plugin-icon

Adminkeep – Email Log, Custom CSS, Disable Comments, Site Lockdown & Admin Enhancements

Email log, custom CSS, disable comments, site lockdown and more admin enhancements. Every feature is off until you switch it on.
Version
2.4.0
Active installations
50
Last updated
Sep 30, 2026
Adminkeep – Email Log, Custom CSS, Disable Comments, Site Lockdown & Admin Enhancements

You decide what changes on this site.

Adminkeep is a set of tools under that one idea. Site Lock stops things changing behind your back — no new comment, no new plugin, no new user. Content makes the changes you do want safe to make.

Every feature is a single switch, off until you turn it on. Switching one off never leaves you repair work: the locks work purely through WordPress filters, so your site is exactly as it was, and what you made with the Content features stays where you put it.

Site Lock

  • Disable Comments — comments off everywhere, including direct POSTs from spam bots and the REST API. Nothing is written to your database, so switching it off brings every comment back. An optional cleanup button deletes spam and trashed comments, after showing you the exact count. Guide
  • Registration Lockdown — stops new accounts being created, and refuses creation of or promotion to administrator. Blocked attempts are logged. Guide
  • Disable XML-RPC — closes xmlrpc.php completely, including pingbacks and system.multicall. Guide
  • Disable File Editing — removes the built-in plugin and theme file editors, reversibly.
  • Installation Lockdown — no new plugins or themes, from WordPress.org or a ZIP, and no replacing one by uploading a ZIP, for anyone. Updates keep working, so security releases still reach your site. Guide
  • Username Privacy — keeps your usernames out of public view. Author pages, the ?author=1 probe, the REST users list, author sitemaps and embed previews stop naming your accounts to visitors; anyone logged in sees everything as before. Nothing is written, so switching it off reopens it all. Guide

Appearance

  • Custom CSS — CSS that belongs to your site instead of your theme. Edit it under Appearance with WordPress’s own code editor, or open Edit CSS from the admin bar on any page and watch the page restyle as you type, the way the Customizer’s CSS box used to. It stays when you switch themes, and your theme’s Additional CSS is left alone.
  • Header & Footer Code — a home for the snippets services ask you to paste into your site: analytics and verification tags in the head, a tag manager’s fallback just after the body opens, chat widgets and scripts in the footer. Three boxes under Appearance with WordPress’s code editor, printed on the front end exactly as you saved them, and kept when you change or update your theme. Each box shows who last changed it and when. Only administrators allowed to post unfiltered HTML can edit them.

Email

  • SMTP — Send your site’s email through an SMTP server so password resets and form messages arrive. Presets for Amazon SES, Brevo, Mailgun, SendGrid, Postmark, Zoho and Gmail; a test email that shows the server’s own error; settings can live in wp-config.php. Moving from WP Mail SMTP? One click copies its SMTP connection settings. Guide
  • Email Log — Email Log, in its own item in the admin menu by default (or under Tools, if you prefer), lists the email your site sends, with recipient, subject and whether it was sent or failed, plus filters by status and date and a search. Open any email to see its sender and headers, and the email itself the way it looked when it went out, with remote images blocked. Content storage can be switched off to keep only the envelope. Password-reset and sign-in links are removed before an email is stored. Works with or without the SMTP feature, and with other SMTP plugins too.
  • Nice Default Emails — WordPress’s own plain-text emails (password resets, new-user and comment notices, update reports, personal data requests, and multisite sign-ups), and Adminkeep’s own contact form, go out in one clean HTML layout headed by your site’s name, with links you can click. WooCommerce and other plugins’ emails, and anything already sent as HTML, are left exactly as they are. No settings. wp adminkeep emails send --all --to=you@example.com shows every one of them in your own inbox.
  • Contact Form — one simple form for any page: name, email and message, as a block or the [adminkeep_contact_form] shortcode. Messages are emailed to you through WordPress’s own mailer, so the SMTP feature delivers them and Email Log shows whether each one went out, with the server’s error if it did not. Works out of the box, protected by a WordPress nonce that needs no keys (not for sites that cache their pages), or by Cloudflare Turnstile or Google reCAPTCHA v3 with your own free keys. Nothing is stored. The form prints its own small style and script with itself, so nothing extra loads on other pages, and the spam check’s script loads only on pages that show the form.

Admin

  • User Registration Date — a sortable Registered column on the Users screen. WordPress records when every account was created but never shows it; this does, for every existing user, and newest-first sorting makes a wave of spam signups easy to spot. Guide

Content

  • Duplicate — copy any post or page as a draft. Custom fields, taxonomies, the featured image and page builder layouts (Elementor, ACF) come along intact, and the original is never modified. Guide
  • Live Draft — rework a published page in a private working copy, then publish it over the original. Same ID, same URL, and the old version is kept as a revision. Guide
  • Keep URL — rename or move a page and its old address keeps working, child pages included. Fills the gaps WordPress leaves for pages and leaves posts to core. Guide
  • Order — drag posts into the order you want on a dedicated Sort screen, one post type at a time. Lists that already ask for their own order, such as WooCommerce products and search results, are left alone. Guide
  • Replace Media — upload a new version of a file over the old one. Same file type keeps the same URL; a different type updates the posts that use it and redirects the old address. Guide

Performance

A feature you have not enabled registers zero hooks and loads zero assets.

Links

External services

Adminkeep connects to no outside service unless you switch on a feature that needs one and set it up. Two features can: SMTP sends your site’s email through the mail server you enter, and the Contact Form uses the spam check you choose (its WordPress nonce option uses none). Nothing is sent to Adminkeep.

Cloudflare Turnstile (Contact Form, when you choose it). On pages that show the form, the visitor’s browser loads Cloudflare’s script from challenges.cloudflare.com, which receives the visitor’s IP address and browser details in order to tell people from bots. When the visitor presses Send, your site sends Cloudflare your secret key and the check’s one-time token, and nothing else, to confirm it. Terms: https://www.cloudflare.com/website-terms/ — Privacy policy: https://www.cloudflare.com/privacypolicy/

Google reCAPTCHA v3 (Contact Form, when you choose it). On pages that show the form, the visitor’s browser loads Google’s script from www.google.com (and the code it needs from www.gstatic.com), which receive the visitor’s IP address and browser details in order to score the visit. When the visitor presses Send, your site sends Google your secret key and the check’s one-time token, and nothing else, to confirm it. Terms: https://policies.google.com/terms — Privacy policy: https://policies.google.com/privacy

WP-CLI

Everything on the Adminkeep settings screen, plus the Custom CSS, Header & Footer Code, SMTP and Contact Form screens, can be done from a shell with wp adminkeep.

wp adminkeep feature list — every feature and whether it is on wp adminkeep feature enable disable_comments — switch a feature on (or `disable` it) wp adminkeep feature set order post_types=post,page — change a feature's settings wp adminkeep setting set hide_unused=true — change a plugin-level setting wp adminkeep comments purge — delete spam and trashed comments, in batches wp adminkeep css set site.css — replace the Custom CSS from a file wp adminkeep code set head analytics.html — replace one Header & Footer Code box (head, body or footer) from a file wp adminkeep smtp set --host=smtp.example.com --port=587 — configure SMTP wp adminkeep smtp test you@example.com — send a test email and see the server's reply wp adminkeep emails send --all --to=you@example.com — see WordPress's own emails in the Nice Default Emails layout wp adminkeep smtp import wp-mail-smtp — copy the SMTP connection settings from WP Mail SMTP wp adminkeep contact-form set --provider=turnstile --turnstile-site-key=<key> — set up the contact form's spam protection (the secret goes in with `--turnstile-secret-stdin`) wp adminkeep contact-form get — the contact form's settings, and whether it is live

Run wp help adminkeep for the full reference. A change made here is cleaned and checked exactly as it is on the screen, and a mistyped value is refused rather than guessed at.

Freeon paid plans
Tested up to
WordPress 7.1.2
This plugin is available for download for your site.