All-in-one WordPress optimization toolkit with 19 modules for performance, security, SEO, and content management. Built with modern WordPress coding standards and a clean module-based dashboard. Optimized for performance with modular initialization, static property caching, and intelligent transients.
Version: 1.7.0
Requires WordPress: 6.3 or later (tested up to 7.1)
Requires PHP: 7.4 or later
License: GPL-2.0-or-later
Text Domain: functionalities
Pricing: Free
- Download: Get the latest production-ready ZIP file from GitHub Releases.
- Upload: In your WordPress admin, go to Plugins > Add New > Upload Plugin and select the downloaded file.
- Activate: Activate the plugin through the Plugins menu in WordPress.
- Setup: Navigate to the new Functionalities menu item to enable and configure your modules.
Alternatively, you can manually copy the functionalities/ folder into wp-content/plugins/.
All modules are accessed through a unified dashboard at wp-admin/admin.php?page=functionalities. Click any module card to configure its settings.
Link Health shows live scan activity, a progress bar, checked-link counts, and 50 results per page across all scanned sources. Filter by result, source type, or URL/source-title text; CSV export uses the same filters. Preview and replace or unlink matching URLs in an individual source post, with revision support and concurrent-save protection. Keep its workspace open for continuous bounded checking; Stop finishes the current batch and Resume continues from saved progress. See live scan verification.
The admin sidebar and dashboard use a simplified vector version of the Functionalities mark that follows WordPress's UI colors. Individual module pages show their own icon, a Back to modules button, and complete breadcrumbs. Settings and module guidance use a responsive grid, with guidance in the right sidebar on wide screens and below settings on smaller screens. Module/action icons are bundled Tabler outline SVGs with their MIT license. Backend controls share consistent spacing, sizing, focus states, and accessible labels, including responsive font and PWA repeaters. See UI verification and sidebar verification.
Full documentation is at functionalities.dev:
| Getting started | Install, enable a module, verify it works |
| Module reference | What each of the 19 modules does |
| Dashboard | Working with the module dashboard |
| Hooks | Every action and filter the plugin fires |
| API reference | Extending the plugin in code |
| FAQ | Common questions |
| Downloads | Current and previous releases |
Per-module guides: Link Management · Redirect Manager · Login Security · Performance & Cleanup · Schema · Snippets · SVG Icons · Block Cleanup · Content Integrity · Assumption Detection · Task Manager
See the public roadmap for planned fixes and features.
This plugin is built with a "Performance First" philosophy. Unlike many all-in-one plugins that slow down your site, Functionalities is designed to be as lightweight as possible:
- Modular Initialization: Each module checks its enabled state before registering its feature hooks. Disabled modules add no frontend assets or feature behavior.
- Minimized Database Load: All module settings are cached in static properties. This ensures that
get_option()is called at most once per module per request, regardless of how many times a feature is accessed. - Zero Frontend Bloat: Most modules are "Zero Footprint" on the frontend, meaning they load no CSS or JS unless explicitly required (like the Components or Fonts modules).
- Intelligent Filtering: Content filters (
the_content, etc.) usestrpos()fast-exit checks. If the specific markers or tags for a feature aren't present in your content, the plugin exits immediately without running expensive parsing. - Efficient HTML Processing: Since 1.6.0, Link Management, Block Cleanup, and Schema use the WordPress HTML API (
WP_HTML_Tag_Processor) to edit attributes in place. Nothing is reserialized, so Vue, Alpine, and mustache templates survive untouched and no framework skip guard is needed. - Aggressive Caching: Heavy operations—such as reading JSON exception lists, calculating file hashes, or managing redirects—are cached using WordPress Transients or versioned options to minimize Disk I/O.
Adds Duplicate as draft to native post/page row actions. The new draft belongs to the current user and preserves stored block content, excerpt, taxonomies, featured image, and page template. Source identity, publication state, comments, revisions, edit locks, and scan metadata are excluded. Copying additional metadata requires the functionalities_content_tools_meta_keys allowlist filter and the corresponding metadata permissions. A failed copy removes the partial draft.
Checks anchor links in stored public, published posts/pages in small resumable batches. Duplicate destinations share expiring results. Safe HEAD requests use bounded GET confirmation before marking 404/410 as broken; authentication errors, rate limits, transport failures, and server errors remain inconclusive. Redirect hops are validated individually.
The workspace provides manual start/resume/stop, per-link ignore/recheck, source editing links, paginated reports, and CSV export. Weekly scans are separately opt-in and use WP-Cron. Reports mark content changes, partial scans, and the 1,000 unique links per post limit. Password-protected content, dynamic output, shortcodes, and navigation are excluded. Scans never rewrite content. Results are stored in post metadata, URL checks in expiring transients, and the worker cursor in protected atomic storage.
Stores a private history of module-setting field changes, post/page status transitions, and plugin/theme changes. Entries include actor ID, event, target, and timestamp. Setting values, snippet bodies, content, passwords, tokens, visitor IPs, and request data are excluded. The workspace supports search, event/actor filters, pagination, and explicit clearing.
History is bounded to 1,000 entries and 30 days, with daily pruning. WordPress privacy export/erasure and user deletion anonymize actor references, including when recording is disabled. Logging failures leave the underlying site operation intact.
All three modules are disabled by default and follow the existing uninstall retention preference.
Complete external link control with nofollow automation.
Features:
- Automatic
rel="nofollow"for external links (priority 999) - Applies to content, widgets, and comments
- Exception lists: full URLs, domains, or partial matches
- JSON preset file support for bulk exceptions
- Database update tool for bulk nofollow addition
- Open external/internal links in new tab
- Pattern-based domain matching
- Zero frontend footprint (no CSS/JS)
Navigate to: ?page=functionalities&module=link-management
Strip common wp-block classes from frontend output (.wp-block-heading, .wp-block-list, .wp-block-image). Cleaner HTML markup without the bloat.
Navigate to: ?page=functionalities&module=block-cleanup
Limit link suggestions to selected post types in the block editor. Reduces clutter in link search dialogs.
Navigate to: ?page=functionalities&module=editor-links
Fine-grained control over WordPress default behaviors and performance tweaks:
- Disable emojis scripts/styles
- Disable embeds (oEmbed)
- Remove REST API and oEmbed discovery links
- Remove RSD, WLWManifest, shortlink tags
- Remove WordPress version meta
- Disable XML-RPC (complete or pingbacks only)
- Disable RSS/Atom feeds
- Disable Gravatars
- Disable self-pingbacks
- Remove query strings from static resources
- Remove DNS prefetch
- Remove Recent Comments inline CSS
- Limit post revisions
- Disable Dashicons for non-logged-in users
- Disable Heartbeat API
- Disable admin bar on frontend
- Remove jQuery Migrate
- Load core block styles separately (per-block CSS)
- Disable block-based widget editor
- Enable PrismJS on admin screens
- Enable fullscreen toggle for backend textareas
Navigate to: ?page=functionalities&module=misc
- Google Analytics 4 integration (just enter Measurement ID)
- Custom header code injection
- Custom footer code injection
- Safe sanitization with
wp_ksesfor non-superadmins
Navigate to: ?page=functionalities&module=snippets
Add microdata to your site's HTML:
itemscope/itemtypeon<html>tag- Optional WPHeader and WPFooter microdata
- Article microdata with customizable itemtype
- Automatic headline, dates, and author properties
Navigate to: ?page=functionalities&module=schema
Define reusable CSS components as selector + CSS rules. Auto-enqueued site-wide.
Default components include: cards, buttons, badges, chips, alerts, avatars, grids, accordions.
Navigate to: ?page=functionalities&module=components
Register custom font families with @font-face:
- WOFF2 and WOFF support
- Variable fonts support
- Font-display control (swap, auto, block, fallback, optional)
- Typography assignments for body and headings via theme.json data layer
- Native Bricks Builder integration — fonts appear in the Bricks typography picker
Navigate to: ?page=functionalities&module=fonts
Copyright, Dublin Core, licensing, and SEO plugin integration.
Features:
- Automatic copyright meta tags and Dublin Core metadata
- Creative Commons licensing integration
- Standalone Schema.org output for copyright/license information
- Integration with popular SEO plugins for unified metadata
Navigate to: ?page=functionalities&module=meta
Upload custom SVG icons and insert them inline in the block editor.
Features:
- Custom SVG icon library with secure sanitization
- Inline insertion via RichText toolbar (inherits surrounding font size)
- Standalone metadata-driven SVG Icon block with alignment, native text color, spacing, anchor, and custom class support
- Pixel,
em, andremsizing with bounded values - Monochrome or original-color rendering
- Decorative or informative accessibility modes with custom labels
- Searchable, paginated, keyboard-accessible icon picker with recent icons first
- WordPress 7 Core Icon library source and two-way transforms with the Core Icon block
- Pattern overrides and block bindings for icon names and accessibility labels
- Reusable Icon Callout pattern
- Zero frontend footprint when no icons are used
Navigate to: ?page=functionalities&module=svg-icons
WordPress 7 sites gain progressive platform integrations without adding frontend assets:
- Abilities API operations for diagnostics, module controls, redirects, tasks, assumption scans, and content checks
- DataViews and DataForm workspaces for Redirect Manager, bounded 404 activity, and Task Manager
- Command Palette shortcuts for common Functionalities actions
- Optional WordPress AI Client explanations for individual Assumption Detection and Content Integrity findings
- Core Icon library interoperability in the SVG Icon block
AI explanations are disabled by default. When enabled, the plugin sends only the finding an administrator explicitly submits to the site's configured WordPress AI provider.
Detect structural regressions when posts are updated.
Internal Link Drop Detection:
- Warns when internal links are accidentally removed
- Configurable percentage threshold (default: 30%)
- Configurable absolute threshold (default: 3 links)
- Option to exclude nofollow links
Word Count Regression:
- Alerts when content is shortened significantly
- Configurable drop percentage (default: 35%)
- Minimum content age requirement (default: 30 days)
- Shortcode exclusion support
Heading Structure Analysis:
- Missing H1 detection
- Multiple H1 detection
- Skipped heading level detection (e.g., H2 → H4)
Also includes: rolling snapshot storage, admin column for regression status, block editor integration with pre-publish warnings.
Navigate to: ?page=functionalities&module=content-regression
Monitor when technical assumptions stop being true. Philosophy: "This used to be true. Now it isn't."
Detects:
- Schema collisions (multiple JSON-LD sources)
- Analytics duplication (GA4, GTM, Facebook Pixel)
- Font redundancy (same font from multiple sources)
- Inline CSS growth (performance debt monitoring)
Dashboard UI with acknowledge/ignore actions for each detected issue.
Navigate to: ?page=functionalities&module=assumption-detection
Simple, file-based project task management for content and development workflows within WordPress admin.
Features:
- Track tasks directly in the WordPress dashboard
- Stored in a portable JSON file for version control friendliness
- Organized by status and priority
Navigate to: ?page=functionalities&module=task-manager
Manage URL redirects directly from WordPress admin with high-performance file-based storage.
Features:
- Supports 301, 302, 307, and 308 redirects
- File-based JSON storage for zero database overhead during redirects
- Integrated hit counter for tracking redirect usage
- Normalized path matching
- CSV import/export with a validated dry-run preview
- Optional bounded 404 aggregation without visitor identifiers or full referrers
Navigate to: ?page=functionalities&module=redirect-manager
Enhanced login protection and security measures for your WordPress site.
Features:
- Limit login attempts to prevent brute force attacks
- Per-username throttling, so a distributed attempt against one account is caught
- IP allowlist, so a shared address behind a CDN cannot lock you out of your own site
- Unlock any address or username directly from the lockout log
- Configurable lockout durations
- Disable XML-RPC authentication and application passwords
- Hide detailed login errors to prevent user enumeration
- Custom login page logo and background styling
Proxy-header mode accepts X-Forwarded-For only from configured trusted proxy IPs or CIDR ranges. Configure the ingress proxies before enabling it; they must overwrite or append the real client address. An empty trusted list ignores forwarding headers.
Navigate to: ?page=functionalities&module=login-security
Make the site installable with a web app manifest, service worker, offline fallback, and optional install prompt.
Features:
- Configurable app name, colors, icons, display mode, and orientation
- Offline page and versioned runtime caching
- App shortcuts, screenshots, and advanced manifest fields
- Optional install prompt and Web Share Target support
- Root-level manifest and service worker endpoints
Navigate to: ?page=functionalities&module=pwa
Create exception-urls.json in your theme or plugin directory:
{
"urls": [
"https://example.com/trusted-page",
"https://partner-site.com",
"https://another-trusted-site.com/blog"
]
}Priority order: Custom path → Developer filter → Child theme → Parent theme → Plugin default
// Add exception domains
add_filter( 'functionalities_exception_domains', function( $domains ) {
$domains[] = 'trusted-site.com';
return $domains;
});
// Add exception URLs
add_filter( 'functionalities_exception_urls', function( $urls ) {
$urls[] = 'https://example.com/page';
return $urls;
});
// Custom JSON file path
add_filter( 'functionalities_json_preset_path', function( $path ) {
return get_stylesheet_directory() . '/my-exceptions.json';
});Navigate to Link Management and scroll to "Database Update Tool":
- Enter the URL you want to add nofollow to
- Click "Update Database"
- Confirm the operation
- Results show how many posts were updated
Caution: This directly modifies post content in the database.
You can render any icon from your library using the [func_icon] shortcode.
[func_icon name="car" class="my-custom-class"]
Attributes:
name(required): The slug of the icon as defined in the SVG Icons library.class(optional): Additional CSS classes to add to the<svg>element.
// Disable the SVG Icons module via code
add_filter( 'functionalities_svg_icons_enabled', '__return_false' );
// Filter the list of available icons
add_filter( 'functionalities_svg_icons_list', function( $icons ) {
// Modify $icons array
return $icons;
});
// Filter sanitized SVG content before it is saved to the database
add_filter( 'functionalities_svg_icons_sanitize', function( $svg, $slug ) {
return $svg;
}, 10, 2 );functionalities/
├── assets/
│ ├── blocks/svg-icon/ Block metadata for the SVG Icon block
│ ├── css/ admin, admin-ui, content-regression, svg-icons-editor
│ ├── js/ admin*, content-regression, svg-icons-editor, wp7-*
│ └── vendor/prism/ Bundled Prism.js (MIT), admin syntax highlighting
├── includes/
│ ├── admin/
│ │ ├── class-admin.php Thin entry point
│ │ ├── class-admin-ui.php Shared UI helpers
│ │ ├── class-module-controller.php Public API + routing
│ │ ├── class-module-docs.php Per-module docs text
│ │ ├── class-settings-portability-controller.php Export / import / diagnostics
│ │ ├── class-site-health-controller.php Scans, schedules, exposure probe
│ │ ├── class-redirect-manager-controller.php
│ │ ├── class-svg-icons-controller.php
│ │ ├── class-task-manager-controller.php
│ │ ├── trait-admin-ajax.php
│ │ ├── trait-admin-options.php
│ │ ├── trait-admin-sanitizers.php
│ │ ├── trait-admin-settings.php Settings registration
│ │ └── trait-admin-*-ui.php Module-specific renderers
│ ├── core/
│ │ ├── class-module-registry.php Module list + lazy loader
│ │ └── class-wordpress-7-integration.php Abilities, DataViews, AI
│ ├── features/ One class per module (19)
│ ├── storage/
│ │ ├── class-atomic-json-store.php Locked, atomic JSON writes
│ │ └── class-data-directory.php Private data path + hardening
│ └── traits/
│ └── trait-css-sanitizer.php
├── languages/
├── src/ Source for the WordPress 7 admin bundle (not shipped)
├── tests/ PHP and JavaScript regression suites
├── docs/ Performance baseline notes (not shipped)
├── exception-urls-sample.json
├── functionalities.php
├── index.php
└── uninstall.php
- Create a feature class in
includes/features/class-your-module.php - Add its definition to
Core\Module_Registry::get_definitions() - Register its settings in
Admin_Settingsand reuse the public module controller API - Add focused tests for defaults and any pure helpers
composer install
composer lint
npm test
composer phpcs
composer test
node --check assets/js/admin.js
bash -n build.sh
./build.shThe pull-request workflow runs PHP syntax checks on PHP 7.4 through 8.5, coding standards, PHPUnit, JavaScript and shell syntax, version consistency, and distribution ZIP assertions.
Example module definition:
'your-module' => array(
'title' => __( 'Your Module', 'functionalities' ),
'description' => __( 'Brief description', 'functionalities' ),
'icon' => 'dashicons-admin-generic',
),Functionalities is a free and open source WordPress plugin with 19 modules for performance, security, SEO and content management, each behind its own toggle. For 1.6.0 I moved Link Management, Block Cleanup and Schema to the WordPress HTML API so they edit attributes in place and leave Vue and Alpine templates alone.
If it replaced a separate redirect manager or a header and footer snippets plugin on your site, you can buy me a coffee.
A star on the repo helps and so does an issue that lists your WordPress and PHP versions, the module you had switched on and the steps that led to the bug.
See readme.txt for the full changelog.
