by Jeff Starr
5 (6 reviews)
Host Header Injection Fix
Sets custom headers for WP notification emails. Also fixes a security issue with WP versions < 5.5.
Compatible with WP 6.9
v3.4
Current Version v3.4
Updated 2 months ago
Last Update on 14 Nov, 2025
Synced 9 hours ago
Last Synced on
Rank
#9,137
-5 this week
Active Installs
500+
-11.7%
KW Avg Position
155
—
No change
Downloads
24.6K
+6 today
Support Resolved
0%
—
No change
Rating
100%
Review 5 out of 5
5
(6 reviews)
Next Milestone 600
500+
600+
196
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro
Unlock Exact Install Count
See the precise estimated active installs for this plugin, calculated from real-time ranking data.
- Exact install estimates within tiers
- Track install growth over time
- Milestone progress predictions
Need 32 more installs to reach 600+
Rank Changes
Current
#9,137
Change
Best
#
Downloads Growth
Downloads
Growth
Peak
Upgrade to Pro
Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.
Upgrade NowReviews & Ratings
5.0
6 reviews
Overall
100%
5
6
(100%)
4
0
(0%)
3
0
(0%)
2
0
(0%)
1
0
(0%)
Tracked Keywords
Showing 1 of 1| Keyword | Position | Change | Type | Updated |
|---|---|---|---|---|
| injection | 155 | — | Tag | 11 hours ago |
Unlock Keyword Analytics
Track keyword rankings, search positions, and discover new ranking opportunities with a Pro subscription.
- Full keyword position tracking
- Historical ranking data
- Competitor keyword analysis
Track This Plugin
Get detailed analytics, keyword tracking, and position alerts delivered to your inbox.
Start Tracking FreePlugin Details
- Version
- 3.4
- Last Updated
- Nov 14, 2025
- Requires WP
- 4.7+
- Tested Up To
- 6.9
- PHP Version
- 5.6.20 or higher
- Author
- Jeff Starr
Support & Rating
- Rating
- ★ ★ ★ ★ ★ 5
- Reviews
- 6
- Support Threads
- 0
- Resolved
- 0%
Keywords
Upgrade to Pro
Unlock keyword rankings, search positions, and detailed analytics with a Pro subscription.
Upgrade NowSimilar Plugins
WP Adminify – White Label WordPress, Admin Menu Editor, Login Customizer
7K+ installs
#2,738
Master Addons For Elementor - White Label, Free Widgets, Hover Effects, Conditions, & Animations
40K+ installs
#930
Query Monitor - The developer tools panel for WordPress
200K+ installs
#255
MalCare WordPress Security Plugin - Malware Scanner, Cleaner, Security Firewall
200K+ installs
#258
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more
200K+ installs
#261
Frequently Asked Questions
Common questions about Host Header Injection Fix
As of WordPress 5.5, this plugin no longer is necessary. They finally fixed the bug reported in Ticket #25239, mentioned in this post WordPress 5.5 Beta 4. Thank You WordPress devs! "So is the plugin still useful?" Yes, HHIF enables you to choose the "From", "Name", and "Return-Path" headers for all WP notification emails. And for versions of WordPress less than 5.5, this plugin continues to fix the host-header injection security issue.
For fixing the host-header injection security issue, this plugin is necessary only for WordPress versions less than 5.5 (they fixed the bug in WP 5.5). So if you are running WP 5.5 or better, then you do not need this plugin. Unless you want to customize the headers used in WP notification emails. If you are using WordPress less than 5.5, you can find more information on testing here and here.
Yes, if activated on an individual per-site basis. I.e., may not work properly with network-wide activation.
Yes, there are numerous hooks available for advanced customization. Refer to the source code for details.
When the HHIF option, WP Notifications > "Use custom address" is enabled, the plugin toggles open another option called "Email Return Path". There you can check the box to use the "Email From Address" as the Return Path for all emails sent by WordPress (e.g., new user notifications, new comment notifications, login related notifications, etc.). So check/enable this option only if you want to use the "Email From Address" as the Return Path for all emails sent by WordPress. If in doubt, leave the option unchecked/disabled.
Yes, three of them: BBQ Firewall for super-fast firewall security Blackhole for Bad Bots to protect your site against bad bots Banhammer to monitor and ban any user or IP address Pro versions with more features available at Plugin Planet.
Yes, works great does not matter which editor (block or classic) is used.
Send any questions or feedback via my contact form