=== SlimPress – Disable Unused Features, Heartbeat & XML-RPC ===
Contributors: macvej
Tags: performance, disable, heartbeat, xml-rpc, optimization
Requires at least: 6.8
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.6.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Switch off WordPress core features you do not use. Every toggle explains what it might affect, including any compatibility concerns.

== Description ==

SlimPress turns off parts of WordPress core that your site does not use - emoji scripts, XML-RPC,
the REST API for logged-out visitors, Heartbeat, comments, feeds, author and date archives,
search, revisions, image sizes, block editor extras, dashboard clutter, automatic updates,
admin emails and more - grouped by area and explained in plain language. A built-in performance test
compares your own pages with and without SlimPress, without changing your settings.

What makes it different:

* **Every toggle is free.** No pro tier, no upsells, no nag banners, no telemetry.
* **"What might break" on every switch**, plus a warning when an active plugin relies on the feature
  you are about to switch off.
* **An honest impact badge** on every toggle, including "None - cleanup only".
* **A performance test that tells the truth.** It loads your pages with and without SlimPress's
  features in the same run and says "within noise" when the difference is too small to be
  reliable. It also shows what each plugin, the theme and WordPress core add to the page,
  marking the files SlimPress can remove. It can measure each feature individually and report
  which autoloaded options each request loads from the database.
* **Undo for every change.** SlimPress keeps the last 10 versions of its settings, so any save,
  preset, import or reset can be undone.

What SlimPress deliberately does not do: page caching, minification, "remove unused CSS",
JavaScript delays, per-page script managers or CDN rewrites. Features must serve the purpose of
turning off something WordPress core does.

Nothing is switched off until you switch it off. Every switch is a runtime filter, so
deactivating SlimPress restores WordPress's default behaviour on the next request. SlimPress never
writes to core tables or core options itself, except when you click the one-off "Delete old
revisions" button and confirm. Retention limits also have lasting effects: when you set a limit
for revisions, trash, WooCommerce scheduled actions or logs, WordPress or WooCommerce permanently deletes anything
that exceeds it. Media switches affect the image copies created during upload; switching them
off or deactivating SlimPress does not recreate missing copies or restore deleted data.

= 116 switches in 13 groups, plus the Assets tab =

* **Front-end** - emoji scripts, generator tag, RSD, shortlink, feed and REST links in the page
  head, global styles, core block CSS, Dashicons and jQuery Migrate for visitors, the image
  lightbox, speculative loading, smart quotes - plus "Load the next page before the click".
* **APIs & connections** - XML-RPC, the REST API for logged-out visitors (with an allowlist),
  the REST user list, Heartbeat per location, WP-Cron on page load, oEmbed, auto-embeds,
  application passwords, the Abilities API, the AI client and Connectors screen.
* **Comments** - comments site-wide or per post type, closing comments while keeping old ones
  visible, pingbacks and self-pingbacks, links in comments, avatars and Gravatar.
* **Content & URLs** - feeds, author and date archives, attachment pages, search, the core sitemap or
  just its users sitemap, `?author=` username lookups, 404 redirect guessing, post formats.
* **Revisions & autosave** - revision limits, autosave interval, trash retention, plus a
  one-off "delete old revisions" button that asks first.
* **Media** - the extra 1536px and 2048px image copies, selected image sizes, saving new
  images as WebP or AVIF, in-browser image processing, PDF preview images, and Openverse in the
  media inserter.
* **Block editor** - welcome guide, the default fullscreen mode, patterns from WordPress.org, the Font
  Library and Google Fonts, Notes, block directory, command palette, the classic editor for
  chosen post types and the classic widgets screen.
* **Dashboard & admin** - dashboard widgets, help tabs, "Howdy", admin bar items, footer text,
  update notices for non-admins, the Customizer on block themes.
* **Updates** - automatic updates for core, plugins, themes and translations.
* **Emails** - the admin emails WordPress sends about updates, new users and password changes,
  the admin email check screen and recovery mode emails.
* **Security** - file editing, installing from the dashboard, Post via email, the login
  language switcher, the front-end password meter.
* **Site Health & privacy** - the weekly Site Health check, the Site Health screen and the
  privacy tool menus.
* **Assets** - load a plugin's CSS and JavaScript only on the pages that use it. Choose between
  Everywhere, Only on chosen pages, Everywhere except, or Nowhere on the front end. Scan plugins
  to see which plugins load files and measure their total size.
* **WooCommerce** (only shown while WooCommerce is active) - shop assets and order attribution
  scripts on non-shop pages, product gallery effects, Analytics, the Marketing hub, remote and
  marketplace suggestions, usage tracking, background thumbnail regeneration, and how long
  Action Scheduler and log files are kept.

Each group has an on/off switch of its own, so you can pause a whole group while you look for a
problem and restore it exactly as it was. The Overview tab counts the requests SlimPress has
blocked today and over the last 30 days.

= Presets =

The Overview tab offers site-wide presets (Safe defaults, Blog, Brochure site, WooCommerce store,
Headless). A preset only enables SlimPress switches: it shows you what it would change first,
skips anything an active plugin relies on, and leaves everything else as it is.

= Built to cost nothing =

A feature that is off loads no code and adds no hooks. SlimPress adds no CSS, JavaScript or
markup to your public pages, ever. With every feature off, SlimPress adds about 115 KB of memory
and no database queries to a front-end request, and its processing overhead was too small to measure
(WordPress 7.1, PHP 8.4, using the median of 40 paired runs).

== Installation ==

1. Upload the plugin to `/wp-content/plugins/slimpress/`, or install it from the Plugins screen.
2. Activate it. Nothing changes on your site until you say so.
3. Go to **Settings -> SlimPress**.

== Frequently Asked Questions ==

= Does activating SlimPress change anything on my site? =

No. Every feature is off by default and activation writes nothing.

= What happens if I deactivate SlimPress? =

WordPress returns to its default behaviour on the very next request. SlimPress applies its
changes through runtime filters and actions, so there are no core settings to restore. Deleted
data does not come back: this includes revisions removed by the "Delete old revisions" button
(which asks first) or by a revision limit when a post was saved, trash emptied under a shorter
retention period, and WooCommerce scheduled actions and logs deleted under shorter retention
limits. Image copies omitted during uploads while a Media switch was on are not recreated.

= Which toggles are risky? =

Every toggle that can cause a visible problem is marked **Careful** and explains what might
stop working. The ones most likely to cause problems are:

* **Disable the REST API for logged-out visitors** - contact forms, booking plugins and
  WooCommerce blocks often use it. Add their namespaces to the allowlist.
* **Disable WP-Cron on page load** - scheduled posts, backups and automatic updates stop until
  a real server cron job runs `wp-cron.php`. Set that up first.
* **Disable XML-RPC** - the WordPress mobile app, Jetpack and pingbacks use it.
* **Disable comments site-wide** - WooCommerce product reviews are comments too.
* **Disable global styles** - block themes rely on these styles for spacing, colours and typography.
* **Disable installing and updating from the dashboard** - also stops security updates. Use this only
  on sites that are updated another way.
* **Disable recovery mode emails** - these emails help you regain access after a fatal error.

SlimPress also warns you when an active plugin is known to need something you are about to switch
off.

= Why doesn't SlimPress remove ?ver= query strings? =

The version string is what makes browsers fetch a fresh file after an update. Removing it offers
no measurable benefit and can leave visitors with outdated CSS and JavaScript. SlimPress also
has no switch for turning off lazy loading, automatic `sizes` attributes on lazy-loaded images
or big-image scaling, because disabling these features makes sites slower. The Media tab explains big-image scaling on an info card instead.

= Does SlimPress need WooCommerce? =

No. It works on any site. On a WooCommerce store, it warns you about switches that affect
features the shop relies on, and the WooCommerce store preset preserves those features. A WooCommerce tab with its own
switches (admin nags, tracking, background jobs and more) appears automatically while WooCommerce
is active, and disappears - without losing your choices - if you deactivate it.

= Will it conflict with my caching plugin? =

SlimPress does not cache, minify or combine anything, so it does not overlap with a caching
plugin. The performance test asks for uncached pages, and if a page cache responds anyway, it says
so rather than showing you the cache's numbers.

= Does SlimPress contact any external service? =

Only if you click the optional PageSpeed button on the performance test tab. See "External
services" below.

= Can I move my settings to another site? =

Yes. The Tools tab exports your settings as a JSON file and imports them on another site. The tab
also lets you reset every switch to off.

= I changed something and the site broke. How do I go back? =

Open **Tools -> Undo a change**. SlimPress keeps the last 10 versions of its settings - every
save, group pause, preset, import and reset - and restores the version you choose. To find the cause
first, pause one group at a time from its tab.

== External services ==

The performance test tab has an optional "Run Google PageSpeed test" button. When you click it,
SlimPress sends your site's homepage URL to Google's PageSpeed Insights API
(`https://www.googleapis.com/pagespeedonline/v5/runPagespeed`) to retrieve Core Web Vitals for that
page, using the test type (`strategy=mobile`) and the category (`category=performance`). No other
data is sent, no API key is used, and nothing is sent automatically. Google also
receives your server's IP address and the standard WordPress User-Agent (which includes your site
address), as with any web request.

This service is provided by Google: [Terms of Service](https://developers.google.com/terms),
[Privacy Policy](https://policies.google.com/privacy).

== Screenshots ==

1. Overview - what is switched off in each group, with the site-wide presets.
2. A group tab - every switch with its impact badge, what it does and what might break.
3. The performance test - choose pages, run the test and see the difference with and without SlimPress.
4. Test history - earlier runs, per-feature results, the settings each run used, and a trend
   chart for HTML size, PHP time and queries across runs.

== Changelog ==

= Unreleased =
* Check it yourself: each switch with a visible effect has a link to the page, address or admin screen where the change shows, opened in a new tab, with a short hint on what to look for.

= 1.6.1 =
* Performance test and plugin scan: database errors, dropped connections and stalled runs are handled with error reports, retries or cancellations instead of leaving the test hanging. The Stop button works while a step is running and no longer cancels a newer test from an out-of-date tab. Leaving the page mid-run cancels the run.
* Assets: large rule sets are no longer truncated, the page picker indicates when only the first 200 pages are listed, and importing settings lists pages referenced by rules that do not exist on this site.
* Comments: comments on the post types you choose are hidden from recent-comment lists, feeds and the REST API for visitors.
* WooCommerce: the order screen no longer shows a script error when remote suggestions are off.
* Failed database writes are reported instead of being shown as successful saves.
* Wording: per-feature results use the viewer's language and are hidden when that feature's settings change. Page weight is no longer described as exact when a page cache is detected, the revision-limit help explains that old revisions are pruned, and counts use the number format for your language.

= 1.6.0 =
* New Assets tab: load a plugin's CSS and JavaScript only on the pages that use it - Everywhere, Only on chosen pages, Everywhere except, or Nowhere on the front end.
* Scan plugins: see which plugins load files on your site and measure the total size and number of files each one adds.
* After a performance test runs, it shows the savings from an asset rule.
* WooCommerce: "Turn off WooCommerce's remote admin suggestions" now works on WooCommerce 11.1 and later. While it is on, WooCommerce's own "Show Suggestions" checkbox (WooCommerce → Settings → Advanced → WooCommerce.com) appears unticked, though the stored setting is not changed, and recommendation lists fall back to WooCommerce's built-in ones.
* Performance test: the PageSpeed result shows how long ago the test was run.

= 1.5.0 =
* Switching tabs on Settings → SlimPress no longer reloads the whole admin page: only the area below the tab bar changes. The address bar still follows the tab, so Back, Forward, reload and bookmarks work as before.
* Tabs are now normal links, so Ctrl-click or middle-click opens a tab in a new browser tab.
* Leaving a tab with unsaved changes now prompts for confirmation ("You have unsaved changes on this tab. Leave without saving?"), including when closing the browser tab.

= 1.4.0 =
* Six new switches: "Process uploaded images on the server, not in the browser" (Media tab),
  "Don't make preview images of uploaded PDFs" (Media tab), "Remove the users (authors)
  sitemap" (Content & URLs tab), "Don't turn web addresses in comments into links" (Comments
  tab), "Turn off Post via email" (Security tab), and "Turn off product gallery effects
  (WooCommerce)" (WooCommerce tab).
* A "Select all" checkbox in each tab's list header, replacing the previous "Turn everything in
  this tab off" link.
* Fix: "Disable author archives" no longer lists the home page once per author in the users
  sitemap.
* Fix: "Disable comments site-wide" no longer unregisters the Recent Comments widget — it now
  renders nothing instead, and also hides the Latest Comments block. Sites where a theme switch
  or saving on the Widgets screen already removed that widget while comments were off need to add it
  again.

= 1.3.1 =
* "Load the next page before the click" now shows a notice when the site uses HTTP: browsers only
  fetch pages early over HTTPS, so the "Fetch" level has no effect there.

= 1.3.0 =
* New switch, "Load the next page before the click" (Front-end tab): fetches or fully renders the
  next page while the pointer rests on a link, so clicks feel instant for logged-out visitors.
  WooCommerce's cart, checkout and My account pages are never rendered in advance.
* New switch, "Save new images as WebP (or AVIF)" (Media tab): new JPEG uploads and their smaller
  copies are saved in the modern format, with the original kept. Only formats the server can
  create are offered. Also works with WordPress 7.1's in-browser image processing.

= 1.2.0 =
* The performance test tab now shows what every request loads from the database: the total size
  of autoloaded options against Site Health's limit, the 20 largest options, an estimate of which plugin,
  theme or WordPress added each one, and a "maybe left over" label for option names that do not match
  any installed plugin. The report changes nothing and does not require a test run.

= 1.1.0 =
* The two Media image-size switches now say that upload plugins that create their own image
  copies in the browser choose their own sizes, so the switches cannot stop those.
* Removed the "Disable all update checks" option at the request of the WordPress.org plugin
  review team: it interfered with the WordPress update system. Automatic-update switches are
  unchanged. If you had it on, WordPress checks for updates again after you update SlimPress.
* Test history now shows a trend chart for HTML size, PHP time and queries across runs.
* The performance test now shows what your pages load, by source: a breakdown of CSS and JS by
  plugin, theme and core, marking the files SlimPress can remove.
* Now supports PHP 7.4 and later (previously required PHP 8.1).

= 1.0.0 =
* Initial release.

== Upgrade Notice ==

= 1.6.1 =
Fixes for the performance test, plugin scan, Assets rules and comment hiding. Your settings remain unchanged.

= 1.6.0 =
Adds an Assets tab: load plugin CSS and JavaScript only on the pages that need them, and scan plugins to see which ones load files and how large those files are. Nothing changes until you add a rule.

= 1.5.0 =
Settings tabs now switch without a full page reload and ask before discarding unsaved changes. Your settings remain unchanged.

= 1.4.0 =
Adds six new switches across the Media, Content & URLs, Comments, Security and WooCommerce tabs, and a "Select all" checkbox on each tab. Fixes author archives and site-wide comments. New switches are off by default.

= 1.3.1 =
Adds a note to the "Load the next page before the click" switch for sites that still use HTTP.

= 1.3.0 =
Adds two switches: load the next page before the click, and save new images as WebP or AVIF. Both are off until you switch them on.

= 1.2.0 =
Adds an autoload report to the performance test: what every request reads from the database, the largest options and which plugin, theme or part of WordPress probably added them.

= 1.1.0 =
Removes the "Disable all update checks" option at WordPress.org's request. Adds a load-by-source breakdown and a trend chart to the performance test.

= 1.0.0 =
First release. Activation changes nothing: every switch is off by default.
