You decide what changes on this site.

The free WordPress admin plugin for email logs, custom CSS and hardening

Adminkeep logs every email your site sends, keeps your custom CSS through theme changes, and adds the switches WordPress hides. Every feature is off until you switch it on.

free · GPL · WordPress 6.9+ · on wordpress.org

Adminkeep's Email Log in its own admin menu, listing a shop's sent, failed and unconfirmed emails with status, period and search filters
Every email your site sends, newest first, marked Sent, Failed or Unconfirmed, with filters for status, period and search. Tap to open it full size.

See every email WordPress sends, and which ones failed

email log

Email Log, its own item in the admin menu, lists every email your site sends, newest first, marked Sent, Failed or Unconfirmed. A failed email keeps the error that came back, so a missing password reset has an answer.

The email log, in detail →

  • Works with or without SMTP: it records what WordPress was asked to send and changes nothing about how it is sent.

  • Preview any email the way it went out. Sign-in and password-reset links are removed before anything is stored.

  • Keep entries for a week, or for up to two years.

Custom CSS that survives a theme switch

custom css

WordPress keeps Additional CSS with the theme, so it stays behind when you switch. Adminkeep's Custom CSS belongs to the site instead: it prints on whichever theme is active, and you edit it under Appearance → Custom CSS in WordPress's own code editor.

Or edit it on the site itself: Edit CSS in the admin bar opens a code panel beside the page, and the page restyles as you type. Nothing changes for visitors until you press Save.

Your theme's Additional CSS is left alone. Use both if you like; Adminkeep's CSS prints second, so it wins when the two disagree.

Custom CSS, in detail →

2.0.0

Header & Footer Code

Its sibling in the Appearance menu, for scripts and tags: analytics, Google Tag Manager, verification and chat widgets, in three boxes (head, body and footer) that stay when you change themes.

Header & Footer Code, in detail →

Live CSS editor docked beside the front page of a site, restyling it as the CSS is typed, with Revert and Save below
Edit CSS in the admin bar: the page restyles as you type.

Harden WordPress without a security suite

Seven switches for the doors most sites leave open: comments, plugin installs, sign-ups, XML-RPC, the code editor, the usernames WordPress publishes and the login itself, which can ask for an emailed code after the password. Each one is a setting, not a line in wp-config.php, so you can switch it back off from the same screen. They close common routes; they are not a firewall or a malware scanner.

01

Disable comments

Comments are hidden, not deleted. Bots that post straight to wp-comments-post.php, or through the REST API, are refused too.

Guide →

02

Block plugin & theme installs

In the plugin: Installation Lockdown

No new plugins or themes, from WordPress.org or a ZIP file. Updates keep working, so security releases still arrive, and activating what is installed still works.

Guide →

03

Disable user registration

In the plugin: Registration Lockdown

Stop spam sign-ups and refuse any attempt to create or promote an administrator. With the default settings, WooCommerce checkout and membership plugins keep working.

Guide →

04

Disable XML-RPC

Closes every method at xmlrpc.php, including pingback.ping and system.multicall, and stops the site advertising the API.

Guide →

05

Disable the theme & plugin file editor

In the plugin: Disable File Editing

Removes the built-in code editors from the dashboard, like DISALLOW_FILE_EDIT, but switchable from the admin. On multisite it reaches super admins too.

Guide →

06

Hide your usernames from visitors

In the plugin: Username Privacy

Author pages, ?author=1, the REST users list, sitemaps and embed previews stop naming your accounts to visitors. Anyone logged in sees everything as before.

Guide →

07

Two-factor login by email

In the plugin: Two-Factor Login

The roles you choose enter a six-digit code, emailed to them, after their password. A stolen password alone no longer opens the account, and a recovery link is your way back if email ever fails.

Guide →

Duplicate, rewrite and republish, reorder, replace media

content tools

Duplicate a post or page

In the plugin: Duplicate

Copy any post, page or custom post type in one click. Copying a page can bring its child pages along.

Guide →

Edit a published page without unpublishing

In the plugin: Live Draft

Rewrite and republish: work on a private copy while the live page stays online, then publish the copy to merge it back into the same URL.

Guide →

Reorder posts and pages

In the plugin: Order

Drag posts, pages or custom post types into place on a Sort screen, and the order is used on the front end.

Guide →

Replace an image and keep its URL

In the plugin: Replace Media

Upload a new file over an old one and every link to it shows the new file. The previous version is kept (30 days by default), so a mistake can be undone.

Guide →

Change a page's slug without breaking links

In the plugin: Keep URL

Rename or move a page and its old address redirects to the new one. Renaming a parent fixes every page underneath it.

Guide →

Also included

1.4.0

SMTP

Send your site's email through a real mail server. Presets for Amazon SES, Brevo, Mailgun, SendGrid, Postmark, Zoho and Gmail, a test email that shows the server's own reply, and credentials that can live in wp-config.php.

Guide →

1.10.0

WordPress's own emails, in a clean layout

In the plugin: Nice Default Emails

Password resets, new-user notices, comment and update emails go out with your site's name at the top and a link home at the bottom, instead of as bare text. WooCommerce and every other plugin's email is left alone.

Which emails, in detail →

2.3.0

A contact form, without a form plugin

In the plugin: Contact Form

Name, email and message, emailed to you and kept nowhere on the site. Works as soon as it is on, with a WordPress nonce and no keys, or with Cloudflare Turnstile or Google reCAPTCHA v3. Placed with a block or a shortcode, and visible in Email Log with whether it was sent.

Set it up →

1.3.0

User registration date

A sortable Registered column on the Users screen. WordPress stores the date for every account but doesn't show it; sort newest first to spot a wave of spam sign-ups.

Guide →

One plugin in place of several small ones

An email log, a custom CSS box, a spot for tracking code, a comments switch, an SMTP mailer, a contact form, a duplicate button: jobs that often mean a plugin each. Adminkeep puts its 19 features on one settings screen, built to be fast and then forgotten.

  • Type to find any setting. The feature list narrows as you type, so there is no hunting through tabs.

  • Switches save themselves. Flip one and it is saved on the spot, with a quiet confirmation instead of a page reload.

  • Off until you switch it on. Switch a feature off again and the site behaves as it did before.

  • Hide what you don't use. One option trims the sidebar to the features you have switched on.

Adminkeep Overview screen listing all 19 features and their current status
The full settings screen: every feature listed, filtered by name, saved without a reload.

Questions, answered.

Will this delete my comments?

Not unless you ask it to. Turning Disable Comments on only hides them — a test asserts the comment rows are untouched after a full enable-and-disable cycle.

There is a separate cleanup button that does delete, and it deletes spam and trashed comments only unless you tick the box to include approved ones. It shows the exact count, asks you to confirm, and cannot be undone.

Can I turn it back off?

Yes, instantly. Switch a feature off and your site behaves exactly as it did before. Its saved settings stay, and so does anything Email Log has already logged, so switching it back on picks up where you left off.

What happens to my settings if I delete Adminkeep?

They stay, unless you ask otherwise. Since 2.2.0, deleting the plugin keeps its settings, your Custom CSS and Header & Footer Code, the SMTP and Contact Form settings, the email log, the Keep URL redirects, and the devices Two-Factor Login remembers with its recovery link, so installing it again brings everything back. Deactivating never deletes anything.

To remove all of it when the plugin is deleted, switch on "Delete all Adminkeep data when the plugin is deleted" under Settings → Adminkeep → Plugin settings before you delete it, or run wp adminkeep setting set delete_data=true.

Is Adminkeep on wordpress.org?

Yes. In your WordPress admin go to Plugins → Add New Plugin, search for "Adminkeep" and install it from there. Updates arrive through the normal WordPress Updates screen.

Adminkeep was called WP Pro Admin before it joined the directory. It is the same plugin under a new name.

All questions →

Switch on what you need. Forget the rest.

A free WordPress plugin — GPL, instantly reversible, and updates come to you.

Type to search the whole site.