RefiTune Ìtumọ̀ Yorùbá: – Site refiner toolkit

Àpèjúwe

Hungarian: Magyar nyelvű bővítmény leírás

RefiTune Ìtumọ̀ Yorùbá: – Site refiner toolkit is a modular Swiss Army knife for WordPress. Clean up unnecessary front-end code, harden login and uploads, tune Heartbeat and updates, or brand wp-login Ìtumọ̀ Yorùbá: – each module is opt-in.

Enable or disable features individually. A clean dashboard shows what is active. In-plugin Help pages document behaviour, trade-offs, and requirements.

WhatÌtumọ̀ Yorùbá: ’s Inside? (37 Modules)

Performance:
* Header Cleanup Ìtumọ̀ Yorùbá: – Strip unnecessary wp_head output for leaner pages.
* Feed Management Ìtumọ̀ Yorùbá: – Control RSS/Atom feed link tags in the document head.
* Disable Emoji Ìtumọ̀ Yorùbá: – Remove WordPress emoji scripts and styles.
* Disable jQuery Migrate Ìtumọ̀ Yorùbá: – Drop legacy jquery-migrate when your stack does not need it.
* Disable oEmbed Ìtumọ̀ Yorùbá: – Stop automatic embeds from pasted YouTube, Vimeo, Twitter/X, and similar URLs.
* Remove Asset Version Query Strings Ìtumọ̀ Yorùbá: – Strip ?ver= from front-end CSS/JS (can break cache busting; prefer CDN purge or hashed filenames). Locked when WP_CACHE is true in wp-config.php.
* Post Revisions Limit Ìtumọ̀ Yorùbá: – Cap stored revisions per post. Locked when WP_POST_REVISIONS is defined in wp-config.php.
* Auto-save Interval Ìtumọ̀ Yorùbá: – Change how often the editor auto-saves. Locked when AUTOSAVE_INTERVAL is defined in wp-config.php.
* Trash Auto-Delete Ìtumọ̀ Yorùbá: – Set trash retention; expired items are removed in batches so large queues stay memory-safe. Locked when EMPTY_TRASH_DAYS is defined in wp-config.php.
* Convert Uploads to WebP Ìtumọ̀ Yorùbá: – Convert JPEG/PNG to WebP on upload, optional max size resize, then remove the original (GD or Imagick with WebP; uses unique filenames and refuses unsafe overwrites).
* Heartbeat API Control Ìtumọ̀ Yorùbá: – Tune or disable Heartbeat in admin, front end, and the post editor.
* Resource Preload Ìtumọ̀ Yorùbá: – Add early link rel="preload" hints for internal site assets by location (everywhere, front page, blog, or post ID), with as, type, crossorigin, and fetchpriority. Optional one-click import of active WordPress Font Library fonts (AJAX on demand).

Security:
* Hide Generator Tags Ìtumọ̀ Yorùbá: – Remove WordPress (and WooCommerce, when active) version meta tags.
* Disable XML-RPC Ìtumọ̀ Yorùbá: – Respond to XML-RPC with 404 and remove RSD discovery.
* Disable Trackback/Pingback Ìtumọ̀ Yorùbá: – Close pings and strip pingback methods/headers.
* Disable File Editor Ìtumọ̀ Yorùbá: – Set DISALLOW_FILE_EDIT so theme/plugin editors stay off. Locked in the UI when the constant is already defined in wp-config.php.
* Automatic Updates Control Ìtumọ̀ Yorùbá: – Tri-state plugin, theme, translation, and core updates; reschedule update checks. Respects AUTOMATIC_UPDATER_DISABLED (full lock) and WP_AUTO_UPDATE_CORE (core-only; plugins/themes/translations and update checks stay configurable).
* Login Error Messages Ìtumọ̀ Yorùbá: – Generic login errors to reduce username enumeration.
* Restrict Admin Access Ìtumọ̀ Yorùbá: – Choose which roles may open wp-admin UI. Users with manage_options always keep access. Front-end admin-ajax.php is intentionally not blocked.
* REST API Restrictions Ìtumọ̀ Yorùbá: – Limit selected core REST routes to users with manage_options.
* Login Limit Ìtumọ̀ Yorùbá: – Rate-limit failed logins by IP and IP+username pair (REMOTE_ADDR only). Optional IP whitelist (one address per line). Covers wp-login.php and other wp_signon() paths (including WooCommerce).
* Verified Upload Ìtumọ̀ Yorùbá: – Block disguised uploads: double extensions, MIME/magic mismatches, and script markers.

Visual:
* Hide Admin Bar Ìtumọ̀ Yorùbá: – Hide the admin bar for selected roles.
* Block Visibility (Mobile) Ìtumọ̀ Yorùbá: – Per-block always / mobile-only / desktop-only via wp_is_mobile(); omits HTML server-side; sends Vary: User-Agent (full-page caches must honour it). Also available in the core Hide block modal.
* Block Visibility (Roles) Ìtumọ̀ Yorùbá: – Per-block visibility for guests, logged-in users, or selected roles; omits HTML server-side. Shares the Visibility panel and Hide block modal with the mobile module.
* Login Page Customization Ìtumọ̀ Yorùbá: – Brand wp-login.php with logo and colours.

Email:
* Email Notifications Ìtumọ̀ Yorùbá: – Disable or redirect selected WordPress system emails.
* Email sending Ìtumọ̀ Yorùbá: – SMTP with encrypted password storage, or disable all site emails. In production, disabling TLS/certificate verification is blocked.

Miscellaneous:
* Disable Comments Ìtumọ̀ Yorùbá: – Site-wide comments off (optional WooCommerce review keep).
* External Links in New Window Ìtumọ̀ Yorùbá: – Open external links in a new tab with safe rel attributes.
* Enable Page Excerpt Ìtumọ̀ Yorùbá: – Excerpt support for pages.
* Clean Upload Filenames Ìtumọ̀ Yorùbá: – Sanitize upload filenames (accents, spaces, special characters).
* SVG Upload Ìtumọ̀ Yorùbá: – Role-gated SVG uploads with allowlist-based sanitization (XXE-safe parse).
* AVIF Upload Ìtumọ̀ Yorùbá: – Role-gated AVIF uploads (full core AVIF support needs WordPress 6.5+).
* Role Redirects Ìtumọ̀ Yorùbá: – Per-role login and logout redirect URLs.
* Maintenance Mode Ìtumọ̀ Yorùbá: – 503 maintenance page for guests; chosen roles keep access. Admin, AJAX, and cron stay available so staff can work.
* Dynamic Year Shortcodes Ìtumọ̀ Yorùbá: – [refi-year] and [refi-year from="2006"].

More plugins: rotistudio.com
Author site: rottenbacher.hu
GitHub: github.com/rotisoft/refitune

Translations

  • English (default Ìtumọ̀ Yorùbá: – source strings in code and refitune.pot)
  • Hungarian (Magyar) Ìtumọ̀ Yorùbá: – refitune-hu_HU.po (compile to .mo for WordPress to load)

Contribute translations under /wp-content/plugins/refitune/languages/. Text Domain: refitune.

Àwọn àwòrán ìbòjú

Ìgbéwọlẹ̀

  1. Upload to /wp-content/plugins/refitune (or install from WordPress.org).
  2. Activate under Plugins.
  3. Open Tools > RefiTune Toolkit and enable the modules you need.
  4. Use the Help tab for per-feature documentation.

FAQ

Will this plugin slow down my site?

No. Most modules remove unused front-end work or add checks only on login/upload. Features are opt-in.

Is it safe to disable jQuery Migrate?

Only if your theme and plugins work with current jQuery. Test first; leave it off when unsure.

What happens if I disable XML-RPC?

The WordPress mobile app, Jetpack sync, and other remote clients that need XML-RPC may stop working.

How does Login Limit identify clients?

It uses REMOTE_ADDR only (not spoofable X-Forwarded-For). Failed attempts are counted per IP and per IP+username pair. Add static office or trusted egress IPs to the whitelist (one per line). Behind a CDN or shared NAT, many visitors share one address Ìtumọ̀ Yorùbá: – whitelist only IPs you control.

Does Login Limit work with email logins and WooCommerce?

Yes. Email logins are canonicalized to usernames where possible, and lockouts are checked on authenticate so wp_signon() paths (including WooCommerce) are covered.

Can I hide wp-admin from certain roles?

Yes. Restrict Admin Access limits the wp-admin UI by role. Anyone with manage_options always retains access. AJAX is not blocked so front-end admin-ajax.php callbacks keep working; each handler must still check capabilities.

WhatÌtumọ̀ Yorùbá: ’s Maintenance Mode good for?

Short downtime windows. Guests get a 503 page; selected roles still browse. Admin, AJAX, and cron remain available so developers can test plugins that need those endpoints.

Can wp-config.php override Automatic Updates Control?

Yes. AUTOMATIC_UPDATER_DISABLED locks the entire feature (all update types and check frequency). WP_AUTO_UPDATE_CORE only locks core auto-updates (true, false, or 'minor') and shows the matching enable/disable state in the UI; plugin, theme, and translation controls and “Check for updates” stay editable. Setting core auto-updates to false is treated as a high-risk configuration and shown with a clear danger notice.

What does “Enable all” mean for plugins and themes?

It forces automatic updates for every plugin or theme and overrides per-item toggles on the Updates screen. “Disable all” blocks them; “WordPress default” leaves native behaviour unchanged.

Is SMTP test mode safe on production?

No. While WP_ENVIRONMENT_TYPE is production, RefiTune will not run without encryption/certificate verification, and the test-mode checkbox cannot be enabled. Set the environment type correctly on live sites.

Àwọn àgbéyẹ̀wò

Òkúdù 6, 2026 1 ìdáhùn
A Wordpress egy jó CMS rendszer, de az alap telepítésből hiányozik pár dolog amiknek alapnak kellene lenni már. Ez a bővítmény pont ezeket a hiányosságokat tölti ki. Nagyon sok apró plugint megspórolhatunk ennek az egy bővítménynek a telepítésével.
Ka gbogbo àgbéyẹ̀wò 1

Àwọn Olùkópa & Olùgbéejáde

“RefiTune Ìtumọ̀ Yorùbá: – Site refiner toolkit” jẹ́ ètò ìṣàmúlò orísun ṣíṣí sílẹ̀. Àwọn ènìyàn wọ̀nyí ti ṣe ìkópa sí plugin yìí.

Àwọn Olùkópa

A ti túmọ̀ “RefiTune Ìtumọ̀ Yorùbá: – Site refiner toolkit” sí èdè agbègbè 1 kan. Ọpẹ́lọpẹ́ fún àwọn atúmọ̀ èdè fún àwọn ìkópa wọn.

Túmọ̀ “RefiTune Ìtumọ̀ Yorùbá: – Site refiner toolkit” sí èdè rẹ.

Ṣe o nífẹ̀ẹ́ sí ìdàgbàsókè?

Ṣàwárí koodu, ṣàyẹ̀wò ibi ìpamọ́ SVN, tàbí ṣe àgbékalẹ̀ sí àkọsílẹ̀ ìdàgbàsókè nípasẹ̀ RSS.

Àkọsílẹ̀ àwọn àyípadà

1.4.0

  • New: Resource Preload Ìtumọ̀ Yorùbá: – internal-URL link rel="preload" hints by location, with as/type/crossorigin/fetchpriority
  • New: Resource Preload Ìtumọ̀ Yorùbá: – import active fonts from Font Library
  • New: Block Visibility (Roles) Ìtumọ̀ Yorùbá: – show blocks to guests, logged-in users, or selected roles; shared Visibility panel and Hide block modal
  • Enhancement: Block Visibility (Mobile) available on all supported WordPress versions; controls also appear in the core Hide block modal
  • Enhancement: wp-config awareness for Post Revisions, Autosave, Trash, Automatic Updates, Disable File Editor, Automatic Updates Control and Remove Asset Versions
  • Enhancement: Core auto-update selectors include short plain-language descriptions (minor / major / development)
  • Fix: Palette PNG-8 (indexed) uploads convert to WebP correctly instead of producing an empty image

1.3.1

  • Minor language file fixes.

1.3.0

  • New: Convert Uploads to WebP (JPEG/PNG), optional resize, original removal when conversion succeeds
  • Security: WebP conversion uses unique filenames and refuses unsafe overwrites; source deleted only after a valid WebP
  • Security: Login Limit uses IP and IP+username pair lockouts (no global per-user lockout); atomic counters; REMOTE_ADDR only; IP whitelist (one per line)
  • Security: Restrict Admin Access always allows manage_options; documents intentional AJAX skip for front-end callbacks
  • Security: SVG sanitizer limits (size/nodes/depth), safer href/style rules; SMTP fail-closed in production for test mode
  • Security: Multisite network upload MIME settings respected for SVG, AVIF, and WebP conversion
  • Fix: WooCommerce-aware load order for comment and head cleanup modules
  • Fix: Trash auto-delete runs in batches and clears schedule on deactivate
  • Fix: Block Visibility sends Vary: User-Agent; asset ?ver= removal warnings clarified
  • Fix: Uninstall cleanup per site on multisite; removes leftover login-limit transients when data deletion is enabled
  • Docs: Help and settings copy for Login Limit, Admin Access, WebP, AVIF, REST labels; Hungarian .po updated
  • Docs: Replaced typographic en/em dashes with ASCII hyphens in admin UI strings, Help text, and language files (.pot / .po)

1.2.2

  • Security: stricter REST restrictions, SVG sanitizer hardening, admin capability checks
  • Fix: Maintenance Mode REST 503; update-check cron restore; Heartbeat/login-limit/email/upload fixes
  • Performance: update-check reschedule limited to admin/cron; auto-updates notice scoped
  • Code quality: shared settings helper, explicit hook priorities; minimum WordPress 6.2

1.2.1

  • Fix: Verified Upload no longer blocks legitimate JPEG/PNG uploads

1.2.0

  • New: Automatic Updates Control, Remove Asset Version Query Strings, Verified Upload, Clean Upload Filenames, Disable oEmbed
  • Fix: Plugin Check compatibility; Media Library / SVG sanitization conflict

1.1.0

  • Security: Safer redirects, SVG sanitization, REST restrictions, SMTP credentials
  • Refactor: Modular settings sanitization

1.0.0

  • Initial release
  • WordPress 7.0 and PHP 8.5 compatibility check