71 Quality Score
Active Installs
17/30

With roughly 6,000 active installs the plugin has a modest footprint, well below category leaders like zipaddr-jp at 50,000 installs, indicating a niche audience.

Update Freshness
25/25

The plugin was updated on 2026-06-10 and is tested against WordPress 7.0 with a minimum requirement of 4.7, which signals an actively maintained codebase despite the small user base.

User Rating
7/15

A score of 74 out of 100 from only 3 ratings is statistically thin and leaves real-world sentiment largely unknown, so the rating should be treated as suggestive rather than reliable.

Support Health
8/15

Zero support threads opened and zero resolved gives a 50 percent score, meaning there is simply no evidence either way about how the author handles user issues.

WP Compatibility
15/15

Full marks here reflect that the plugin declares compatibility with WordPress 7.0 and only requires PHP 7.1, which is a low bar that virtually every modern host meets.

Scores higher than 26% of indexed plugins

About

Please read the plugin description before installing to ensure compatibility and avoid potential issues. This plugin will be free forever.

Active Installs 6k+
Rating ★★★½ 3.7/5
Last Updated 2026-07-15 6:50pm GMT
Requires WordPress 4.7+
Tested Up To 7.0.4
Requires PHP 7.1+

Security History

1 known vulnerability, all patched
1 Critical

Most recent: June 18, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

Enable CORS adds Cross-Origin Resource Sharing headers to your WordPress site's HTTP responses, allowing browsers to permit requests from external domains, origins, or applications. In practice, it solves problems where JavaScript on a different domain cannot fetch data, submit forms, or call your WordPress REST API because the browser blocks the request. It is a small utility plugin aimed at a specific server configuration task rather than a feature-rich CORS management suite.

Who It's For

This plugin is best for developers or technical site owners running headless WordPress setups, mobile app backends, or any site that exposes its REST API to third-party frontends, SaaS platforms, or partner domains. It suits users who understand what CORS means and just want a quick, free way to enable the necessary response headers without editing .htaccess or writing custom code. It is also useful for teams prototyping cross-domain integrations who need a fast, low-commitment solution.

Who Should Skip It

If your site only serves content to its own domain or you do not have any cross-origin AJAX or API requests, you do not need this plugin at all. Developers comfortable editing .htaccess, nginx config, or adding a few lines to functions.php can also skip it, since the underlying CORS headers are trivial to set without a plugin.

The Bottom Line

Enable CORS does a narrow job and appears to do it competently, with strong maintenance and compatibility signals offsetting thin ratings and no visible support track record. With only 3 ratings and a 71.08 overall quality score, it is a reasonable pick for developers who want a lightweight, no-cost solution, but anyone uncomfortable with the lack of community validation should consider setting CORS headers manually instead. The plugin is functional, not exceptional.

Tags

ajax cors enable error fix