Invizo Headless Mode
Turn WordPress into a headless CMS backend with frontend redirects, CORS controls, draft previews, login branding, and security hardening.
Use with caution
Invizo Headless Mode works, but test it on a staging site before relying on it in 2026. It runs on 20+ sites and was last updated 3 months ago, and scores 52/100 on our health check.
- Small user base (20+ active installs)
- Very few reviews so far
- Needs PHP 8.1 or newer
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Invizo Headless Mode stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| cors | #31 |
| headless | #21 |
| rest-api | >100 |
| security | >100 |
| wp-headless | #19 |
Version adoption
Share of active sites per release.
About Invizo Headless Mode
From the official readme · v1.0.3Description
Invizo Headless Mode helps teams run WordPress as a headless CMS and API backend for a decoupled frontend built with frameworks such as Next.js, Gatsby, Nuxt, SvelteKit, Remix, Astro, or a custom application.
The plugin can disable the WordPress frontend for public visitors by redirecting frontend routes to your configured site URL. WordPress admin, REST API, AJAX, cron, static assets, and supported API routes remain available.
What this plugin offers
- Disable WP frontend access by redirecting public WordPress routes to your frontend.
- Keep REST API, AJAX, cron, static assets, and WPGraphQL requests available.
- Add strict CORS headers for your frontend origin or origin allowlist.
- Generate signed draft preview links for headless WordPress preview workflows.
- Optional custom admin/login slug for hiding default login URLs.
- Return generic JSON errors for blocked
/wp-admin/and/wp-login.phprequests. - Customize the WordPress login page logo, colors, background image, and back-to-site link visibility.
- Disable XML-RPC, hide the WordPress version, and block common user enumeration routes.
- Disable RSS/Atom feeds, RSD, WLW manifest, oEmbed discovery, shortlinks, and related frontend discovery links.
- Rewrite generated post, page, custom post type, and term permalinks to the headless frontend URL.
- Redirect logout to the frontend and login to WordPress admin.
Privacy and external requests
This plugin does not send tracking data to the plugin author.
When you configure a Front-End URL, the plugin may redirect visitors or logged-out users to that URL according to your settings. CORS headers, logout redirects, permalink rewriting, and preview URLs are also based on URLs that you configure in the plugin settings.
Installation
- Upload the
invizo-headless-modefolder to/wp-content/plugins/. - Activate the plugin through the Plugins screen in WordPress.
- Go to Settings > Headless Mode.
- Enter your headless frontend URL.
- Review the CORS, preview, security, login, discovery, permalink, and login design settings.
- Save changes.
If you enable permalink restructuring or change the custom admin slug, visit Settings > Permalinks and click Save Changes once to flush rewrite rules.
Frequently asked questions
Will this disable the WordPress frontend?
Yes. When a Front-End URL is configured, public WordPress frontend routes redirect to the same path on your headless frontend. Admin, API, AJAX, cron, and static asset requests remain available.
Will this break my REST API?
No. REST API requests are excluded from public frontend redirects.
Does this support WPGraphQL?
Yes. Requests marked by WPGraphQL are excluded from redirects, and the CORS handler can send headers for GraphQL requests.
Can this hide wp-admin and wp-login.php?
Yes. Set a custom admin slug. Direct logged-out access to /wp-admin/ and /wp-login.php returns a generic JSON error and does not reveal the custom login URL.
What is the Preview Secret?
The Preview Secret signs draft preview tokens. Your frontend can verify those tokens before showing unpublished content.
What does Restructure Permalinks do?
When enabled, generated post, page, custom post type, and term links point to your configured frontend URL instead of the WordPress backend URL.
Does the plugin contact invizo.io?
No. The author URL is listed as plugin metadata only. The plugin uses the frontend URL that you configure.
Changelog
1.0.3
- Automatically trigger outgoing frontend revalidation webhooks when posts, pages, or taxonomy terms (categories/tags) are created, updated, or deleted.
1.0.2
- Fix revalidation tab settings save issues where Debug Mode would fail to save.
- Prevent settings from resetting to zero/empty when saving other tabs.
- Move the revalidation activity log table below the Save Changes button for a cleaner full-width layout.
1.0.1
- Rename plugin and slug to Invizo Headless Mode.
- Remove arbitrary custom CSS input from login page customization.
- Move admin JavaScript output to the WordPress enqueue APIs.
- Clean up readme wording for WordPress.org review.
1.0.0
- Initial release.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best Invizo Headless Mode alternatives
All cors plugins →FAQ
Invizo Headless Mode: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 2, 2026
Is Invizo Headless Mode free?
Yes. Invizo Headless Mode is free to download and use from the official WordPress.org plugin directory.
Is Invizo Headless Mode safe to use in 2026?
Invizo Headless Mode works, but test it on a staging site before relying on it in 2026. It runs on 20+ sites and was last updated 3 months ago, and scores 52/100 on our health check.
How many websites use Invizo Headless Mode?
Invizo Headless Mode is active on 20+ WordPress websites and has been downloaded 269 times since it launched in July 2026. It was downloaded 101 times in the last 30 days.
Does Invizo Headless Mode work with WordPress 7.1?
Invizo Headless Mode is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does Invizo Headless Mode need?
Invizo Headless Mode requires PHP 8.1 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Invizo Headless Mode last updated?
The latest version, 1.0.3, was released on July 1, 2026 (3 months ago).
Who makes Invizo Headless Mode?
Invizo Headless Mode is developed and maintained by Invizo.
What are the best alternatives to Invizo Headless Mode?
The most popular alternatives to Invizo Headless Mode are Enable CORS (6K+ installs), WP-CORS (1K+ installs) and CoCart CORS Support (300+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card