Configuration

View as Markdown

Every Adminkeep setting, feature by feature — what each switch does, what its options mean, and what the defaults are.

Everything is configured from the Adminkeep screen in your admin menu. Each feature is a single switch, off by default, and starts working the moment you turn it on. Changes save as you make them — a “Changes saved” confirmation appears, and if a save fails, nothing is changed.

Looking for a specific setting? Type in the Filter settings box at the top of the sidebar — the feature list narrows as you type.

Every feature is instantly reversible: switch it off and your site behaves exactly as it did before, with nothing to repair.

Disable Comments

One switch, nothing else to configure — on purpose. Comment forms disappear, existing comments are hidden (never deleted), direct bot POSTs to wp-comments-post.php and REST comment creation are refused.

Below the switch is the plugin’s one destructive tool, the cleanup button:

  • By default it deletes only comments already marked spam or already in the trash.
  • A separate checkbox extends it to approved and pending comments — never the default, always behind a confirmation.
  • It shows the exact count before deleting, and deletes in batches so large sites can’t time out.
  • Comments on trashed posts are skipped — they return if the post is restored.

Installation Lockdown

One switch stops new code arriving: no new plugins or themes, and no uploads, for anyone. Activating and deactivating what’s already installed still works.

Updates are untouched. Update notifications, manual updates and auto-updates all keep working while the lock is on, so security releases still reach your site. There is nothing else to configure.

Registration Lockdown

Stops new user accounts. Three layers, each its own setting:

  • Registration form — forces “Anyone can register” off by filter, so it stays off even if something flips the database row directly.
  • Administrator guard (on by default) — refuses creation of, or promotion to, administrator. This is the layer that stops an attacker’s first move, and it leaves ordinary customer registration alone.
  • Plugin-code blocking (off by default) — also blocks accounts created by plugin code. Leave this off if you run WooCommerce checkout or a membership plugin; it breaks them.

Blocked administrator attempts are recorded with the time and requested username.

Disable XML-RPC

One switch. Closes every method at xmlrpc.php, including pingback.ping and system.multicall, and stops the site advertising the API. Leave it off if you use the Jetpack mobile app or a legacy remote publishing tool.

Disable File Editing

One switch. Removes the built-in plugin and theme file editors. Implemented as a setting rather than the DISALLOW_FILE_EDIT constant, so you can always switch it back off from the same screen.

Content tools

Their settings, briefly:

  • Duplicate — choose which post types offer the one-click copy, and whether copying a page brings its child pages along.
  • Live Draft — no options; each published page can have one private working copy, and publishing it is the merge.
  • Keep URL — no options while on; renamed and moved pages keep answering on their old addresses. Recorded redirects are listed on the settings screen and can be removed one at a time.
  • Order — enabled one post type at a time. Each enabled post type gets a Sort entry in its own admin menu: a dedicated screen where you drag rows into place and press Save. Put new posts at decides whether a new post lands at the top or the bottom of the order (bottom by default). Lists that already ask for a specific order (WooCommerce, search results) are always left alone. Taxonomy terms are not ordered.
  • Replace Media — replaced files keep their previous version for 30 days so a mistaken replace can be undone.

Install it, lock it, forget it.

A free WordPress plugin — GPL, instantly reversible, and updates come to you.

Type to search the whole site.