BACK TO DIRECTORY

Adminkeep – Site Lockdown & Admin Enhancements

by Shazzad Hossain Khan

0.0
(0 ratings)

Site lockdown and admin enhancements for WordPress, under one idea: you decide what changes on this site.

Site Lock stops things changing behind your back — no new comment, no new plugin, no new user, no new account with admin rights. The rest are admin enhancements that make the changes you do want safe to make: an email log, custom CSS, header and footer code, SMTP, a contact form, duplicate and reorder posts, replace a file in place.

Every feature is a single switch, off until you turn it on. Switching one off never leaves you repair work: the locks work through WordPress filters, so your site is exactly as it was (the devices Two-Factor Login remembers stay behind, doing nothing), and what you made with the Content features stays where you put it.

Site Lock

  • Disable Comments — comments off everywhere, including direct POSTs from spam bots and the REST API. Nothing is written to your database, so switching it off brings every comment back. An optional cleanup button deletes spam and trashed comments, after showing you the exact count. Guide
  • Registration Lockdown — stops new accounts being created, and refuses creation of or promotion to administrator. Blocked attempts are logged. Guide
  • Disable XML-RPC — closes xmlrpc.php completely, including pingbacks and system.multicall. Guide
  • Disable File Editing — removes the built-in plugin and theme file editors, reversibly.
  • Installation Lockdown — no new plugins or themes, from WordPress.org or a ZIP, and no replacing one by uploading a ZIP, for anyone. Updates keep working, so security releases still reach your site. Guide
  • Username Privacy — keeps your usernames out of public view. Author pages, the ?author=1 probe, the REST users list, author sitemaps and embed previews stop naming your accounts to visitors; anyone logged in sees everything as before. Nothing is written, so switching it off reopens it all. Guide
  • Two-Factor Login — users in the roles you choose enter a six-digit code emailed to them after their password, so a stolen password alone no longer opens the account. The code screen emails the code when the user presses its button, so they can warn whoever reads that mailbox first, and the code works once, for up to ten minutes. Five wrong codes lock the code step for that account for 15 minutes, doubling on repeat. At most five code emails go to one user in ten minutes, and wrong codes are reported as failed logins, so login-limiting plugins count them. “Remember this device” skips the code on that browser for 30 days, or the number you set. On multisite, super admins are asked whenever administrators are. The code is asked for on the main login screen; other login forms, such as WooCommerce’s My Account, send these users there. The REST API, application passwords and XML-RPC are not asked. Switching it on emails you a recovery link that turns Two-Factor Login off without logging in, in case you are ever locked out.

Appearance

  • Custom CSS — CSS that belongs to your site instead of your theme. Edit it under Appearance with WordPress’s own code editor, or open Edit CSS from the admin bar on any page and watch the page restyle as you type, the way the Customizer’s CSS box used to. It stays when you switch themes, and your theme’s Additional CSS is left alone.
  • Header & Footer Code — a home for the snippets services ask you to paste into your site: analytics and verification tags in the head, a tag manager’s fallback just after the body opens, chat widgets and scripts in the footer. Three boxes under Appearance with WordPress’s code editor, printed on the front end exactly as you saved them, and kept when you change or update your theme. Each box shows who last changed it and when. Only administrators allowed to post unfiltered HTML can edit them.

Email

  • SMTP — Send your site’s email through an SMTP server so password resets and form messages arrive. Presets for Amazon SES, Brevo, Mailgun, SendGrid, Postmark, Zoho and Gmail; a test email that shows the server’s own error; settings can live in wp-config.php. Moving from WP Mail SMTP? One click copies its SMTP connection settings. Guide
  • Email Log — Email Log, in its own item in the admin menu by default (or under Tools, if you prefer), lists the email your site sends, with recipient, subject and whether it was sent or failed, plus filters by status and date and a search. Open any email to see its sender and headers, and the email itself the way it looked when it went out, with remote images blocked. Content storage can be switched off to keep only the envelope. Password-reset and sign-in links are removed before an email is stored, and a Two-Factor Login code email keeps only its envelope. Works with or without the SMTP feature, and with other SMTP plugins too.
  • Nice Default Emails — WordPress’s own plain-text emails (password resets, new-user and comment notices, update reports, personal data requests, and multisite sign-ups), and Adminkeep’s own contact form, go out in one clean HTML layout headed by your site’s name, with links you can click. WooCommerce and other plugins’ emails, and anything already sent as HTML, are left exactly as they are. No settings. wp adminkeep emails send --all --to=you@example.com shows every one of them in your own inbox.
  • Contact Form — one simple form for any page: name, email and message, as a block or the [adminkeep_contact_form] shortcode. Messages are emailed to you through WordPress’s own mailer, so the SMTP feature delivers them and Email Log shows whether each one went out, with the server’s error if it did not. Works out of the box, protected by a WordPress nonce that needs no keys (not for sites that cache their pages), or by Cloudflare Turnstile or Google reCAPTCHA v3 with your own free keys. Nothing is stored. The form prints its own small style and script with itself, so nothing extra loads on other pages, and the spam check’s script loads only on pages that show the form.

Admin

  • User Registration Date — a sortable Registered column on the Users screen. WordPress records when every account was created but never shows it; this does, for every existing user, and newest-first sorting makes a wave of spam signups easy to spot. Guide

Content

  • Duplicate — copy any post or page as a draft. Custom fields, taxonomies, the featured image and page builder layouts (Elementor, ACF) come along intact, and the original is never modified. Guide
  • Live Draft — rework a published page in a private working copy, then publish it over the original. Same ID, same URL, and the old version is kept as a revision. Guide
  • Keep URL — rename or move a page and its old address keeps working, child pages included. Fills the gaps WordPress leaves for pages and leaves posts to core. Guide
  • Order — drag posts into the order you want on a dedicated Sort screen, one post type at a time. Lists that already ask for their own order, such as WooCommerce products and search results, are left alone. Guide
  • Replace Media — upload a new version of a file over the old one. Same file type keeps the same URL; a different type updates the posts that use it and redirects the old address. Guide

Performance

A feature you have not enabled registers zero hooks and loads zero assets.

Links

External services

Adminkeep connects to no outside service unless you switch on a feature that needs one and set it up. Two features can: SMTP sends your site’s email through the mail server you enter, and the Contact Form uses the spam check you choose (its WordPress nonce option uses none). Nothing is sent to Adminkeep.

Cloudflare Turnstile (Contact Form, when you choose it). On pages that show the form, the visitor’s browser loads Cloudflare’s script from challenges.cloudflare.com, which receives the visitor’s IP address and browser details in order to tell people from bots. When the visitor presses Send, your site sends Cloudflare your secret key and the check’s one-time token, and nothing else, to confirm it. Terms: https://www.cloudflare.com/website-terms/ — Privacy policy: https://www.cloudflare.com/privacypolicy/

Google reCAPTCHA v3 (Contact Form, when you choose it). On pages that show the form, the visitor’s browser loads Google’s script from www.google.com (and the code it needs from www.gstatic.com), which receive the visitor’s IP address and browser details in order to score the visit. When the visitor presses Send, your site sends Google your secret key and the check’s one-time token, and nothing else, to confirm it. Terms: https://policies.google.com/terms — Privacy policy: https://policies.google.com/privacy

WP-CLI

Everything on the Adminkeep settings screen, plus the Custom CSS, Header & Footer Code, SMTP and Contact Form screens, can be done from a shell with wp adminkeep.

wp adminkeep feature list — every feature and whether it is on
wp adminkeep feature enable disable_comments — switch a feature on (or `disable` it)
wp adminkeep feature set order post_types=post,page — change a feature's settings
wp adminkeep feature set two_factor roles=administrator,editor — choose who is asked for a login code
wp adminkeep feature disable two_factor — a way back in if the site cannot send email
wp adminkeep feature enable two_factor — switches it on and says where the recovery link was emailed
wp adminkeep setting set hide_unused=true — change a plugin-level setting
wp adminkeep comments purge — delete spam and trashed comments, in batches
wp adminkeep css set site.css — replace the Custom CSS from a file
wp adminkeep code set head analytics.html — replace one Header & Footer Code box (head, body or footer) from a file
wp adminkeep smtp set --host=smtp.example.com --port=587 — configure SMTP
wp adminkeep smtp test you@example.com — send a test email and see the server's reply
wp adminkeep emails send --all --to=you@example.com — see WordPress's own emails in the Nice Default Emails layout
wp adminkeep smtp import wp-mail-smtp — copy the SMTP connection settings from WP Mail SMTP
wp adminkeep contact-form set --provider=turnstile --turnstile-site-key=<key> — set up the contact form's spam protection (the secret goes in with `--turnstile-secret-stdin`)
wp adminkeep contact-form get — the contact form's settings, and whether it is live

Run wp help adminkeep for the full reference. A change made here is cleaned and checked exactly as it is on the screen, and a mistyped value is refused rather than guessed at.

Screenshots

Five groups, nineteen features, one switch each. Turn on only what you need.

Five groups, nineteen features, one switch each. Turn on only what you need.

Nothing is deleted until you have seen the exact count. Order notes and reviews are excluded unless you say otherwise.

Nothing is deleted until you have seen the exact count. Order notes and reviews are excluded unless you say otherwise.

The administrator guard is on by default. Blocking plugin-created accounts is opt-in, because it breaks WooCommerce checkout.

The administrator guard is on by default. Blocking plugin-created accounts is opt-in, because it breaks WooCommerce checkout.

Stop plugin and theme installs and uploads, while updates keep working — and switch it back off from this same screen.

Stop plugin and theme installs and uploads, while updates keep working — and switch it back off from this same screen.

Custom CSS lives under Appearance, in WordPress's own code editor, and stays when you switch themes.

Custom CSS lives under Appearance, in WordPress's own code editor, and stays when you switch themes.

Edit CSS from the admin bar on any page of your site: the page restyles as you type, and nothing is saved until you press Save.

Edit CSS from the admin bar on any page of your site: the page restyles as you type, and nothing is saved until you press Save.

Header &amp; Footer Code under Appearance: one box each for the head, the top of the body and the footer, and who last changed each one.

Header & Footer Code under Appearance: one box each for the head, the top of the body and the footer, and who last changed each one.

SMTP under Settings: pick a provider, save, and send a test email that shows what the server said.

SMTP under Settings: pick a provider, save, and send a test email that shows what the server said.

Email Log in its own admin menu: every email your site sends, whether it went out, and filters for status, period and search.

Email Log in its own admin menu: every email your site sends, whether it went out, and filters for status, period and search.

Open any logged email as it was sent, with its source a tab away. Scripts and remote images are blocked in the preview.

Open any logged email as it was sent, with its source a tab away. Scripts and remote images are blocked in the preview.

Contact Form under Settings: where messages go, and the spam protection: a WordPress nonce out of the box, or Cloudflare Turnstile or Google reCAPTCHA. The shortcode and block are in the Usage box.

Contact Form under Settings: where messages go, and the spam protection: a WordPress nonce out of the box, or Cloudflare Turnstile or Google reCAPTCHA. The shortcode and block are in the Usage box.

Duplicate and Live Draft where you already work — the row actions, not a new menu.

Duplicate and Live Draft where you already work — the row actions, not a new menu.

Rewrite a published page while it stays published. Merge back into the same post, same URL.

Rewrite a published page while it stays published. Merge back into the same post, same URL.

The redirects WordPress core skips: hierarchical pages, and posts moved to a new parent.

The redirects WordPress core skips: hierarchical pages, and posts moved to a new parent.

Sorting gets a screen of its own: drag a row where you want it — and the order applies to your front-end queries too.

Sorting gets a screen of its own: drag a row where you want it — and the order applies to your front-end queries too.

Swapping a file for a different format tells you what references it first, then keeps the old URL redirecting.

Swapping a file for a different format tells you what references it first, then keeps the old URL redirecting.

Two-Factor Login on the login screen: after the password, a six-digit code emailed to the account's address, shown partly hidden, with the option to remember the device.

Two-Factor Login on the login screen: after the password, a six-digit code emailed to the account's address, shown partly hidden, with the option to remember the device.

Locked out? The recovery link emailed when you switch Two-Factor Login on opens this page, and one button turns the code step off without logging in.

Locked out? The recovery link emailed when you switch Two-Factor Login on opens this page, and one button turns the code step off without logging in.

Two-Factor Login in the settings: choose which roles are asked for a code, and see where the recovery link was emailed.

Two-Factor Login in the settings: choose which roles are asked for a code, and see where the recovery link was emailed.

Plugin Details

Active Installs
70
Total Downloads
1,423
Version
2.6.0
Requires WP
6.9
Requires PHP
7.4
Tested Up To
7.1.3
Added
2026-09-19
Last Updated
2026-10-07 8:26am GMT

Ratings

5
0
4
0
3
0
2
0
1
0