Skip to content
WordPress.org

ភាសា​ខ្មែរ

  • រូបរាង
  • កម្មវិធីបន្ថែម
  • News
  • អំពី WordPress
  • ទំនាក់​ទំនង
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

Clicks Admin Toolkit

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Clicks Admin Toolkit

By sykologicist
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

Clicks Admin Toolkit packs 139+ individually toggleable administration modules into a single, lightning-fast dashboard — replacing 20 to 30 standalone plugins you’d otherwise install on every WordPress site.

Most WordPress admin toolkits give you 10 or 20 features and lock the rest behind a paywall. Clicks Admin Toolkit ships 139+ production-ready modules across 10 categories — every single one free, with zero upsells, zero ads, and zero nag banners.

The Problem Clicks Admin Toolkit Solves

A typical WordPress installation ends up with a pile of single-purpose plugins:

  • One plugin to duplicate posts
  • One plugin to upload SVGs safely
  • One plugin for SMTP email
  • One plugin to limit login attempts
  • One plugin to disable emojis
  • One plugin for maintenance mode
  • One plugin to hide the WordPress version
  • …and on and on

Each of those plugins loads its own CSS, JavaScript, admin menus, database queries, and update checkers — on every single page load. The result? A bloated, slow, cluttered WordPress admin that takes seconds to respond.

Clicks Admin Toolkit replaces all of them with one plugin that uses exactly one database query.

How 100+ Modules Stay Fast

Zero-Overhead Conditional Loading: When a module is toggled OFF, its PHP file is never included, its class is never instantiated, and zero WordPress hooks are registered. Your server literally does not know the module exists.

Single Autoloaded Database Row: All 100+ module states and their sub-settings are serialized into one single wp_options row. Whether you enable 1 module or all 100, the database cost is identical: one lightweight autoloaded query during WordPress bootstrap.

What You Get: 100+ Modules in 10 Categories

📂 Category 1: Content & Media (10 modules)

  • Duplicate Post / Page / CPT — clone any content into draft with all meta, taxonomies, and custom fields
  • Safe SVG Upload & DOMDocument XML Sanitizer — strips scripts, event handlers, iframes, and XXE attacks before saving
  • Media File In-Place Replacement — swap the physical file behind any attachment without breaking existing embeds
  • Media Library Categories & Taxonomies — organize thousands of assets with hierarchical folder-like categories
  • Restrict Media to Own Uploads — non-admin users only see files they uploaded
  • Drag & Drop Post Reordering — AJAX-powered sortable list tables with persistent menu_order
  • Enable Page Excerpts — adds the Excerpt meta box to WordPress Pages
  • External Links → New Tab — auto-appends target=”_blank” and rel=”noopener noreferrer” to outbound links
  • Auto Image Alt Text Fallback — fills missing alt tags from parent post titles for SEO and accessibility
  • Clean Filename Sanitizer — converts messy uploads like “DSC_0042 (1).JPG” into clean “dsc-0042-1.jpg” slugs

🎨 Category 2: Admin UI & Navigation (10 modules)

  • Admin Menu Organizer — rename, reorder, or hide sidebar items
  • Admin Toolbar Cleaner — strip the WP logo, comments, updates, and “Howdy” greeting
  • Custom Admin Favicon — upload via native Media Library picker
  • Custom Admin Columns — add ID, Thumbnail, Word Count columns to any post type
  • Last Modified Date & Author Column — see who edited what and when
  • Sticky List Table Headers — headers stay pinned while scrolling
  • Wider List Tables — full-width layouts on widescreen monitors
  • Admin Footer Customizer — replace WordPress footer text with your brand
  • Admin Dark Mode — modern dark theme across the entire backend
  • Custom Admin Bar Quick Links — add shortcuts and client support links to the toolbar

🔕 Category 3: Dashboard & Notice Control (10 modules)

  • Admin Notice Drawer & Bell Tray — collects ALL plugin nags and banners into an organized slide-out drawer with a notification bell badge
  • Disable Notices by Role — suppress plugin banners for Editors, Authors, and Subscribers
  • Disable Gutenberg Fullscreen — stops the block editor from auto-maximizing
  • Disable Default Dashboard Widgets — removes Quick Draft, Events, Site Health clutter
  • Custom Dashboard Welcome Widget — create branded onboarding messages with HTML support
  • Highlight Duplicate Post Titles — visual warnings to prevent SEO cannibalization
  • Disable Block Directory Search — stops Gutenberg from querying WordPress.org for third-party blocks
  • Admin Quick Search (Ctrl+K) — instant spotlight search to jump to any admin page
  • Disable Update Nag for Non-Admins — hides “WordPress X.X is available” for users who can’t update
  • Frontend / Backend Quick Switcher — one-click jump between viewing and editing a page

🔐 Category 4: Login & Access Control (10 modules)

  • Custom Secret Login URL — move /wp-login.php to a secret slug like /my-portal to block brute-force bots
  • Custom Login Page Styler — brand your login screen with custom logo, background color, and button color via native Media Library
  • Limit Login Attempts & IP Lockout — block IPs after configurable failed attempts with customizable lockout duration
  • Login Identifier Rules — force username-only or email-only authentication
  • Role-Based Login Redirects — send Subscribers to /my-account, Editors to /edit.php
  • Role-Based Logout Redirects — redirect users to a custom page after logout
  • Two-Factor Authentication (2FA TOTP) — RFC 6238 compliant, works with Google Authenticator, Authy, 1Password
  • Emergency 2FA Bypass Codes — single-use backup recovery keys
  • Hide Login Meta Links — remove Register, Lost Password, and Back to Blog links
  • Auto-Logout Idle Sessions — terminate inactive sessions after configurable timeout

🛡️ Category 5: Security Hardening (10 modules)

  • Disable XML-RPC — blocks brute-force amplification and pingback DDoS
  • Hide WordPress Version — strips version from head, RSS, and REST API
  • Disable Theme & Plugin File Editor — enforces DISALLOW_FILE_EDIT
  • Anti-Spam Honeypot — invisible trap field catches bots without CAPTCHAs
  • Block Author Enumeration — stops /?author=N username discovery scans
  • Restrict REST API — blocks unauthenticated access to WP REST endpoints
  • Admin Login IP Alert — email notification when admin logs in from a new IP
  • Obscure Login Errors — replaces “Invalid username” with generic “Invalid credentials”
  • Disable Self-Pingbacks — stops WordPress from pinging its own URLs
  • Disable Application Passwords — prevents REST API credential generation

⚡ Category 6: Speed & Performance (10 modules)

  • Disable Emojis & DNS Prefetch — removes emoji scripts, inline styles, and DNS prefetch calls
  • Heartbeat API Throttle — reduce background AJAX from 15s to 120s intervals
  • Limit Post Revisions — cap revision count to prevent database bloat
  • Autosave Interval Control — adjust autosave from 15s to 600s
  • Clean HTML Head — strips RSD, WLW Manifest, shortlinks, and generator tags
  • Disable RSS Feeds — removes RSS/RDF/Atom feeds for non-blog sites
  • Defer JavaScript — adds defer attribute to non-critical scripts
  • Remove Query Strings — strips ?ver= from scripts and styles for CDN caching
  • Disable Frontend Dashicons — prevents dashicons.css from loading for logged-out visitors
  • Disable jQuery Migrate — removes legacy compatibility script on modern themes

🛍️ Category 7: WooCommerce Enhancements (10 modules)

  • Disable WooCommerce Nags — clears marketplace promos, setup inbox, and admin banners
  • Orders Extra Columns — adds Customer Email, Payment Method, Shipping Method to orders table
  • Direct Checkout (Skip Cart) — redirect straight to checkout after Add to Cart
  • Auto-Complete Virtual Orders — automatically mark virtual/downloadable orders as Completed
  • Hide Shipping When Free Available — removes paid shipping options when free shipping threshold is met
  • Custom Add-to-Cart Text — change button label to “Buy Now”, “Order Today”, etc.
  • Empty Cart Button — 1-click clear cart action on the cart page
  • Cleanup Expired Coupons — auto-purge expired coupons and orphaned cart transients
  • Currency Symbol Customizer — custom currency symbols, positions, and formats
  • Custom Thank You Page — redirect post-checkout to a custom landing page or funnel

👥 Category 8: User Management (10 modules)

  • Last Login Tracker — log and display exact login timestamps in the Users table
  • Force Password Change on First Login — require temporary passwords to be changed immediately
  • Disable Registration Admin Email — stop admin notification flood from high-volume signups
  • Hide Admin Bar by Role — remove the frontend toolbar for Subscribers, Customers, etc.
  • Restrict WP Admin by Role — redirect non-admin roles away from /wp-admin/
  • Secure 1-Click User Switcher — switch into any user with HMAC SHA-256 cryptographic tokens
  • Enforce Display Name — auto-set public display names to full names, preventing username exposure
  • Terminate All Sessions — emergency 1-click action to log out every user site-wide
  • Prevent Password Reset by Role — disable password resets for restricted accounts
  • Default Registration Role Override — force a specific default role for new registrations

✉️ Category 9: Email & SMTP (10 modules)

  • Built-in SMTP Mailer — configure SMTP host, port, SSL/TLS encryption, and authentication
  • From Name & Email Override — enforce professional sender credentials on all outgoing mail
  • Outbound Email Logger — log every wp_mail() call with recipients, subject, status, and body preview
  • Live SMTP Test Sender — 1-click diagnostic test email with instant success/failure feedback
  • HTML Email Template — wrap plain-text WordPress emails in a clean responsive HTML template
  • Disable Auto-Update Emails — stop core/theme/plugin auto-update notification emails
  • Disable Comment Moderation Emails — suppress comment notification emails to admins
  • Alert on Profile/Email Change — instant security alerts when user profiles are modified
  • BCC Admin on System Emails — blind-copy site admin on customer-facing notifications
  • Custom Email Header Logo — inject brand logo into outgoing email headers via Media Library

🔧 Category 10: Utilities & Maintenance (10 modules)

  • Maintenance Mode — stylish coming-soon screen with HTTP 503 headers for SEO preservation
  • Site Password Gate — protect the entire website behind a master password with custom branding
  • System Health Inspector — PHP version, memory limit, MySQL version, max upload size, extensions
  • Database Optimizer — 1-click cleanup for expired transients, spam, trash, and orphaned postmeta
  • Search & Replace — safe database-wide string replacement with serialized data handling and dry-run preview
  • Admin Activity Audit Log — tracks plugin activations, role changes, and settings modifications
  • Scroll to Top Button — smooth floating back-to-top button on frontend and admin
  • Clear Cache Toolbar Button — instant transient and object cache flush from the admin bar
  • HTTP 503 Maintenance Header — proper Service Unavailable headers during maintenance windows
  • Settings Export & Import — 1-click JSON backup and restore of all 100+ module configurations

Enterprise-Grade Security Built In

Every module follows strict WordPress.org coding standards:

  • HMAC SHA-256 Cryptographic Tokens for user switching — mathematically prevents session tampering
  • DOMDocument XML Sanitizer for SVG uploads — parses with LIBXML_NONET to block XXE and XSS
  • WP_Filesystem API for all disk operations — no forbidden functions like move_uploaded_file()
  • Strict Nonce Verification on every AJAX action and settings save
  • Capability Checks (manage_options) on every administrative operation
  • Output Escaping (esc_html, esc_attr, esc_url, wp_kses_post) on every rendered value

Who Is This For?

  • Agencies & Freelancers: Configure your preferred stack of 100+ admin tweaks once, export the JSON configuration, and deploy across every client site in seconds.
  • WooCommerce Merchants: Speed up checkout with direct cart-skip, auto-complete virtual orders, suppress admin nags, and track customer details right from the orders table.
  • High-Traffic Publishers: Throttle the Heartbeat API, remove query strings, defer scripts, limit revisions, and slash server resource consumption.
  • Security-Focused Admins: Relocate the login URL, disable XML-RPC, enforce 2FA TOTP, restrict the REST API, and block author enumeration scans.

100% Free. No Paywalls. No Locked Features.

Every single module is completely free and fully functional. There is no “Pro” version, no feature restrictions, no teaser locks, and no upsell banners. What you see is what you get — 100+ production-ready tools.

Built by Clicks

Clicks Admin Toolkit is developed and maintained by Rayhan Bajwa (@rayhan.bajwa on Instagram) and the team at Clicks — a digital agency specializing in WordPress development, performance optimization, and WooCommerce solutions.

  • Website: clicks.com.pk
  • Instagram: @rayhan.bajwa
  • Support & Feature Requests: clicks.com.pk/clicks-admin-toolkit

External services

This plugin conditionally connects to the following third-party services only if the administrator explicitly enables the respective module:

  1. Cloudflare Turnstile (Optional — Login CAPTCHA module)

* Domain: https://challenges.cloudflare.com
* Purpose: Provides privacy-preserving bot and abuse protection on the login, registration, and lost password screens when Cloudflare Turnstile is selected in module settings.
* Data sent: Cryptographic challenge token, client IP address, and site verification key.
* Terms of Service: https://www.cloudflare.com/terms/
* Privacy Policy: https://www.cloudflare.com/privacypolicy/

  1. Google reCAPTCHA (Optional — Login CAPTCHA module)

* Domain: https://www.google.com
* Purpose: Provides automated spam and bot protection on the login, registration, and lost password screens when Google reCAPTCHA is selected in module settings.
* Data sent: User interaction response token, client IP address, and site verification key.
* Terms of Service: https://policies.google.com/terms
* Privacy Policy: https://policies.google.com/privacy

Installation

  1. Upload the clicks-admin-toolkit folder to /wp-content/plugins/, or install directly via Plugins > Add New > Upload Plugin.
  2. Activate the plugin through the Plugins screen.
  3. Navigate to Clicks Admin Toolkit in the admin sidebar to access the modular dashboard.
  4. Toggle any module ON, configure its options in the slide-out drawer, and click Save Changes.
  5. Use Ctrl+K or the search bar to instantly find any of the 100+ modules.

FAQ

How many modules does Clicks Admin Toolkit include?

100+ individually toggleable modules organized into 10 categories: Content & Media, Admin UI, Dashboard & Notices, Login & Access, Security, Performance, WooCommerce, User Management, Email & SMTP, and Utilities.

Does activating 100 modules slow down my site?

No. The plugin uses a zero-overhead conditional loader. Disabled modules are never loaded into PHP memory — their files aren’t even included. All settings are stored in a single autoloaded database row, so enabling 1 or 100 modules costs the same: one lightweight query.

Is it compatible with WooCommerce?

Yes. Category 7 includes 10 dedicated WooCommerce modules (direct checkout, auto-complete orders, custom cart text, etc.). These modules only load when WooCommerce is active.

Can I export settings and import them on another site?

Yes. The built-in Settings Export & Import module lets you copy your entire 100+ module configuration as a JSON string and paste it onto any WordPress site running Clicks Admin Toolkit.

Does this plugin run arbitrary PHP code?

No. In strict compliance with WordPress.org security guidelines, this plugin does not use eval(), exec(), move_uploaded_file(), or any arbitrary code execution functions.

Is PHP 8.x supported?

Yes. Fully tested on PHP 7.4, 8.0, 8.1, 8.2, 8.3 and WordPress 6.0 through 7.1+.

What happens if I deactivate the plugin?

All behaviors gracefully revert to WordPress defaults. No core files, database tables, or content are modified. Your settings are preserved in the database and will be restored if you reactivate.

Is there a Pro or paid version?

No. All 100+ modules are completely free with zero restrictions, zero upsells, and zero locked features.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Clicks Admin Toolkit” is open source software. The following people have contributed to this plugin.

Contributors
  • sykologicist

Translate “Clicks Admin Toolkit” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.1.0

  • Major expansion: Added 39 new production-grade modules, expanding the toolkit to 139+ tools.
  • Added 7 Executive Dashboard Widgets on wp-admin: File Change Monitor, Login Radar, Outbound Mail Deliverability, Activity Stream, Broken Link Checker, Database Health Inspector, and REST Rate Limiter.
  • Added 1-Click Starter Preset Packs: Agency Starter, Maximum Security Shield, Speed & Core Web Vitals, and High-Converting Store Pack.
  • Added GeoIP Multi-Currency Switcher with live exchange rate sync and customizable currency flags.
  • Added WooCommerce Conversions suite: Slide-Out Cart Drawer, Sticky Buy Now Bar, Free Shipping Progress Bar, Custom Order Statuses, and Quick Order Notes.
  • Added Advanced Security modules: REST API Rate Limiter, File Integrity & Change Monitor, Disposable Email Blocker, Content Security Policy (CSP) Manager, and Session Timeout Inactivity Modal.
  • Added Content & Workflow tools: Editorial Publishing Calendar, Smart 404 Auto-Redirects, 301/302 Redirect Manager, Broken Link Checker, and Image Lossless Compressor.
  • Added Maintenance & Reliability tools: Automated Scheduled DB Optimizer, Database Backup & Snapshot Generator, and Plugin/Theme Auto-Rollback safeguard.
  • Added interactive “What’s New in v1.1.0” announcement modal with 1-click dismiss.
  • Enhanced Limit Login Attempts with dedicated IP Whitelisting and lockout countdown on wp-login.php.
  • Verified 100% WordPress.org coding standard compliance with zero security flags.

1.0.3

  • Initial public release with 100+ free modular administration tools.
  • 10 organized categories: Content, Admin UI, Dashboard, Login, Security, Performance, WooCommerce, Users, Email, Utilities.
  • Zero-overhead conditional module loader — disabled modules are never loaded.
  • Single autoloaded database row for all 100+ module configurations.
  • DOMDocument SVG XML sanitizer with LIBXML_NONET XXE prevention.
  • HMAC SHA-256 cryptographic tokens for secure user switching.
  • Native WordPress Media Library integration for all image/asset fields.
  • Full WordPress.org automated review compliance.
  • PHP 7.4 – 8.3 and WordPress 6.0 – 7.1+ compatibility.

មេតា

  • Version 1.1.0
  • Last updated 5 នាទី មុន
  • Active installations Fewer than 10
  • WordPress version 6.0 or higher
  • Tested up to 7.1
  • PHP version 7.4 or higher
  • Language
    English (US)
  • Tags
    disable xmlrpcduplicate postlimit login attemptssvg upload
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • sykologicist

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Support
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

ភាសា​ខ្មែរ

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
កូដ​គឺកាព្យ។
The WordPress® trademark is the intellectual property of the WordPress Foundation.