RefiTune – Site refiner toolkit
Hungarian: Magyar nyelvű bővítmény leírás RefiTune – Site refiner toolkit is a modular Swiss Army knife for WordPress. Clean up unnecessary front-end code, harden login and uploads, tune Heartbeat and updates, or brand wp-login – each module is opt-in. Enable or disable features individually. A clean dashboard shows what is active. In-plugin Help pages document behaviour, trade-offs, and requirements. What’s Inside? (35 Modules) Performance: * Header Cleanup – Strip unnecessary wp_head output for leaner pages. * Feed Management – Control RSS/Atom feed link tags in the document head. * Disable Emoji – Remove WordPress emoji scripts and styles. * Disable jQuery Migrate – Drop legacy jquery-migrate when your stack does not need it. * Disable oEmbed – Stop automatic embeds from pasted YouTube, Vimeo, Twitter/X, and similar URLs. * Remove Asset Version Query Strings – Strip ?ver= from front-end CSS/JS (can break cache busting; prefer CDN purge or hashed filenames). * Post Revisions Limit – Cap stored revisions per post. * Auto-save Interval – Change how often the editor auto-saves. * Trash Auto-Delete – Set trash retention; expired items are removed in batches so large queues stay memory-safe. * Convert Uploads to WebP – Convert JPEG/PNG to WebP on upload, optional max size resize, then remove the original (GD or Imagick with WebP; uses unique filenames and refuses unsafe overwrites). * Heartbeat API Control – Tune or disable Heartbeat in admin, front end, and the post editor. Security: * Hide Generator Tags – Remove WordPress (and WooCommerce, when active) version meta tags. * Disable XML-RPC – Respond to XML-RPC with 404 and remove RSD discovery. * Disable Trackback/Pingback – Close pings and strip pingback methods/headers. * Disable File Editor – Set DISALLOW_FILE_EDIT so theme/plugin editors stay off. * Automatic Updates Control – Tri-state plugin, theme, translation, and core updates; reschedule update checks. Respects AUTOMATIC_UPDATER_DISABLED and WP_AUTO_UPDATE_CORE when defined. * Login Error Messages – Generic login errors to reduce username enumeration. * Restrict Admin Access – Choose which roles may open wp-admin UI. Users with manage_options always keep access. Front-end admin-ajax.php is intentionally not blocked. * REST API Restrictions – Limit selected core REST routes to users with manage_options. * Login Limit – Rate-limit failed logins by IP and IP+username pair (REMOTE_ADDR only). Optional IP whitelist (one address per line). Covers wp-login.php and other wp_signon() paths (including WooCommerce). * Verified Upload – Block disguised uploads: double extensions, MIME/magic mismatches, and script markers. Visual: * Hide Admin Bar – Hide the admin bar for selected roles. * Block Visibility (Mobile) – Show/hide blocks by device via wp_is_mobile(); sends Vary: User-Agent (full-page caches must honour it). * Login Page Customization – Brand wp-login.php with logo and colours. Email: * Email Notifications – Disable or redirect selected WordPress system emails. * Email sending – SMTP with encrypted password storage, or disable all site emails. In production, disabling TLS/certificate verification is blocked. Miscellaneous: * Disable Comments – Site-wide comments off (optional WooCommerce review keep). * External Links in New Window – Open external links in a new tab with safe rel attributes. * Enable Page Excerpt – Excerpt support for pages. * Clean Upload Filenames – Sanitize upload filenames (accents, spaces, special characters). * SVG Upload – Role-gated SVG uploads with allowlist-based sanitization (XXE-safe parse). * AVIF Upload – Role-gated AVIF uploads (full core AVIF support needs WordPress 6.5+). * Role Redirects – Per-role login and logout redirect URLs. * Maintenance Mode – 503 maintenance page for guests; chosen roles keep access. Admin, AJAX, and cron stay available so staff can work. * Dynamic Year Shortcodes – [refi-year] and [refi-year from="2006"]. More plugins: rotistudio.com Author site: rottenbacher.hu GitHub: github.com/rotisoft/refitune Translations English (default – source strings in code and refitune.pot) Hungarian (Magyar) – refitune-hu_HU.po (compile to .mo for WordPress to load) Contribute translations under /wp-content/plugins/refitune/languages/. Text Domain: refitune.
Top keywords
- disable11×1.82%
- login6×0.99%
- upload6×0.99%
- wordpress6×0.99%
- admin5×0.83%
- refitune5×0.83%
- remove5×0.83%
- uploads5×0.83%
- core4×0.66%
- filenames4×0.66%
- hide4×0.66%
- wp4×0.66%
DietPress
DietPress is a free WordPress speed optimization plugin with a built-in page cache. Page caching, browser caching, GZIP and Brotli compression, deferred JavaScript, critical CSS, image loading attributes, preloading, locally hosted Google Fonts and selective asset loading, all in one plugin and all free. And it goes further than a caching plugin: it also puts WordPress itself on a diet, switching off the features your site never uses. It pairs that with a clean, risk-based interface. Everything is configurable, the optimizations are already on by default, and nothing is hidden behind a paid tier. Activate it and your site is faster, or open the settings and tune every detail. By default WordPress loads functions, services and scripts that most sites do not need. They slow down loading times and consume hosting resources. DietPress lets you trim that fat and apply battle-tested performance tweaks, with a clear description of what each option does and what might break, organized by risk level so you always know what is safe. WHY CHOOSE DIETPRESS Page caching, for free. Serve anonymous visitors a copy stored on disk instead of building the page again. The feature people buy WP Rocket or a NitroPack subscription for, with no licence and no monthly fee. No drop-in, no changes to wp-config.php. Unlike WP Super Cache or W3 Total Cache, DietPress installs no advanced-cache.php and never edits wp-config.php. Switching it off leaves your site exactly as it was, with nothing orphaned behind. It tells you why. Most cache plugins leave you guessing when nothing is cached. DietPress reports its own status, tests itself against your home page, and names the exact reason a page was skipped. WooCommerce-safe by design. Carts, checkout, my account and any visitor carrying a cart cookie always get the live site, so nobody ever sees somebody else’s basket. Diet as well as speed. Where Perfmatters focuses on disabling scripts, DietPress covers that ground and adds page caching, critical CSS, local Google Fonts and a dashboard, admin and email cleanup, in one plugin. Light on your server. No account, no external service, no telemetry, no upsell nags. Everything runs on your own hosting. WHAT THE PAGE CACHE DOES TO YOUR RESPONSE TIME Measured on a WordPress 7.0 install with GeneratePress, WooCommerce and a 76 product catalogue, PHP 8.5, taking the median of 15 requests per URL. Your own hosting will give different figures, but the shape of the result will not change. Server response time, the same pages with the page cache off and on: Home page – 52.7 ms without, 15.1 ms with, 71% faster WooCommerce shop – 45.4 ms without, 14.8 ms with, 67% faster A 110 KB article – 43.0 ms without, 15.1 ms with, 65% faster A 98 KB page – 41.0 ms without, 14.9 ms with, 64% faster A product category – 41.3 ms without, 15.1 ms with, 63% faster The interesting part is not the percentage, it is that the cached figure barely moves. Serving a stored file costs the same whether the page was cheap or expensive to build, so the saving grows with the size of your site rather than with the power of your server. The heaviest page in the test is the one that gained most. It also changes how much traffic your hosting can take at once. In the same test the server went from serving about 40 visits a second to more than 210, five times as many, on exactly the same plan. That is what keeps a small site standing up when one of your posts does well. TWO THINGS IN ONE PLUGIN 1. Performance optimizations (on by default) Automatic Critical CSS inlined in the head (optional experimental deferral of non-critical CSS) JavaScript defer parsing with smart dependency handling Image loading attributes safety net: lazy loading, decoding=async and fetchpriority for images that bypass core Automatic image dimensions for better CLS scores (including picture elements) Resource hints: preconnect and DNS prefetch for common third-party origins Theme stylesheet, critical fonts and logo preloading for a faster LCP Google Fonts display=swap Google Fonts local hosting: serve the fonts your theme uses from your own server, GDPR-friendly with a silent fallback to the Google CDN (opt-in) Selective third-party loading: WooCommerce, Contact Form 7, block library, Slider Revolution, TablePress, Smash Balloon, Formidable Forms and Everest Forms assets only load where they are used (opt-in) RSS feed optimization (cache headers and item limit) Server rules in .htaccess: browser caching with a configurable lifetime for media, for styles and scripts and for fonts, GZIP and Brotli compression, immutable cache headers, CORS for fonts and keep-alive (master switch plus per-feature toggles) Database maintenance: daily expired-transient cleanup and safe query optimizations Page cache: store each page on disk and serve it to anonymous visitors without building it again, with automatic purging, gzip precompression and a status panel that says whether it is working (opt-in, in its own tab) 2. Put WordPress on a diet (risk-based, opt-in) Light (safe for any site): emojis, RSD/WLW tags, shortlinks, self-pingbacks, comment pagination, and more Moderate (evaluate first): oEmbed, jQuery Migrate, Dashicons on the frontend, Global Styles and Duotone, remote block patterns, avatars and Gravatar, comment threading, and more Strict (site-specific): granular RSS feed control, Heartbeat API mode, post revisions and autosave, disable comments, XML sitemap, native lazy loading/fetchpriority, content types, selective loading for WooCommerce, Contact Form 7, block assets, Slider Revolution, TablePress, Smash Balloon, Formidable Forms and Everest Forms, and more Widgets: dashboard widgets (including third-party ones from Yoast, WooCommerce, Elementor, Jetpack, Wordfence, Rank Math, Gravity Forms), classic sidebar widgets, block-editor widgets and the Customizer Emails: silence the automatic emails WordPress sends on its own, grouped by area: auto-update results for core, plugins and themes (plus the new-version notice), comment moderation and new-comment notices, and new user, password and email-change notices, plus toggles for the admin email verification prompt and post-by-email. Every option is off by default, and critical notices such as a failed core update are always kept SCALE, PROFILES AND ANALYZER Savings indicator: HTTP requests removed, CSS/JS saved and active optimizations at a glance Quick profiles: Personal Blog, WooCommerce Store, Landing Page and Maximum Cleanup Site analyzer: personalized recommendations based on your active plugins and content, page cache included Import and export your whole configuration as a JSON file COMPATIBILITY AND EXTENSIBILITY The plugin includes filters for developers: dietpress_critical_css – Customize the inline critical CSS dietpress_critical_css_handles – Define which CSS handles are critical dietpress_skip_defer_script_handles – Opt scripts out of the JavaScript defer dietpress_skip_defer_style_handles – Opt stylesheets out of the CSS deferral dietpress_preconnect_hints – Customize preconnect origins dietpress_dns_prefetch_domains – Customize DNS prefetch domains dietpress_critical_fonts – Define critical fonts to preload dietpress_exclude_local_fonts – Exclude Google Fonts stylesheets from local hosting dietpress_selective_{module}_has_content – Mark a page as showing the content of a selective loading module, so its assets are kept. The module is wc, cf7, formidable, everest_forms or revslider dietpress_selective_{module}_styles / dietpress_selective_{module}_scripts – Adjust the handles removed by each module dietpress_selective_page_hides_content – Mark a page as rendering content the content scan cannot reach, so no module removes anything (this is what handles Elementor) dietpress_selective_is_wc_page – Override the WooCommerce page detection of selective loading dietpress_selective_wc_keep_cart_fragments – Keep the cart fragments script when your theme has a hand-coded mini-cart dietpress_selective_cf7_has_form – Mark pages that load a Contact Form 7 form dynamically dietpress_selective_blocks_dequeue – Override the block library dequeue decision dietpress_selective_everest_forms_dequeue_dashicons – Keep Dashicons when another plugin enqueues it directly dietpress_native_sitemap_in_use – Tell DietPress your plugin builds on the native WordPress sitemap, so the option that removes it becomes unavailable dietpress_cache_bypass – Keep the current page out of the page cache dietpress_cache_bypass_cookies – Adjust the cookie name prefixes that make a visitor uncacheable dietpress_cache_ignored_params – Adjust the query parameters that do not change the page dietpress_cache_exclude_urls – Adjust the excluded URL patterns dietpress_cache_post_urls – Adjust the URLs purged along with a post Compatible with: Well-coded themes and page builders (Divi, Elementor, Beaver Builder, Bricks Gutenberg) Cache plugins (WP Rocket, LiteSpeed Cache, W3 Total Cache, WP Super Cache, etc.). The one exception is the optional page cache module, which will not run beside another page cache and says so; everything else in DietPress works alongside them as it always has Security plugins (DietPress focuses on performance and deliberately leaves security to them; we recommend our free Vigilant) CDNs (Cloudflare, StackPath, KeyCDN, etc.) thanks to CORS and Vary headers WordPress Multisite (except the optional page cache module, which does not support it yet) HOW TO VERIFY THE OPTIMIZATIONS Cache rules: check your .htaccess for a block marked # BEGIN DietPress with immutable Cache-Control headers Logo preload: view page source and look for pointing to your logo Critical CSS: view source and look for in the head Compression: test at giftofspeed.com/gzip-test Always measure with tools like Google PageSpeed, GTMetrix or WebPageTest, and run each test at least twice to account for caching. Support Need private support or custom development? Do you need one-on-one help, priority troubleshooting, or a custom feature, integration, or tweak built specifically for your site? I offer private support and custom development. Just contact me and tell me what you need. Need help or have suggestions? Official website WordPress support forum YouTube channel Documentation and tutorials Love the plugin? Please leave us a 5-star review and help spread the word! About AyudaWP We are specialists in WordPress security, SEO, AI and performance optimization plugins. We create tools that solve real problems for WordPress site owners while maintaining the highest coding standards and accessibility requirements.