Site Cleanup Controls
Abhishek Site Cleanup Controls gives developers and site owners fine-grained control over 35+ WordPress features that are often unnecessary. Each feature has a simple on/off toggle, organised into five logical groups inside Settings -> Site Cleanup Controls. No features are enabled by default — activate only what you need. Security User Enumeration — Block ?author=N redirect attacks that expose usernames. Author Archives — Return 404 for author archive pages. XML-RPC + Pingback — Fully disable the XML-RPC endpoint and remove the X-Pingback header. Plugin and Theme Editor — Set DISALLOW_FILE_EDIT to prevent in-admin file editing. Application Passwords — Disable the Application Passwords feature. REST API — Restrict REST API access to authenticated users only. Right Click — Disable the browser context menu on the frontend. Performance Emojis — Remove all emoji scripts, styles, and DNS prefetch hints. Embed Objects — Disable WordPress oEmbed and embed scripts. Dashicons — Prevent Dashicons from loading for non-logged-in visitors. Heartbeat — Deregister the Heartbeat API script. Block Library CSS — Remove wp-block-library and global-styles stylesheets on the frontend. Version Var (?ver=) — Strip ?ver= query strings from enqueued asset URLs. PDF Thumbnails — Skip thumbnail generation for uploaded PDF files. oEmbed — Remove oEmbed discovery links and disable autoembed. Remote Block Patterns — Stop WordPress fetching patterns from api.wordpress.org. Head Cleanup Generator Meta Tag — Remove the WordPress version meta tag from head. WLW Manifest — Remove the Windows Live Writer manifest link. Really Simple Discovery (RSD) — Remove the RSD link tag. Short Link — Remove the shortlink tag and HTTP header. Adjacent Posts Links — Remove prev/next link tags from single post heads. RSS Feeds — Redirect all feed URLs to the homepage. Admin Cleanup capital_P_dangit — Remove WordPress forced capitalisation filter. Screen Options and Help Tabs — Hide Screen Options and Help dropdowns. Howdy to Welcome — Replace “Howdy,” with “Welcome,” in the admin bar. Navigation Items in Admin Bar — Remove WP logo, site name, updates, and comments. Clean Dashboard — Remove all default dashboard widgets. Privacy Tools — Hide Export/Erase Personal Data from the Tools menu. Site Health Page — Hide Site Health from the Tools menu. WP Login Logo and Favicon — Hide the WordPress logo on the login page. Admin Email Verification Prompt — Disable the admin email confirm interstitial. Empty Trash (1 week) — Shorten automatic trash-emptying from 30 days to 7 days. Content Comments — Disable comments sitewide. Post Revisions — Disable revision storage. Search — Redirect all search queries to the homepage. WordPress Features Thumbnails / Featured Images — Remove post thumbnail support. Widgets — Disable all widgets and sidebars. Navigation Menus — Remove nav menu theme support. Tags — Unregister tags from posts. Categories — Unregister categories from posts. Post Formats — Remove post format theme support. Custom Fields — Remove custom fields meta box from editor. Excerpts — Remove excerpt support from posts and pages. Trackbacks — Remove trackback support from posts. Attachment Pages — Redirect attachment URLs to the file directly. Automatic Updates — Disable automatic core, plugin, and theme updates. Self Pings — Stop WordPress pinging your own site. jQuery Migrate — Remove jQuery Migrate script on the frontend.
Top keywords
- remove19×3.89%
- disable10×2.05%
- wordpress9×1.84%
- site7×1.43%
- admin5×1.02%
- post5×1.02%
- posts5×1.02%
- support5×1.02%
- api4×0.82%
- cleanup4×0.82%
- hide4×0.82%
- link4×0.82%
Sitevorx
Sitevorx is a lightweight, all-in-one WordPress plugin that helps you optimize performance, harden security, and manage your website from a single, modern dashboard. No bloat, no external dependencies — just the tools you need. Security Center (NEW in 1.1.0) Security Score Dashboard: A single 0–100 score that summarizes the hardening state of your site, with prioritized recommendations. Core Integrity Checker: Compares every WordPress core file against the official api.wordpress.org MD5 checksums to detect modified, missing, or extra files. HTTP Security Headers: One-click enable X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy on the frontend. Login Honeypot: Invisible bait field on wp-login.php that silently rejects spam bots without affecting real users. User Enumeration Protection: Blocks ?author=N probing and the public REST /wp/v2/users endpoint for non-logged-in visitors. Login Notification: Emails the administrator whenever an account with manage_options logs in successfully (1-hour cooldown per IP). Login Attempt Limiter: Lock out IPs after repeated failed login attempts, with configurable threshold, lockout duration, and IP allowlist. Secret Login URL: Hide the default wp-login.php behind a custom keyword. Google reCAPTCHA v2 / v3: Protect the login form from bots, with a configurable v3 score threshold. Disable XML-RPC and Disable File Editor: Block DDoS / brute-force vectors and stop code editing from the dashboard. Speed Optimization Heartbeat Throttle: Slows the Heartbeat API to 60 seconds instead of disabling it, preserving autosave and post-locking. System Tweaks: Lazy load images, limit post revisions, allow safe SVG uploads (with XXE-hardened sanitizer). Database Cleanup: Remove revisions, spam comments, and expired transients in one click. Malware Scanner: Scan your entire codebase and database for suspicious injections. SMTP Configuration Send emails via Gmail (App Password) or a custom SMTP server (SSL/TLS). Built-in Test Email sender. Email delivery log with success/failure tracking. Force From Name and From Email to prevent address drift. Website Utilities Inject tracking codes in Header/Footer (Google Analytics, Facebook Pixel, etc.). Content Protection: Disable right-click, text selection, and drag-and-drop. Maintenance Mode: Display a professional “under construction” page to visitors. Custom Login Logo: Replace the WordPress logo on the login screen with your own brand. Disk Space Manager Recursively scan your hosting for large files (>50 MB). Auto-categorize files (backups, error logs, large media). Bulk delete to free up disk space instantly. Floating Contact Buttons Phone Hotline button with animated icon. Zalo chat button (auto-opens Zalo app). Messenger chat button (m.me deep link). Fully responsive floating widget in the corner of your site. Import / Export Settings Export all Sitevorx settings as a JSON file. Import settings from another site in one click. Reset all settings to factory defaults. Scheduled Cleanup (WP-Cron) Automatic cleanup: daily, twice daily, or weekly. Clears temp files, auto-drafts, spam, and optimizes database tables. Activity log showing the last 20 cleanup runs. Maintenance & Update Monitor Track plugins and themes that need updating. Check WordPress core, PHP version, SSL status, and WP_DEBUG. Maintenance health score with actionable recommendations. Server Info View Web Server, PHP, MySQL, and WordPress versions at a glance. PHP limits: memory, execution time, input vars, upload size. List all loaded PHP extensions. Database size monitoring. External Services Google reCAPTCHA (v2 and v3) Sitevorx can optionally integrate with Google reCAPTCHA (v2 checkbox or v3 invisible / score-based) to protect the WordPress login form. This feature is disabled by default and only works when an administrator explicitly enables it, selects a version, and provides valid Google-issued API keys. When enabled, the plugin loads the Google reCAPTCHA JavaScript on the login screen and sends the generated verification token to Google’s verification endpoint (https://www.google.com/recaptcha/api/siteverify) during login validation. For v3, the configurable score threshold (filter sitevorx_recaptcha_v3_score_threshold, default 0.5) is compared against Google’s returned score. This service is provided by Google: * Service URL: https://www.google.com/recaptcha/ * Verification endpoint: https://www.google.com/recaptcha/api/siteverify * Terms of Service: https://policies.google.com/terms * Privacy Policy: https://policies.google.com/privacy WordPress.org Core Checksums API The Security Center → Kiểm Tra Toàn Diện → WordPress Core Integrity check (off by default; runs only when the admin clicks “Kiểm tra”) fetches the official MD5 checksums for the installed WordPress version from WordPress.org so it can flag modified or missing core files. Verification endpoint: https://api.wordpress.org/core/checksums/1.0/ Request payload: only the installed WordPress version string (e.g. 6.4.2) and the locale en_US. No site URL, user data, or content is sent. Operated by: WordPress.org Terms of Service: https://wordpress.org/about/privacy/ Highlights All-in-one: Replaces 5-7 single-purpose plugins (SMTP, Security, Optimization, Cleanup, Maintenance). Modern UI: Gradient banners, collapsible sidebar, toast notifications, fully responsive. Secure by design: Nonce verification, input sanitization, CSRF protection, prepared database queries. Lightweight: Modular architecture — only loads what you use. Zero frontend impact. No Composer or NPM required. Localized: Full Vietnamese (vi) translation included via .po/.mo files.