=== SlimPress – Disable Unused Features, Heartbeat & XML-RPC ===
Contributors: macvej
Tags: performance, disable, heartbeat, xml-rpc, optimization
Requires at least: 6.8
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Switch off WordPress core features you do not use. Every toggle explains what it might affect, including possible compatibility concerns.

== Description ==

SlimPress turns off parts of WordPress core that your site does not use - emoji scripts, XML-RPC,
the REST API for logged-out visitors, Heartbeat, comments, feeds, author and date archives,
search, revisions, image sizes, block editor extras, dashboard clutter, automatic updates,
admin emails and more - grouped by area and explained in plain language. A built-in performance test
measures what it changes on your own pages, with and without SlimPress, without changing a setting.

What makes it different:

* **Every toggle is free.** No pro tier, no upsells, no nag banners, no telemetry.
* **"What might break" on every switch**, plus a warning when an active plugin needs the thing
  you are about to switch off.
* **An honest impact badge** on every toggle, including "None - cleanup only".
* **A performance test that tells the truth.** It loads your pages with SlimPress's features and
  without them, in the same run, and says "within noise" when the difference is too small to
  trust - and shows what each plugin, theme and core adds to the page, with the files SlimPress
  can remove marked.

What SlimPress deliberately does not do: page caching, minification, "remove unused CSS",
delay-JS, per-page script managers, CDN rewrites. If a feature is not "turn off something core
WordPress does", it does not go in.

Nothing is switched off until you switch it off. Every switch is a runtime filter, so
deactivating SlimPress restores WordPress completely on the next request. SlimPress never writes to
core tables or core options.

= 108 switches in 13 groups =

* **Front-end** - emoji scripts, generator tag, RSD, shortlink and REST links in the page head,
  global styles, core block CSS, Dashicons and jQuery Migrate for visitors.
* **APIs & connections** - XML-RPC, the REST API for logged-out visitors (with an allowlist),
  Heartbeat per location, WP-Cron on page load, oEmbed, auto-embeds, application passwords, the
  Abilities API.
* **Comments** - comments site-wide or per post type, pingbacks, avatars and Gravatar.
* **Content & URLs** - feeds, author, date and attachment pages, search.
* **Revisions & autosave** - revision limits, autosave interval, trash retention, plus a
  one-off "delete old revisions" button that asks first.
* **Media** - the extra 1536px and 2048px image copies, image sizes you choose, and Openverse
  in the media inserter.
* **Block editor** - welcome guide, block directory, command palette, the classic editor for
  chosen post types.
* **Dashboard & admin** - dashboard widgets, admin bar items, footer text, the Customizer on
  block themes.
* **Updates** - automatic updates for core, plugins, themes and translations.
* **Emails** - the admin emails WordPress sends about updates, new users and password changes.
* **Security** - file editing, installing from the dashboard, the front-end password meter.
* **Site Health & privacy** - Site Health checks and the privacy tools menus.
* **WooCommerce** (only shown while WooCommerce is active) - shop assets and order attribution
  scripts on non-shop pages, Analytics, the Marketing hub, remote and marketplace suggestions,
  usage tracking, background thumbnail regeneration, and how long Action Scheduler and log files
  are kept.

Each group has an on/off switch of its own, so you can pause a whole group while you look for a
problem, and put it back exactly as it was.

= Presets =

The Overview tab offers site-wide presets (Safe defaults, Blog, Brochure site, WooCommerce store,
Headless). A preset only ever switches things on: it shows you what it would change first,
skips anything an active plugin relies on, and leaves everything else as it is.

= Built to cost nothing =

A feature that is off loads no code and adds no hooks. SlimPress adds no CSS, JavaScript or
markup to your public pages, ever. With every feature off, SlimPress adds about 105 KB of memory
and no database queries to a front-end request, and the time it adds was too small to measure
(WordPress 7.1, PHP 8.4, median of 40 paired runs).

== Installation ==

1. Upload the plugin to `/wp-content/plugins/slimpress/`, or install it from the Plugins screen.
2. Activate it. Nothing changes on your site until you say so.
3. Go to **Settings -> SlimPress**.

== Frequently Asked Questions ==

= Does activating SlimPress change anything on my site? =

No. Every feature is off by default and activation writes nothing.

= What happens if I deactivate SlimPress? =

WordPress is back to stock on the very next request. SlimPress applies everything through runtime
filters and actions, so there is nothing to undo. The one exception is the "Delete old
revisions" button: revisions it deleted stay deleted, which is why it asks first.

= Which toggles are risky? =

Every toggle that can visibly break something is marked **Careful** and says what might stop
working. The ones most likely to catch you out:

* **Disable the REST API for logged-out visitors** - contact forms, booking plugins and
  WooCommerce blocks often use it. Add their namespaces to the allowlist.
* **Disable WP-Cron on page load** - scheduled posts, backups and automatic updates stop until
  a real server cron job runs `wp-cron.php`. Set that up first.
* **Disable XML-RPC** - the WordPress mobile app, Jetpack and pingbacks use it.
* **Disable comments site-wide** - WooCommerce product reviews are comments too.
* **Disable global styles** - block themes rely on it for spacing, colours and typography.
* **Disable installing and updating from the dashboard** - also stops security updates. Only
  for sites that are updated some other way.
* **Disable recovery mode emails** - that email is how you get back in after a fatal error.

SlimPress also warns you when an active plugin is known to need something you are about to switch
off.

= Why doesn't SlimPress remove ?ver= query strings? =

The version string is what makes browsers fetch a fresh file after an update. Removing it gains
nothing measurable and can serve visitors stale CSS and JavaScript. SlimPress also has no switch
for turning off lazy loading, auto `sizes` on lazy images or big-image scaling, because each of
those makes sites slower. The Media tab explains big-image scaling on an info card instead.

= Does SlimPress need WooCommerce? =

No. It works on any site. On a WooCommerce store it warns you about switches the shop relies on,
and there is a WooCommerce store preset that leaves the shop alone. A WooCommerce tab with its own
switches (admin nags, tracking, background jobs and more) appears automatically while WooCommerce
is active, and disappears - without losing your choices - if you deactivate it.

= Will it conflict with my caching plugin? =

SlimPress does not cache, minify or combine anything, so it does not overlap with a caching
plugin. The performance test asks for uncached pages, and if a page cache answers anyway it says
so rather than showing you the cache's numbers.

= Does SlimPress contact any external service? =

Only if you click the optional PageSpeed button on the performance test tab. See "External
services" below.

= Can I move my settings to another site? =

Yes. The Tools tab exports your settings as a JSON file and imports them on another site. It
also resets every switch to off.

== External services ==

The performance test tab has an optional "Run Google PageSpeed test" button. Only when you click it,
SlimPress sends your site's homepage URL to Google's PageSpeed Insights API
(`https://www.googleapis.com/pagespeedonline/v5/runPagespeed`) to fetch Core Web Vitals for that
page. No other data is sent, no API key is used, and nothing is sent automatically.

This service is provided by Google: [Terms of Service](https://developers.google.com/terms),
[Privacy Policy](https://policies.google.com/privacy).

== Screenshots ==

1. Overview - what is switched off, per group, with the site-wide presets.
2. A group tab - every switch with its impact badge, what it does and what might break.
3. The performance test - pick pages, run, and see the difference with and without SlimPress.
4. Test history - earlier runs, per-feature results, the settings each run used, and a trend
   chart for HTML size, PHP time and queries across runs.
5. Tools - export, import and reset.

== Changelog ==

= Unreleased =
* Removed the "Disable all update checks" option at the request of the wordpress.org plugin
  review team: it interfered with the WordPress update system. Automatic-update switches are
  unchanged. If you had it on, WordPress checks for updates again after you update SlimPress.
* Test history now shows a trend chart for HTML size, PHP time and queries across runs.
* The performance test now shows what your pages load, by source: a breakdown of CSS and JS by
  plugin, theme and core, with the files SlimPress can remove marked.
* Now runs on PHP 7.4 and later (was 8.1).

= 1.0.0 =
* Initial release.

== Upgrade Notice ==

= 1.0.0 =
First release. Activating changes nothing: every switch starts off.
