RefiTune – Site refiner toolkit
Hungarian: Magyar nyelvű bővítmény leírás RefiTune – Site refiner toolkit is a modular Swiss Army knife for WordPress. Clean up unnecessary front-end code, harden login and uploads, tune Heartbeat and updates, or brand wp-login – each module is opt-in. Enable or disable features individually. A clean dashboard shows what is active. In-plugin Help pages document behaviour, trade-offs, and requirements. What’s Inside? (35 Modules) Performance: * Header Cleanup – Strip unnecessary wp_head output for leaner pages. * Feed Management – Control RSS/Atom feed link tags in the document head. * Disable Emoji – Remove WordPress emoji scripts and styles. * Disable jQuery Migrate – Drop legacy jquery-migrate when your stack does not need it. * Disable oEmbed – Stop automatic embeds from pasted YouTube, Vimeo, Twitter/X, and similar URLs. * Remove Asset Version Query Strings – Strip ?ver= from front-end CSS/JS (can break cache busting; prefer CDN purge or hashed filenames). * Post Revisions Limit – Cap stored revisions per post. * Auto-save Interval – Change how often the editor auto-saves. * Trash Auto-Delete – Set trash retention; expired items are removed in batches so large queues stay memory-safe. * Convert Uploads to WebP – Convert JPEG/PNG to WebP on upload, optional max size resize, then remove the original (GD or Imagick with WebP; uses unique filenames and refuses unsafe overwrites). * Heartbeat API Control – Tune or disable Heartbeat in admin, front end, and the post editor. Security: * Hide Generator Tags – Remove WordPress (and WooCommerce, when active) version meta tags. * Disable XML-RPC – Respond to XML-RPC with 404 and remove RSD discovery. * Disable Trackback/Pingback – Close pings and strip pingback methods/headers. * Disable File Editor – Set DISALLOW_FILE_EDIT so theme/plugin editors stay off. * Automatic Updates Control – Tri-state plugin, theme, translation, and core updates; reschedule update checks. Respects AUTOMATIC_UPDATER_DISABLED and WP_AUTO_UPDATE_CORE when defined. * Login Error Messages – Generic login errors to reduce username enumeration. * Restrict Admin Access – Choose which roles may open wp-admin UI. Users with manage_options always keep access. Front-end admin-ajax.php is intentionally not blocked. * REST API Restrictions – Limit selected core REST routes to users with manage_options. * Login Limit – Rate-limit failed logins by IP and IP+username pair (REMOTE_ADDR only). Optional IP whitelist (one address per line). Covers wp-login.php and other wp_signon() paths (including WooCommerce). * Verified Upload – Block disguised uploads: double extensions, MIME/magic mismatches, and script markers. Visual: * Hide Admin Bar – Hide the admin bar for selected roles. * Block Visibility (Mobile) – Show/hide blocks by device via wp_is_mobile(); sends Vary: User-Agent (full-page caches must honour it). * Login Page Customization – Brand wp-login.php with logo and colours. Email: * Email Notifications – Disable or redirect selected WordPress system emails. * Email sending – SMTP with encrypted password storage, or disable all site emails. In production, disabling TLS/certificate verification is blocked. Miscellaneous: * Disable Comments – Site-wide comments off (optional WooCommerce review keep). * External Links in New Window – Open external links in a new tab with safe rel attributes. * Enable Page Excerpt – Excerpt support for pages. * Clean Upload Filenames – Sanitize upload filenames (accents, spaces, special characters). * SVG Upload – Role-gated SVG uploads with allowlist-based sanitization (XXE-safe parse). * AVIF Upload – Role-gated AVIF uploads (full core AVIF support needs WordPress 6.5+). * Role Redirects – Per-role login and logout redirect URLs. * Maintenance Mode – 503 maintenance page for guests; chosen roles keep access. Admin, AJAX, and cron stay available so staff can work. * Dynamic Year Shortcodes – [refi-year] and [refi-year from="2006"]. More plugins: rotistudio.com Author site: rottenbacher.hu GitHub: github.com/rotisoft/refitune Translations English (default – source strings in code and refitune.pot) Hungarian (Magyar) – refitune-hu_HU.po (compile to .mo for WordPress to load) Contribute translations under /wp-content/plugins/refitune/languages/. Text Domain: refitune.
Top keywords
- disable11×1.82%
- login6×0.99%
- upload6×0.99%
- wordpress6×0.99%
- admin5×0.83%
- refitune5×0.83%
- remove5×0.83%
- uploads5×0.83%
- core4×0.66%
- filenames4×0.66%
- hide4×0.66%
- wp4×0.66%
Site Speed Test – SpeedGuard
Track Core Web Vitals for the entire website and for individual URLs. Mobile and Desktop. Every day. Automatically. For free. No need to guess whether your website performance needs your attention or not – you will get the definite answer in your WordPress Dashboard in a few minutes. With SpeedGuard you get: Core Web Vitals (LCP, CLS, INP) testing for individual URLs of your website PageSpeed Insights (LCP, CLS) for the cases if your website doesn’t have Core Web Vitals yet automatic everyday monitoring both desktop and mobile testing links to the Google PageSpeed Insights reports (that include CWV on top as well) which you can pass to the performance engineer to improve your site speed tests are completely automated — you don’t need to do anything easy to use — just pick pages of your website that you would like to monitor It’s free 🙂 Test performance of any content in WordPress : Posts Pages Events WooCommerce Products any other Custom Post Type Archives Categories Tags any other Custom Taxonomy Idea Behind There is no need to say that performance IS very important. What’s also important — is to understand whether you have to worry about your website performance or it’s doing fine. Google Core Web Vitals are the metrics that Google uses to measure the user experience on the web (real user experience!). If your website passes CWV assessment for Origin — it means that your website is fast enough for the majority of users. If it doesn’t pass — it means that you have to fix this. If it does pass but quite a few specific URLs are not passing — it’s a good time to look into those URLs and improve them to prevent the entrire webstie to be marked as failing CWV. I wanted a simple easy-to-use tool to warn me in case my clients’ websites performance has a bad tendency and needs my attention. I wanted a native WordPress solution, with all information available from the dashboard, simple but still informative, a guard who will do the monitoring every day and ping me, in case something goes wrong. I have not found one and that’s why I’ve built this plugin. I’ll be happy to know that you find it useful as well — please, leave a review. P.S. Note about PageSpeed Insights: you SHOULD always use CWV data in case it is available for your website. In case it is not available (when the website is new and/or doesn’t have enough traffic yet) — use PageSpeed Insights. But you have to remember, that PSI — are lab tests, it’s just an emulation of real users experience. It’s better than nothing, of course. Watch my talk here if you want to understand Core Web Vitals Mystery better.
Top keywords
- website10×2.15%
- performance6×