PluginSift
PluginsThemesCompare
Directory
  • Plugins
  • Themes
  • Compare Plugins
Plugin Comparisons
  • SEO
  • Security
  • Ecommerce
  • Page Builders
  • Caching
  • Backup
  • Forms
  • Analytics
Resources
  • About
  • Contact
  • llms.txt

© 2026 PluginSift. Data sourced from WordPress.org. · [email protected]

  1. Home
  2. Plugins
  3. Email
  4. Host Header Injection Fix
Host Header Injection Fix icon

Host Header Injection Fix

Sets custom headers for WP notification emails. Also fixes a security issue with WP versions < 5.5.

By Jeff Starr·Email·Free
5(6 reviews)
·500 active installs·Updated 1 week ago
DownloadVisit HomepageCompare

As of April 2026, Host Header Injection Fix is a WordPress email plugin with 500 active installations and a 5/5 rating from 6 reviews. It has been downloaded 25K+ times in total. Requires WordPress 4.7+ and PHP 5.6.20+. Available on WordPress.org since 2017. Actively maintained — updated within the last month. Top alternative: WP Mail SMTP by WPForms – The Most….

5/56 reviews
500active installs
25K+total downloads
9 yearssince 2017

Overview

👉 Enables custom headers for WP email notifications

👉 Also provides a “set it and forget it” security fix for WP < 5.5

👉 Uses only 50KB of code, so super lightweight, fast, and effective

Important

As of WordPress 5.5, this plugin no longer is necessary to fix the host-header security issue reported in Ticket #25239 finally is fixed, and mentioned in this post WordPress 5.5 Beta 4. Thank You WordPress devs!

Is this plugin still useful?

Yes, it enables you to choose the “From”, “Name”, and “Return-Path” headers for all WP notification emails. And for versions of WordPress less than 5.5, this plugin continues to fix the host-header injection security issue.

Features

This simple plugin does three things:

  1. Sets custom From, Name, and Return…
Read full description on WordPress.org

Screenshots

Ratings & Reviews

56 reviews
5 ★
6
4 ★
0
3 ★
0
2 ★
0
1 ★
0

Compatibility

WordPress4.7+ requiredTested up to 7.0
PHP5.6.20+ required

Top Alternatives to Host Header Injection Fix

WP Mail SMTP by WPForms &#8211; The Most Popular SMTP and Email Log Plugin icon
WP Mail SMTP by WPForms – The Most…
4.84.0M+ installsUpdated 4 months ago
ViewCompare
MC4WP: Mailchimp for WordPress icon
MC4WP: Mailchimp for WordPress
4.81.0M+ installsUpdated 1 week ago
ViewCompare
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more icon
Easy WP SMTP – WordPress SMTP and Email…
4.6500K+ installsUpdated 3 days ago
ViewCompare
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP &amp; Mobile App icon
Post SMTP – Complete Email…
4.7400K+ installsUpdated 3 days ago
ViewCompare
WP Mail Logging icon
WP Mail Logging
4.7300K+ installsUpdated 1 month ago
ViewCompare
View all email plugins →

Frequently Asked Questions

Changelog

If you like Host Header Injection Fix, please take a moment to give a 5-star rating. It helps to keep development and support going strong. Thank you!

3.5 (2026/01/29)

  • Improves readme.txt documentation
  • Tests on PHP 8.4 and 8.5
  • Tests on WordPress 6.9

Full changelog @

View full changelog on WordPress.org

Contributors

Jeff StarrJeff Starr
Plugin Info
Version
3.5
Last Updated
Mar 27, 2026
WP Requires
4.7+
Tested Up To
7.0
PHP Requires
5.6.20+
Active Installs
500
Downloads
25K+
Added
Nov 6, 2017
Business
Free

Tags

emailheaderssecurityinjectionnotification

Developer

J
Jeff Starr
31 plugins1.2M+ total installs
View all plugins →

Quick Compare

Host Header Injection Fix vs WP Mail SMTP by WPForms – The Most…→Host Header Injection Fix vs MC4WP: Mailchimp for WordPress→Host Header Injection Fix vs Easy WP SMTP – WordPress SMTP and Email…→

Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.