{"id":336098,"date":"2026-07-23T17:02:50","date_gmt":"2026-07-23T17:02:50","guid":{"rendered":"https:\/\/es.wordpress.org\/plugins\/tso-swiss-knife-advanced-maintenance-developer-toolkit\/"},"modified":"2026-09-20T18:31:21","modified_gmt":"2026-09-20T18:31:21","slug":"tso-swiss-knife-advanced-maintenance-developer-toolkit","status":"publish","type":"plugin","link":"https:\/\/ary.wordpress.org\/plugins\/tso-swiss-knife-advanced-maintenance-developer-toolkit\/","author":9581708,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.1.1","requires":"6.1","requires_php":"8.0","requires_plugins":null,"header_name":"TSO Swiss Knife \u2013 Advanced Maintenance & Developer Toolkit","header_author":"Tu Soporte Online","header_description":"Complete maintenance and developer toolkit: cron manager, debug mode, transients, database tools, hooks inspector, maintenance mode, plugin sandbox and more.","assets_banners_color":"1d3632","last_updated":"2026-09-20 18:31:21","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/ko-fi.com\/deadko_cat","header_plugin_uri":"","header_author_uri":"https:\/\/www.tusoporteonline.es\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":498,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.6":{"tag":"1.0.6","author":"deadko","date":"2026-08-24 19:58:09","revision":3664209},"1.0.7":{"tag":"1.0.7","author":"deadko","date":"2026-09-13 16:42:57","revision":3693953},"1.0.8":{"tag":"1.0.8","author":"deadko","date":"2026-09-10 19:49:43","revision":3690424},"1.0.9":{"tag":"1.0.9","author":"deadko","date":"2026-09-17 22:49:43","revision":3701082},"1.1.0":{"tag":"1.1.0","author":"deadko","date":"2026-09-20 18:31:21","revision":3704538}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3620303,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3620303,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x499.png":{"filename":"banner-1544x499.png","revision":3620303,"resolution":"1544x499","location":"assets","locale":"","width":1500,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3620303,"resolution":"772x250","location":"assets","locale":"","width":772,"height":257}},"assets_blueprints":{},"all_blocks":{"tsosk\/404-url":{"name":"tsosk\/404-url","title":"Tsosk Url"}},"tagged_versions":["1.0.6","1.0.7","1.0.8","1.0.9","1.1.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3620303,"resolution":"1","location":"assets","locale":"","width":1413,"height":851},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3620303,"resolution":"2","location":"assets","locale":"","width":1411,"height":778},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3620303,"resolution":"3","location":"assets","locale":"","width":1409,"height":781},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3620303,"resolution":"4","location":"assets","locale":"","width":1399,"height":856}},"screenshots":{"1":"Hidden WordPress Profiles \u2014 apply quick presets and toggle performance, content, and privacy constants via the plugin config under uploads (no wp-config.php editing).","2":"Custom 404 Page \u2014 assign any WordPress page as the site 404 response while keeping the original URL and a real HTTP 404 status (no redirect).","3":"Reorder &amp; Hide Sidebar \u2014 drag to reorder WordPress admin menu items, rename labels, nest items under another section, or hide items for all admins.","4":"Slow Query Monitor \u2014 inspect slow and live database queries when SAVEQUERIES is enabled, export the log, and open a summary from the admin bar."}},"plugin_section":[],"plugin_tags":[4567,153,94,4932,732],"plugin_category":[52,59],"plugin_contributors":[260487],"plugin_business_model":[],"class_list":["post-336098","plugin","type-plugin","status-publish","hentry","plugin_tags-cron","plugin_tags-database","plugin_tags-debug","plugin_tags-developer-tools","plugin_tags-maintenance","plugin_category-performance","plugin_category-utilities-and-tools","plugin_contributors-deadko","plugin_committers-deadko"],"banners":{"banner":"https:\/\/ps.w.org\/tso-swiss-knife-advanced-maintenance-developer-toolkit\/assets\/banner-772x250.png?rev=3620303","banner_2x":false,"banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/tso-swiss-knife-advanced-maintenance-developer-toolkit\/assets\/icon-128x128.png?rev=3620303","icon_2x":"https:\/\/ps.w.org\/tso-swiss-knife-advanced-maintenance-developer-toolkit\/assets\/icon-256x256.png?rev=3620303","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/tso-swiss-knife-advanced-maintenance-developer-toolkit\/assets\/screenshot-1.png?rev=3620303","caption":"Hidden WordPress Profiles \u2014 apply quick presets and toggle performance, content, and privacy constants via the plugin config under uploads (no wp-config.php editing)."},{"src":"https:\/\/ps.w.org\/tso-swiss-knife-advanced-maintenance-developer-toolkit\/assets\/screenshot-2.png?rev=3620303","caption":"Custom 404 Page \u2014 assign any WordPress page as the site 404 response while keeping the original URL and a real HTTP 404 status (no redirect)."},{"src":"https:\/\/ps.w.org\/tso-swiss-knife-advanced-maintenance-developer-toolkit\/assets\/screenshot-3.png?rev=3620303","caption":"Reorder &amp; Hide Sidebar \u2014 drag to reorder WordPress admin menu items, rename labels, nest items under another section, or hide items for all admins."},{"src":"https:\/\/ps.w.org\/tso-swiss-knife-advanced-maintenance-developer-toolkit\/assets\/screenshot-4.png?rev=3620303","caption":"Slow Query Monitor \u2014 inspect slow and live database queries when SAVEQUERIES is enabled, export the log, and open a summary from the admin bar."}],"raw_content":"<!--section=description-->\n<p>TSO Swiss Knife gives WordPress developers and site administrators a single, well-organised panel (under <strong>Tools \u203a TSO Swiss Knife<\/strong>) to inspect and control the internal systems that affect performance, stability, and security.<\/p>\n\n<h4>Included modules<\/h4>\n\n<ul>\n<li><strong>Activity History<\/strong> \u2014 Central log of changes across all plugin tools (options edited, database replacements, maintenance mode, admin menu, and more). Pinned as the default favorite for quick access.<\/li>\n<li><strong>Hidden WordPress Profiles<\/strong> \u2014 Apply quick presets and toggle safe performance, content, and privacy constants via JSON under the plugin uploads folder (no wp-config.php editing). Runtime filters apply on the next request.<\/li>\n<li><strong>Cron Manager<\/strong> \u2014 List scheduled WP-Cron events, run or delete non-core hooks, and keep WordPress core cron events read-only (no manual Run \/ Edit \/ Delete).<\/li>\n<li><strong>Action Scheduler<\/strong> \u2014 Inspect WooCommerce Action Scheduler tables, pending actions, and queue health when the library is present.<\/li>\n<li><strong>Debug Mode<\/strong> \u2014 One-click <strong>Developer mode<\/strong> preset for staging (<code>WP_DEBUG<\/code>, <code>WP_DEBUG_LOG<\/code>, <code>SAVEQUERIES<\/code>; errors hidden from visitors), saved as JSON under <code>wp-content\/uploads\/tso-swiss-knife-advanced-maintenance-developer-toolkit\/config\/<\/code>. The tab shows the constants currently in effect (read-only) and copy-paste <code>wp-config.php<\/code> snippets. Constants already defined in <code>wp-config.php<\/code> cannot be overridden.<\/li>\n<li><strong>Options Editor<\/strong> \u2014 Search, inspect, edit, and safely delete <code>wp_options<\/code> rows with core options protected.<\/li>\n<li><strong>Meta Editor<\/strong> \u2014 Browse and edit post and user meta. Without an object ID, search matches meta keys only (not values).<\/li>\n<li><strong>Option Library<\/strong> \u2014 Save named option presets and re-apply them across environments.<\/li>\n<li><strong>Export\/Import TSO Configuration<\/strong> \u2014 Back up and restore selected plugin <code>wp_options<\/code> settings as JSON (Redirects, Staging Mode switches, Login Protect, Slow Query settings, and more). Does not include Debug\/Security JSON under uploads, the Staging mail log, sandbox sessions, or the Slow Query log.<\/li>\n<li><strong>Transients<\/strong> \u2014 Filter by status and purge expired or all transients in bulk (site transients on multisite require a network\/super admin).<\/li>\n<li><strong>WP Constants<\/strong> \u2014 Read-only overview of relevant constants grouped by category.<\/li>\n<li><strong>WP Internals<\/strong> \u2014 Inspect post types, taxonomies, roles, query vars, rewrite tags, and shortcodes.<\/li>\n<li><strong>REST API Controls<\/strong> \u2014 Disable anonymous REST API access or block individual namespaces.<\/li>\n<li><strong>Heartbeat Controls<\/strong> \u2014 Set Heartbeat mode (default \/ disable frontend \/ disable editor \/ disable all) and interval.<\/li>\n<li><strong>Update Manager<\/strong> \u2014 Review pending core, plugin, and theme updates, optionally block update checks (staging), and control update email notifications.<\/li>\n<li><strong>Slow Query Monitor<\/strong> \u2014 Log slow database queries when SAVEQUERIES is enabled, inspect live queries for the current request, export CSV\/JSON, and open a summary from the admin bar.<\/li>\n<li><strong>Search &amp; Replace<\/strong> \u2014 Run dry-run or live serialized-safe search and replace across database tables.<\/li>\n<li><strong>Hooks Inspector<\/strong> \u2014 Browse the live <code>$wp_filter<\/code> global, with callback details and a real-time search filter.<\/li>\n<li><strong>Rewrite Rules Flush<\/strong> \u2014 Soft or hard flush with a single click; search within the current rules table.<\/li>\n<li><strong>Server Files Review<\/strong> \u2014 Scan for unexpected PHP files in uploads and other writable directories; optionally save <code>robots.txt<\/code> \/ <code>.htaccess<\/code> when you confirm.<\/li>\n<li><strong>Redirects<\/strong> \u2014 Manage safe redirect rules stored in the database with import and export support.<\/li>\n<li><strong>Custom 404 Page<\/strong> \u2014 Assign a WordPress page as the site 404 response while keeping the original URL and a real HTTP 404 status (no redirect).<\/li>\n<li><strong>Slug Manager<\/strong> \u2014 Bulk-edit post and term slugs with conflict detection.<\/li>\n<li><strong>Health Report<\/strong> \u2014 Compact checks for risky settings, logs, 404 noise, and related issues; download HTML\/JSON in the plugin UI language.<\/li>\n<li><strong>Reorder &amp; Hide Sidebar<\/strong> \u2014 Drag to reorder WordPress admin menu items, rename labels, nest items under another section, or hide items for all admins.<\/li>\n<li><strong>Users &amp; Sessions<\/strong> \u2014 Review administrators, role-less users, old accounts, and active sessions.<\/li>\n<li><strong>Roles &amp; Capabilities<\/strong> \u2014 Compare roles, apply capability templates, and audit dangerous caps.<\/li>\n<li><strong>Media Cleaner<\/strong> \u2014 Review unattached media, missing attachment files, and unreferenced uploads.<\/li>\n<li><strong>Uploads Disk Footprint<\/strong> \u2014 Scan the uploads folder for size and file-type footprint statistics.<\/li>\n<li><strong>Image Sizes Audit<\/strong> \u2014 Review registered image sizes and disable unused sizes where appropriate.<\/li>\n<li><strong>Security Review<\/strong> \u2014 Highlight common hardening and update issues.<\/li>\n<li><strong>Core File Integrity<\/strong> \u2014 Verify WordPress core files against official checksums and flag unexpected changes.<\/li>\n<li><strong>Login Protection<\/strong> \u2014 Custom login URL, brute-force limits, and related hardening controls.<\/li>\n<li><strong>Comment Anti-Spam<\/strong> \u2014 Local honeypot\/rate-limit rules plus optional reputation or cloud checks (off until you enable them and add keys where required).<\/li>\n<li><strong>Email Diagnostics<\/strong> \u2014 Inspect wp_mail settings and send a test email.<\/li>\n<li><strong>Staging Mode<\/strong> \u2014 For test copies only (all off by default): red STAGING admin-bar label, ask search engines not to list this copy (without changing Settings \u2192 Reading), hold outbound email, pause WP-Cron execution, and keep a short administrator-only mail log in the database (CSV export). Turn everything off before copying the database back to production.<\/li>\n<li><strong>URL &amp; HTTPS Doctor<\/strong> \u2014 Explain whether the saved Home and Site addresses still match https, www, and how you opened the admin. Optional one-click loopback check of this site\u2019s own home URL (redirects are not followed), and an optional count of leftover http:\/\/ copies of that address. Does not change the database.<\/li>\n<li><strong>Server &amp; Runtime<\/strong> \u2014 Read-only view of PHP limits, object-cache drop-in, other wp-content drop-ins, must-use plugins, and optional OPcache reset when the host allows it.<\/li>\n<li><strong>Content Audit<\/strong> \u2014 Find hidden content issues such as empty titles, missing thumbnails, long slugs, and broken shortcodes.<\/li>\n<li><strong>Maintenance Mode<\/strong> \u2014 Toggle a 503 maintenance page with a custom message and IP whitelist.<\/li>\n<li><strong>Plugin Sandbox<\/strong> \u2014 Isolate plugin conflicts via a must-use loader: only your selected plugins load for your admin session.<\/li>\n<\/ul>\n\n<h4>Translations<\/h4>\n\n<ul>\n<li>On <strong>Tools \u203a TSO Swiss Knife<\/strong>, administrators can switch the plugin UI to Catalan (CAT), Spanish (ES), or English (ENG) without changing the site-wide language.<\/li>\n<li>The same choice applies to this plugin\u2019s AJAX responses and admin downloads (for example Health Report HTML\/JSON and URL Doctor messages). It does not change the rest of wp-admin.<\/li>\n<li>Further locales can be contributed via <a href=\"https:\/\/translate.wordpress.org\/\">Translate WordPress<\/a> once the plugin is published.<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>This plugin can optionally contact third-party services. None of these calls run unless a site administrator enables the related feature and, where required, provides an API key.<\/p>\n\n<h4>Comment Antispam (optional)<\/h4>\n\n<p>When <strong>Comment Antispam<\/strong> reputation or cloud checks are enabled, visitor data from comments or protected contact forms may be sent as follows:<\/p>\n\n<ul>\n<li><strong>Stop Forum Spam<\/strong> (<code>https:\/\/api.stopforumspam.org\/api<\/code>) \u2014 Used to look up whether an IP, email address, or username has been reported as spam. Sent on each checked submission (results may be cached briefly). Service: <a href=\"https:\/\/www.stopforumspam.com\/\">Stop Forum Spam<\/a>. <a href=\"https:\/\/www.stopforumspam.com\/legal\">Terms of use<\/a> \u00b7 <a href=\"https:\/\/www.stopforumspam.com\/privacy\">Privacy policy<\/a>.<\/li>\n<li><strong>AbuseIPDB<\/strong> (<code>https:\/\/api.abuseipdb.com\/api\/v2\/check<\/code>) \u2014 Used to check IP reputation. Sends the visitor IP and your AbuseIPDB API key (request header). Service: <a href=\"https:\/\/www.abuseipdb.com\/\">AbuseIPDB<\/a>. <a href=\"https:\/\/www.abuseipdb.com\/legal\">Terms of use<\/a> \u00b7 <a href=\"https:\/\/www.abuseipdb.com\/privacy\">Privacy policy<\/a>.<\/li>\n<li><strong>CleanTalk<\/strong> (<code>https:\/\/moderate.cleantalk.org\/api2.0<\/code>) \u2014 Used for cloud spam filtering when CleanTalk mode is selected. Sends your CleanTalk access key plus sender email, IP, nickname, URL, message content, and post\/page context. Service: <a href=\"https:\/\/cleantalk.org\/\">CleanTalk<\/a>. <a href=\"https:\/\/cleantalk.org\/publicoffer\">Terms of use and privacy policy<\/a>.<\/li>\n<li><strong>Project Honey Pot (HTTP:BL)<\/strong> \u2014 Optional DNS-based IP reputation lookup using your HTTP:BL access key and the visitor IPv4 address. Service: <a href=\"https:\/\/www.projecthoneypot.org\/\">Project Honey Pot<\/a>. <a href=\"https:\/\/www.projecthoneypot.org\/terms_of_use.php\">Terms of use<\/a> \u00b7 <a href=\"https:\/\/www.projecthoneypot.org\/privacy_policy.php\">Privacy policy<\/a>.<\/li>\n<li><strong>Akismet<\/strong> \u2014 When cloud mode is set to Akismet and the Akismet plugin is active, spam checks are handled by Akismet according to its own settings and policies. Service: <a href=\"https:\/\/akismet.com\/\">Akismet<\/a>. <a href=\"https:\/\/akismet.com\/tos\/\">Terms of service<\/a> \u00b7 <a href=\"https:\/\/automattic.com\/privacy\/\">Privacy policy<\/a>.<\/li>\n<\/ul>\n\n<h4>Core File Integrity (optional)<\/h4>\n\n<p>When you run a core integrity scan, the plugin requests official WordPress core checksums from <code>https:\/\/api.wordpress.org\/core\/checksums\/1.0\/<\/code>. Only the WordPress version and locale are sent (no personal data). Service: <a href=\"https:\/\/wordpress.org\/\">WordPress.org<\/a>. <a href=\"https:\/\/wordpress.org\/about\/privacy\/\">Privacy policy<\/a>.<\/p>\n\n<h4>Update Manager language packs (optional)<\/h4>\n\n<p>When an administrator clicks <strong>Install pending translations<\/strong> on the Update Manager tab, WordPress downloads language packs from <code>https:\/\/api.wordpress.org\/translations\/<\/code> (via core <code>Language_Pack_Upgrader<\/code>). Locale and package metadata for pending translations are sent; no personal visitor data. This does not run automatically. Service: <a href=\"https:\/\/wordpress.org\/\">WordPress.org<\/a>. <a href=\"https:\/\/wordpress.org\/about\/privacy\/\">Privacy policy<\/a>.<\/p>\n\n<h4>URL &amp; HTTPS Doctor (optional)<\/h4>\n\n<p>When you click <strong>Check this site<\/strong>, the plugin requests this site\u2019s own home URL through the WordPress HTTP API (a loopback, similar to Site Health). Redirects are not followed. No third-party host is contacted and no personal data is sent. The request only runs after an administrator clicks the button.<\/p>\n\n<h4>Health Report security headers (optional)<\/h4>\n\n<p>Opening <strong>Health Report<\/strong> (or downloading its HTML\/JSON) may request this site\u2019s own home URL with a HEAD request to list common security response headers. Results are cached briefly. No third-party host is contacted and no personal data is sent.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>tso-swiss-knife-advanced-maintenance-developer-toolkit<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or use <strong>Plugins \u203a Add New \u203a Upload Plugin<\/strong> with the ZIP.<\/li>\n<li>Activate the plugin via <strong>Plugins \u203a Installed Plugins<\/strong>.<\/li>\n<li>Navigate to <strong>Tools \u203a TSO Swiss Knife<\/strong>.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20work%20with%20object-cache%20plugins%20like%20redis%3F\"><h3>Does this plugin work with object-cache plugins like Redis?<\/h3><\/dt>\n<dd><p>Yes. Features that use WordPress cache APIs (for example flushing related caches after cleanup tools) call core functions such as <code>wp_cache_flush()<\/code> \/ <code>wp_cache_delete()<\/code>, which delegate to whatever persistent object-cache drop-in is active (Redis, Memcached, etc.).<\/p><\/dd>\n<dt id=\"is%20it%20safe%20to%20delete%20an%20option%20from%20the%20options%20editor%20tab%3F\"><h3>Is it safe to delete an option from the Options Editor tab?<\/h3><\/dt>\n<dd><p>The module protects a list of known WordPress core options. For third-party options, verify in your code or database that they are truly unused before deleting.<\/p><\/dd>\n<dt id=\"does%20enabling%20maintenance%20mode%20block%20the%20admin%3F\"><h3>Does enabling Maintenance Mode block the admin?<\/h3><\/dt>\n<dd><p>No. Logged-in administrators are always bypassed, regardless of IP whitelist settings.<\/p><\/dd>\n<dt id=\"can%20i%20run%20multiple%20plugin-testing%20tools%20at%20once%3F\"><h3>Can I run multiple plugin-testing tools at once?<\/h3><\/dt>\n<dd><p>Use only the <strong>Plugin Sandbox<\/strong> in this plugin. Combining it with other per-user plugin override tools may produce unpredictable results.<\/p><\/dd>\n<dt id=\"does%20update%20manager%20change%20wordpress%20auto-updates%3F\"><h3>Does Update Manager change WordPress auto-updates?<\/h3><\/dt>\n<dd><p>No. Automatic updates are managed only by WordPress core (<strong>Dashboard \u2192 Updates<\/strong>). Update Manager can block update checks on staging sites, hide specific plugin updates, and control update email notifications \u2014 it does not write <code>auto_update_*<\/code> site options or hook <code>auto_update_*<\/code> filters.<\/p><\/dd>\n<dt id=\"when%20should%20i%20use%20staging%20mode%3F\"><h3>When should I use Staging Mode?<\/h3><\/dt>\n<dd><p>Use it on a <strong>cloned \/ staging \/ local copy<\/strong>, right after you copy the live site, and before you place test orders or browse as a customer. Enable only the switches you need (badge, noindex, hold email, pause cron, mail log). Turn them all off before you copy that database back to production. Do not leave Staging Mode options enabled on the live site.<\/p><\/dd>\n<dt id=\"does%20staging%20mode%20change%20settings%20%E2%86%92%20reading%20%28%E2%80%9Cdiscourage%20search%20engines%E2%80%9D%29%3F\"><h3>Does Staging Mode change Settings \u2192 Reading (\u201cDiscourage search engines\u201d)?<\/h3><\/dt>\n<dd><p>No. It adds noindex headers, pauses XML sitemaps, and adjusts robots.txt while the option is on. It does <strong>not<\/strong> filter or save <code>blog_public<\/code>, so opening Settings \u2192 Reading will not permanently lock \u201cDiscourage search engines\u201d after you turn Staging Mode off.<\/p><\/dd>\n<dt id=\"does%20staging%20mode%20send%20customer%20emails%20from%20a%20test%20copy%3F\"><h3>Does Staging Mode send customer emails from a test copy?<\/h3><\/dt>\n<dd><p>Not if you enable <strong>Do not send real emails<\/strong>. WordPress still thinks the mail was accepted, but it never leaves the server. A short copy (recipient, subject, excerpt) is stored in the WordPress database for administrators only (not as a public file under uploads). All Staging Mode switches are off until you turn them on.<\/p><\/dd>\n<dt id=\"does%20pausing%20scheduled%20tasks%20in%20staging%20mode%20delete%20cron%20events%3F\"><h3>Does pausing scheduled tasks in Staging Mode delete cron events?<\/h3><\/dt>\n<dd><p>No. Due events stay in <strong>Cron Manager<\/strong> but are not executed while that Staging Mode option is on. Turn it off on the live site so reminders and queues run again.<\/p><\/dd>\n<dt id=\"does%20url%20%26%20https%20doctor%20change%20my%20site%20address%3F\"><h3>Does URL &amp; HTTPS Doctor change my site address?<\/h3><\/dt>\n<dd><p>No. It only explains mismatches (http vs https, www, folder, and constants locked in wp-config.php). The leftover-http count is also read-only. Use <strong>Search &amp; Replace<\/strong> if you decide to rewrite stored URLs, after a backup \u2014 always run preview first.<\/p><\/dd>\n<dt id=\"can%20i%20manually%20run%20wordpress%20core%20cron%20events%3F\"><h3>Can I manually run WordPress core cron events?<\/h3><\/dt>\n<dd><p>No. Core hooks (for example <code>wp_version_check<\/code> or <code>wp_maybe_auto_update<\/code>) are read-only in Cron Manager: Run, Edit, and Delete are blocked in the UI and in AJAX.<\/p><\/dd>\n<dt id=\"what%20does%20export%2Fimport%20tso%20configuration%20include%3F\"><h3>What does Export\/Import TSO Configuration include?<\/h3><\/dt>\n<dd><p>Selected plugin settings stored in <code>wp_options<\/code> (Redirects, Staging Mode switches, Login Protect, Comment Anti-Spam, Slow Query settings, Health alerts, and similar). It does <strong>not<\/strong> include Debug\/Security\/Hidden Profiles JSON under uploads, sandbox sessions, the Staging mail log, or the Slow Query log. Import overwrites the sections you choose; always export a backup first. Login Protect never imports an enabled custom login URL (to avoid lockouts). If Staging switches arrive enabled, confirm you are on a test site.<\/p><\/dd>\n<dt id=\"does%20the%20cat%20%2F%20es%20%2F%20eng%20language%20switcher%20affect%20downloads%20and%20ajax%3F\"><h3>Does the CAT \/ ES \/ ENG language switcher affect downloads and AJAX?<\/h3><\/dt>\n<dd><p>Yes for this plugin. Health Report HTML\/JSON, URL Doctor messages, and other TSO AJAX\/admin-post responses follow the language selected on <strong>Tools \u203a TSO Swiss Knife<\/strong>. The rest of WordPress admin keeps the site language.<\/p><\/dd>\n<dt id=\"where%20does%20the%20plugin%20write%20files%3F\"><h3>Where does the plugin write files?<\/h3><\/dt>\n<dd><p>Runtime config and other managed files go under <code>wp-content\/uploads\/tso-swiss-knife-advanced-maintenance-developer-toolkit\/<\/code>. The Staging Mode mail log is stored in the database (not under uploads). The Plugin Sandbox may install a must-use loader under <code>mu-plugins<\/code> (via the WordPress Filesystem API) so early plugin filtering can run; that loader is removed when no sandbox sessions remain. The plugin does not write <code>wp-content\/debug.log<\/code> or edit <code>wp-config.php<\/code>.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20edit%20wp-config.php%3F\"><h3>Does this plugin edit wp-config.php?<\/h3><\/dt>\n<dd><p>No. Debug flags, security constants, and hidden-profile toggles are saved as JSON under <code>wp-content\/uploads\/tso-swiss-knife-advanced-maintenance-developer-toolkit\/config\/<\/code> and applied at runtime. Constants already defined in <code>wp-config.php<\/code> always take precedence and cannot be overridden from the plugin.<\/p><\/dd>\n<dt id=\"does%20debug%20mode%20create%20or%20manage%20wp-content%2Fdebug.log%3F\"><h3>Does Debug Mode create or manage wp-content\/debug.log?<\/h3><\/dt>\n<dd><p>No. Debug Mode does not create, truncate, or rotate <code>wp-content\/debug.log<\/code>. Enabling <strong>Developer mode<\/strong> only stores JSON flags (<code>WP_DEBUG<\/code>, <code>WP_DEBUG_LOG<\/code>, <code>SAVEQUERIES<\/code>, and related) in the plugin uploads config folder; WordPress or the server then writes <code>debug.log<\/code> as usual if logging is on. The Debug tab can list and preview common log paths when they already exist. Empty and shrink actions apply only to logs the plugin owns under <code>wp-content\/uploads\/tso-swiss-knife-advanced-maintenance-developer-toolkit\/<\/code> \u2014 never to <code>wp-content\/debug.log<\/code>.<\/p><\/dd>\n<dt id=\"is%20debug.log%20safe%20to%20leave%20on%20a%20live%20site%3F\"><h3>Is debug.log safe to leave on a live site?<\/h3><\/dt>\n<dd><p>Not by default. With <code>WP_DEBUG_LOG<\/code> set to <code>true<\/code>, WordPress writes <code>wp-content\/debug.log<\/code>, which is inside the web root under a predictable name. Depending on your server it may be downloadable by URL, and it can contain absolute server paths, SQL queries and, occasionally, credentials or tokens printed by other plugins. This plugin cannot move the log outside the web root: it only saves <code>WP_DEBUG_LOG<\/code> as <code>true<\/code>\/<code>false<\/code>, and a log path must be defined in <code>wp-config.php<\/code> before plugins load. Recommended: use Developer mode only on staging, block direct access to <code>debug.log<\/code> at the server level (Apache\/nginx rule), or set <code>define( 'WP_DEBUG_LOG', '\/path\/outside\/webroot\/debug.log' );<\/code> in <code>wp-config.php<\/code>. Delete or empty the file when you finish debugging. The plugin's own protected folder under uploads (<code>.htaccess<\/code> deny rules) does not cover <code>wp-content\/debug.log<\/code>.<\/p><\/dd>\n<dt id=\"can%20server%20files%20write%20robots.txt%20or%20.htaccess%3F\"><h3>Can Server Files write robots.txt or .htaccess?<\/h3><\/dt>\n<dd><p>Yes, but only when you explicitly save from the <strong>Server Files Review<\/strong> module. It can write <code>robots.txt<\/code> and <code>.htaccess<\/code> at the site or WordPress root \u2014 not under <code>wp-content\/uploads\/<\/code>. Always review the generated content before saving on production.<\/p><\/dd>\n<dt id=\"who%20should%20use%20search%20%26%20replace%20or%20the%20options%20editor%3F\"><h3>Who should use Search &amp; Replace or the Options Editor?<\/h3><\/dt>\n<dd><p>These tools are intended for experienced administrators and developers. Always run <strong>Search &amp; Replace<\/strong> as a dry-run first and keep a database backup. In <strong>Options Editor<\/strong>, core options are protected, but deleting or editing third-party options can break plugins or themes. When in doubt, export a snapshot or test on staging.<\/p><\/dd>\n<dt id=\"does%20comment%20antispam%20send%20data%20to%20third%20parties%3F\"><h3>Does Comment Antispam send data to third parties?<\/h3><\/dt>\n<dd><p>Only when you enable reputation or cloud checks and, where required, provide API keys. See the <strong>External services<\/strong> section above for each provider, what data is sent, and links to their terms and privacy policies. With all cloud features off, checks run locally (honeypot, rate limits, keyword rules, and similar).<\/p><\/dd>\n<dt id=\"why%20do%20i%20see%20two%20copies%20of%20this%20plugin%20after%20installing%3F\"><h3>Why do I see two copies of this plugin after installing?<\/h3><\/dt>\n<dd><p>That usually means the ZIP folder name was wrong (for example <code>\u2026-main<\/code> from a GitHub download instead of <code>tso-swiss-knife-advanced-maintenance-developer-toolkit<\/code>). Remove the duplicate folder under <code>wp-content\/plugins\/<\/code>, keep only the folder whose name matches the plugin slug, and reactivate.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Slow Query Monitor: redesigned admin-bar item (severity dot, count pills, sectioned submenu, compact SQL with full text on hover); the slow-query log, live counters and duplicate detection now all ignore queries fired by the admin bar itself; fixed singular\/plural wording.<\/li>\n<li>Security: capped the number of outbound-link URLs the public View Counter beacon will track, and fixed Staging Mode mail log CSV formula injection.<\/li>\n<li>Fixed: Database Search &amp; Replace infinite loop, regex preview mismatch and serialized-object corruption.<\/li>\n<li>Fixed: Redirects wildcard loop detection, Content Audit shortcode removal stripping block backslashes, Admin Menu rules hitting the wrong plugin page, robots.txt \"Allow: \/\" override, Image Sizes Audit core-size validation, and leftover legacy .php flag files.<\/li>\n<li>Fixed: several View Counter issues (table upgrade on admin_init, import sources, CSV in Excel, timezone date range, mobile overflow); added a 7\/15\/30-day summary email period and persistent import results; removed the unused \"Keep daily detail for\" setting.<\/li>\n<li>Removed an unused module file (File Footprint).<\/li>\n<li>Docs: FAQ explains that debug.log lives inside the web root (wp-content\/debug.log), what it can leak, and how to block it or move it outside the web root via wp-config.php.<\/li>\n<\/ul>\n\n<h4>1.0.9<\/h4>\n\n<ul>\n<li>New: View Counter module. Counts post, page and outbound-link-click visits with a small front-end beacon, so counting keeps working even behind a full-page cache (LiteSpeed, etc.). No cookies \u2014 de-duplication uses a short-lived, server-side fingerprint only. Adds a \"TSO Views\" column (with icon) to the Posts\/Pages list, sortable by total views, and an importer for totals previously collected by Post Views Counter, WP-PostViews or WP Statistics (WP Statistics' real per-day history is preserved; the other two only expose a lifetime total, so that one lands dated today). Includes a Top Content report (most viewed posts\/pages and most clicked outbound links, filterable by period), a CSV export of the daily detail, and an optional weekly summary email.<\/li>\n<li>Security: real-time email alert when a new Administrator account is created or a user is promoted to Administrator, including the IP address and how the request reached WordPress (normal admin form vs. a silent REST\/AJAX\/XML-RPC request) \u2014 the same pattern seen in real-world \"hidden rogue admin\" incidents caused by a compromised browser extension.<\/li>\n<li>Security: Application Passwords audit \u2014 lists every active Application Password site-wide with its owner, name, creation and last-used dates and last IP, with per-item and \"Revoke All\" buttons, since these survive deletion of the user account that created them.<\/li>\n<li>Security: added \"Application Passwords\" and \"Recent administrator accounts\" checks to the Security Checks table, plus an informational notice explaining that a compromised browser extension can act with a logged-in admin's session without touching the server, which is outside any WordPress plugin's control.<\/li>\n<li>Security: new \"PHP Execution in Uploads\" test and one-click protection \u2014 probes whether the server executes PHP files placed inside wp-content\/uploads (the single control that most often stops an arbitrary-file-upload exploit from becoming a full takeover) and can write the blocking rule into wp-content\/uploads\/.htaccess on Apache\/LiteSpeed.<\/li>\n<li>Security: detects administrator accounts that share their exact creation timestamp with another user \u2014 a known technique some malware uses to hide a rogue admin from \"sort users by newest\".<\/li>\n<li>File Integrity: now also scans wp-content\/uploads for files with an executable script extension (.php, .phtml, .phar\u2026), since uploads should only ever contain media\/data and this is exactly where file-upload exploits drop their payload.<\/li>\n<li>REST API: added an option to block anonymous access to \/wp-json\/wp\/v2\/users specifically (user enumeration), without disabling the rest of the wp\/v2 namespace that the Block Editor needs.<\/li>\n<li>Fixed slow queries flagged by Query Monitor: Login Protect and Admin Menu settings options are now autoloaded (both are read on every request\/admin screen), instead of triggering a dedicated DB query each time. Existing installs are migrated automatically.<\/li>\n<li>Security fix: Login Protect's custom login URL could be revealed to a logged-out visitor on the first request to any wp-admin page, since WordPress core's own redirect used the same filtered login URL. Direct \/wp-admin\/ access is now blocked for logged-out visitors before that redirect can happen.<\/li>\n<li>Fixed: the REST API namespace-blocking option could also block an unrelated namespace that happened to start with the same text (e.g. blocking \"foo\/v1\" also blocked \"foo\/v10\").<\/li>\n<li>Security: the \"user promoted to Administrator\" alert now also fires when a role is added via WP_User::add_role(), not only via the classic role-change dropdown.<\/li>\n<\/ul>\n\n<h4>1.0.8<\/h4>\n\n<ul>\n<li>Admin Menu: the menu manifest (previously an uncached direct DB query on every admin screen) is now cached via the standard WP object cache, compatible with any persistent object-cache backend (Redis, Memcached, LiteSpeed object cache).<\/li>\n<\/ul>\n\n<p>Older versions: see changelog.txt in the plugin folder.<\/p>","raw_excerpt":"Admin toolkit with 40+ modules for cron, debug, security, database, redirects, roles, maintenance, staging copies, and site health reports.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/336098","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=336098"}],"author":[{"embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/deadko"}],"wp:attachment":[{"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=336098"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=336098"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=336098"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=336098"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=336098"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=336098"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}