What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
“Disable oEmbed” can mean four different changes in WordPress: stop your site discovering external provider embeds, stop other sites discovering your posts, prevent the WordPress embed host script, or remove one provider such as YouTube. Use the narrowest hook for the behavior you want; none of these snippets disables every oEmbed feature.
What oEmbed does in WordPress
WordPress describes oEmbed as a way for a consumer, such as a blog, to request embed HTML from a provider such as YouTube. It handles media including video, images and text. WordPress keeps an internal provider whitelist, and developers can add providers with wp_oembed_add_provider(), register custom handlers, or remove providers with wp_oembed_remove_provider(). The official handbook explains the overall system in WordPress oEmbed documentation.
There are two directions to consider:
- Incoming embeds: your WordPress site consumes a URL from an external provider.
- Outgoing discovery: your WordPress page advertises oEmbed endpoints so another site can embed your post.
WordPress added discovery support in version 4.4. For non-whitelisted sites, discovered HTML and video are filtered to restricted elements and sandboxed; discovery for those sites is limited to users with the unfiltered_html capability. Preserve those filtering and sandbox protections rather than bypassing them.
Choose the change you actually need
| Goal | Control | Scope |
|---|---|---|
| Stop WordPress inspecting external URLs for provider discovery | embed_oembed_discover |
Incoming discovery only |
| Remove oEmbed links from your page head | wp_oembed_add_discovery_links |
Outgoing discovery metadata |
| Prevent the WordPress embed host JavaScript | Remove wp_oembed_add_host_js |
Host script only |
| Disable one service while retaining others | wp_oembed_remove_provider() |
One provider |
Put custom PHP in a site-specific plugin or a child theme’s functions.php so a parent-theme update does not overwrite it. After changing a hook, inspect a freshly rendered page and test a representative embed.
#1 Best Overall
Stop WordPress discovering external provider endpoints
Use this when WordPress should not inspect an external URL for discoverable oEmbed link tags. WordPress documents the filter’s scope as “Filters whether to inspect the given URL for discoverable link tags.” Its documented default is true; that default changed in WordPress 4.4.0. [embed_oembed_discover reference]
add_filter( 'embed_oembed_discover', '__return_false' );
This prevents the discovery step for incoming URLs. It does not remove oEmbed links emitted by your own pages and does not remove the host JavaScript. WordPress can still handle providers that are already registered or whitelisted.
Remove oEmbed discovery links from your WordPress header
Use this when you do not want other sites to discover your posts through alternate links in the page head. WordPress adds those links for eligible singular posts through wp_oembed_add_discovery_links().
add_action( 'init', function () {
remove_action( 'wp_head', 'wp_oembed_add_discovery_links' );
} );
The function reference records the callback at wp_head priority 4, with a fallback at priority 10, in WordPress 6.9.0. Because hook timing can differ by installed core version or another plugin, check the resulting source rather than assuming removal succeeded. Look for the absence of application/json+oembed alternate links and, where emitted, the XML alternate link. See the official function reference.
Rank #3
If you need to adjust the emitted markup instead of removing the callback, the same reference documents the oembed_discovery_links filter. Removing discovery links does not disable embeds inside the editor or remove provider support for incoming content.
Prevent the WordPress embed host JavaScript
If your specific goal is to stop the WordPress embed host script (commonly seen as wp-embed.min.js), use the documented compatibility removal pattern:
Rank #4
remove_action( 'wp_head', 'wp_oembed_add_host_js' );
wp_oembed_add_host_js() has been deprecated since WordPress 5.9.0 and is no longer used directly as the implementation function. WordPress retains the action as a compatibility signal checked by wp_maybe_enqueue_oembed_host_js(). Therefore, this snippet affects the host-script behavior only; it is not a global oEmbed shutdown. Confirm the result against your WordPress release and inspect the rendered page. Details are in the function reference.
Disable one provider, such as YouTube
When one service is the problem, remove that provider rather than changing unrelated oEmbed behavior. WordPress documents wp_oembed_remove_provider() for removing an oEmbed-enabled provider while leaving other providers available.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBest Value
add_action( 'init', function () {
wp_oembed_remove_provider( 'https://www.youtube.com/oembed' );
} );
The provider URL and pattern must match the registration used by your WordPress version and configuration. Verify the registered pattern before deploying this example; a mismatched pattern will not remove the service. Test both a new URL and any previously saved embed, since cached embed data or content already stored in a post may behave differently.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Verify the change and troubleshoot
- Confirm the installed core version. The discovery-link priority note applies to WordPress 6.9.0, and the host-JavaScript deprecation applies from 5.9.0 onward.
- Clear relevant caches. Purge page, CDN and optimization-plugin caches, then load the page in a private browser window.
- Inspect page source. For outgoing discovery, search for
application/json+oembedand XML alternate links. For the host script, search forwp-embed. - Test the intended direction. Paste an external provider URL into a test post for incoming behavior, or inspect a singular post’s head for outgoing behavior.
- Check competing code. A theme or plugin may add the callback again, run it at a different priority, or cache the old HTML.
Security and compatibility considerations
Do not replace WordPress’s filtering and sandboxing for discovered non-whitelisted content merely to make an embed work. Those restrictions are part of the security model described in the official oEmbed handbook. A targeted filter is safer and easier to maintain than removing all embed-related functionality when your actual requirement concerns one direction, one script or one provider.
The Bottom Line
Use embed_oembed_discover for incoming provider discovery, remove wp_oembed_add_discovery_links for outgoing header links, remove the deprecated host-JavaScript action only when that script is the target, and use wp_oembed_remove_provider() for a single service. Verify the rendered HTML on the WordPress version your site actually runs.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools




