigation showing the visitor's path to their current location. by John Havlik 800K+ ★★★★★★★★★★ 4.6 (132) 1 month ago 77
3 PDF Embedder – PDF Viewer & Embed PDF Files for WordPress PDF Embedder – PDF Viewer & Embed PDF Files for WordPress Embed PDF files in WordPress posts and pages with a responsive PDF viewer block, live Block… by Syed Balkhi 300K+ ★★★★★★★★★★ 4.7 (526) 2 months ago 85
4 Layout Grid Block Layout Grid Block A Gutenberg container block to let you align items consistently across a global grid. by Automattic 200K+ ★★★★★★★★★★ 4.7 (13) 3 years ago 43
5 Crowdsignal Forms Crowdsignal Forms The Crowdsignal Forms plugin allows you to create and manage polls right from within the… by Automattic 200K+ ★★★★★★★★★★ 5 (3) 2 days ago 77
6 Content Views – Post Grid & Filter (Shortcode, Blocks, Elementor Widgets) Content Views Easy to show posts, pages, custom posts in customizable grid, list, slider, accordion… by Content Views 100K+ ★★★★★★★★★★ 4.8 (333) 1 month ago 81
7 Email Address Encoder Email Address Encoder A lightweight plugin that protects email addresses from email-harvesting robots, by… by Till Krüss 100K+ ★★★★★★★★★★ 4.2 (160) 6 months ago 77
8 Simple Sitemap – Responsive HTML Sitemap for WordPress Simple Sitemap – Responsive HTML Sitemap for WordPress Build a responsive HTML sitemap in the block editor with live preview, flexible sorting… by David Gwyer 60K+ ★★★★★★★★★★ 3.9 (72) 1 week ago 90
9 Flexible Table Block Flexible Table Block Flexible Table Block is a custom block plugin for the WordPress block editor that allows… by Aki Hamano 40K+ ★★★★★★★★★★ 4.9 (34) 3 months ago 76
10 Genesis Blocks Genesis Blocks A collection of content blocks, sections, & full-page layouts for the block editor. by StudioPress 40K+ ★★★★★★★★★★ 3.7 (24) 2 months ago 65

FAQ

Headless: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 10, 2026

Is Headless free?

Yes. Headless is free to download and use from the official WordPress.org plugin directory.

Is Headless safe to use in 2026?

Headless is a solid plugin choice in 2026, with a few things worth checking first. It runs on 10+ sites and was last updated 1 week ago, and scores 66/100 on our health check.

How many websites use Headless?

Headless is active on 10+ WordPress websites and has been downloaded 3,313 times since it launched in May 2022. It was downloaded 196 times in the last 30 days.

Does Headless work with WordPress 7.1?

Yes. The developer has tested Headless up to WordPress 7.1.3, the latest release. It requires WordPress 5.0 or newer.

What PHP version does Headless need?

Headless requires PHP 8.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Headless last updated?

The latest version, 3.0.5, was released on October 2, 2026 (1 week ago).

Who makes Headless?

Headless is developed and maintained by Palasthotel GmbH.

What are the best alternatives to Headless?

The most popular alternatives to Headless are Spectra Legacy (1M+ installs), Breadcrumb NavXT (800K+ installs) and PDF Embedder (300K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.