Signocore Toolkit comes with tools for running and debugging a site: a mail log that can hold emails back on staging, an activity log, viewers for transients and scheduled tasks, a system report, user switching and a few admin bar helpers. Most of them live under Signocore Toolkit → Dev Tools, which has its own navigation: Settings, Mail Log, Activity Log, Transients, Cron Jobs and System Status.
Who can see what
"Administrators" below means users who can manage the site's options, which on a normal site is the Administrator role.
| Tool | Where | Who sees it |
|---|---|---|
| Dev Tools settings, Mail Log, Activity Log, Transients, Cron Jobs, System Status | Signocore Toolkit → Dev Tools | Administrators |
| User switching | Users screen and user profiles | Administrators, for users they are allowed to edit |
| Environment label | Admin bar | Everyone who sees the admin bar |
| Performance stats | Admin bar | Administrators |
| Optimize WP | Admin bar on admin screens | Administrators, see Performance and media |
| Plugin and theme downloads | Plugins and Appearance → Themes | Administrators |
| Debug notice | Top of admin screens | Everyone who can open the admin area |
Two environment settings
Signocore Toolkit has two settings with "environment" in the name. They do different things and are easy to mix up.
| Environment | Environment Override | |
|---|---|---|
| Where | Settings → Reading | Signocore Toolkit → Dev Tools → Settings, Environment card |
| Choices | Production, Local, Development, Staging | Auto-detect (default), Development, Staging, Production |
| What it changes | WordPress's environment type, WP_ENVIRONMENT_TYPE, for the whole site. WordPress, themes and other plugins read it |
Only Signocore Toolkit's environment: the admin bar label, whether the mail log holds emails back, and the Environment card on the Overview tab |
| Inside the Toolkit | Cache headers and favicon.ico, see Performance and media. Also feeds Environment Override while that is on Auto-detect | Nothing else |
| Ignored when | WP_ENVIRONMENT_TYPE is defined in wp-config.php. The field then shows that value, locked |
Never |
With Auto-detect, the Toolkit follows WordPress: Local and Development show as Development, Staging as Staging, and anything else as Production.
For a staging site, set Settings → Reading → Environment to Staging, or define WP_ENVIRONMENT_TYPE in the staging site's wp-config.php. Use Environment Override only when you want the Toolkit to treat the site differently from what WordPress reports, for example to hold emails back on a site that WordPress sees as production.
Important: Both settings are stored in the database, so they travel with a database copy. After you copy a database between live and staging, check both, or define
WP_ENVIRONMENT_TYPEin each server's wp-config.php. Environment Type under Dev Tools → System Status shows WordPress's type, followed by the override when one is set.
The environment label
The admin bar shows the Toolkit's environment as a label: Development in green, Staging in amber and Production in a neutral label with a red dot. Everyone who sees the admin bar sees it, on the frontend and in the admin area.
Mail log
The mail log keeps a copy of the emails your site sends. Set it up on Signocore Toolkit → Dev Tools → Settings, in the Mail Log card:
| Setting | Default | What it does |
|---|---|---|
| Log Mode | All emails | All emails logs every email. Blocked emails only logs only the emails that Prevent Sending held back or tried to hold back. |
| Prevent Sending | Off | Holds every outgoing email back, but only while the Toolkit's environment is not Production. |
| Auto-delete After | 30 days | Deletes logged emails older than this once a day. 0 keeps them until you delete them. |
Stop emails on a staging site
A copy of a live site still has real customers, orders and users in it. Hold its emails back so nobody gets a message from the copy:
- On the staging site, set Settings → Reading → Environment to Staging, or set Environment Override to Staging.
- On Signocore Toolkit → Dev Tools → Settings, turn on Prevent Sending and click Save Changes.
- Check the Mail Log card on the Overview tab. It should say Sending blocked.
- Test it: send yourself a password reset email. It shows up on the Mail Log page as Blocked and never arrives. If it shows as Not confirmed, another plugin replaces WordPress's mail function, as explained below.
In Production, Prevent Sending does nothing, even when it is on, so the setting cannot stop mail on your live site as long as the live site reports Production.
Most mail plugins send through WordPress's own mail function, where the block always applies and the log says Blocked. When another plugin replaces that function, the Toolkit cannot guarantee the block. The Mail Log page then shows a warning, and held-back emails are logged as Not confirmed, unless that plugin lets the Toolkit stop them, which turns them Blocked. A plugin that sends through a web API is usually still stopped, because the Toolkit answers its request itself. A plugin that connects to an SMTP server directly still sends the email. Test with a password reset email before you rely on it.
Read the log
Open Signocore Toolkit → Dev Tools → Mail Log:
- The table lists Subject, To, Status and Date, newest first. Search by subject or recipient.
- Click a subject to preview the email with its headers. HTML emails are shown as they would look, with scripts turned off.
- Select emails, choose Delete Selected under Bulk Actions and click Apply, or click Empty Log to delete everything.
Sent means WordPress handed the email over for sending. It does not confirm that the email arrived. Blocked means Prevent Sending held it back. Not confirmed means Prevent Sending tried to hold it back, but another plugin replaces WordPress's mail function and may have sent it anyway.
Links with a secret key, such as password reset, account setup and privacy confirmation links, are stored with the key replaced by [masked], so the log never holds a working link.
Activity log
The activity log records who did what and when. Set it up on Signocore Toolkit → Dev Tools → Settings, in the Activity Log card:
| Setting | Default | What it does |
|---|---|---|
| Record Activity | On | Records the events listed below. |
| Keep Entries For | 90 days | Deletes entries older than this once a day. 0 keeps them forever. |
Each entry stores the date, the user, the IP address, the event and a description. Events without a user, such as scheduled tasks and WP-CLI commands, are marked as System and have no IP address. Visitors who are not logged in, for example on a failed login, are marked as Not logged in.
Note: IP addresses are personal data. Keep the retention period as short as your needs allow, and mention the log in your privacy policy.
What is recorded
| Group | Events |
|---|---|
| Login & Passwords | Successful logins, failed logins, IP addresses blocked by login protection, password reset requests, completed password resets, user switches and switches back |
| Users | Users created (with role and email address), deleted, role changes, email address changes and password changes |
| Plugins, Themes & Updates | Plugins activated, deactivated, deleted, installed and updated; themes changed, installed and updated; WordPress and translation updates; failed automatic updates |
| Content | Posts, pages and other public content published, scheduled, updated, unpublished, trashed, restored and permanently deleted; files uploaded to and deleted from the media library; categories, tags and other public terms created and deleted |
| Settings | Changes to the site address, site title, administration email address, membership and default role, search engine visibility, permalinks, timezone, site language and homepage settings, and to Signocore Toolkit's own settings |
| Toolkit & Privacy | Maintenance mode changes, Optimize WP runs, SVG sanitizing, clearing the log, confirmed privacy requests, erased personal data and personal data exports |
To keep bots from flooding the log, a failed login is recorded at most once per IP address every 15 minutes, and a password reset request once per IP address and username every 15 minutes. Blocks by login protection are always recorded. Updates to published content are recorded with the fields that changed, such as the title, content or slug.
Read the log
Open Signocore Toolkit → Dev Tools → Activity Log. Filter by event group, by user (including System and Not logged in), by date range or by a search for a name, user or IP address, then click Filter. Reset clears the filters. Click Details on an entry for the extra data stored with it. Clear Log deletes every entry, and records that you did.
Transients
Transients are cached values that WordPress, themes and plugins store with an expiry time. Signocore Toolkit → Dev Tools → Transients lists the ones stored in your database with their Name, Value, Expiration and Size. Expired transients are marked Expired, and ones without an expiry time show Never.
- Search by name.
- Delete one transient with Delete in its row, or several with Delete Selected.
- Delete All Expired removes every expired transient at once.
Transients are meant to be temporary, so the code that stored one builds it again when it needs it. On sites with a persistent object cache, such as Redis or Memcached, WordPress keeps transients in that cache instead, so this list can be empty.
Cron Jobs
Signocore Toolkit → Dev Tools → Cron Jobs lists every scheduled task, the WordPress cron events, with its Hook Name, Next Run, Schedule and Arguments. A task whose time has passed is marked Overdue. If tasks stay overdue, the site may get too few visits to trigger WordPress's cron, or WordPress's cron is turned off without a server cron job to replace it.
Click Run Now to run a task at once. It runs in your own request, so it may take a moment. A one-time task is removed after it runs, and a recurring task keeps its next scheduled time.
System Status
Signocore Toolkit → Dev Tools → System Status collects the facts support usually asks for:
- WordPress Environment: versions, addresses, HTTPS, environment type, multisite, permalinks, debug settings, memory limit, upload size, cron and object cache.
- Server Environment: PHP, web server and MySQL versions, PHP limits, cURL and OpenSSL.
- Database: table prefix, database size, size of the autoloaded options and the number of transients.
- Active Plugins, Inactive Plugins, Must-Use Plugins, Theme and Inactive Themes.
Copy to Clipboard copies the whole report as text, ready to paste into a support request. Delete All Inactive on the plugin and theme cards deletes every inactive plugin or every theme except the active theme and its parent. It asks for confirmation, and it cannot be undone. You only see these buttons if you are allowed to delete plugins or themes.
User switching
User switching lets you see the site exactly as another user does, without their password. It is useful for checking what a customer, member or editor sees.
- Go to Users and hover over a user, then click Switch to. On a user's profile you can also click Switch to followed by their name.
- You are now logged in as that user. A bar at the bottom of every page says "Logged in as" with their name.
- Click Switch back to followed by your own name in that bar to return to your own account.
A few rules apply:
- Only administrators can switch, and only to users they are allowed to edit. On a multisite network, a site administrator cannot switch to a super admin.
- You cannot switch again while you are switched. Switch back first.
- The way back only works in the browser session you switched in, for up to two days. If you log out while switched, you are logged out completely and log in again as yourself.
- Both switches are recorded in the activity log.
Admin bar helpers
Performance stats
Administrators see a summary such as 42Q | 12 MB | 0.184s in the admin bar: database queries, peak memory and load time of the current page. Hover over it for DB Queries, Peak Memory with the memory limit, Load Time, PHP Version, the WordPress version and, when it is active, the WooCommerce version. The numbers are measured when the admin bar is built, near the end of the page.
Plugin and theme downloads
Administrators can download any installed plugin or theme as a zip file, for example to move it to another site:
- Plugins: click Download in the plugin's row.
- Themes: open a theme's details under Appearance → Themes and click Download.
The file is named after the folder and version, such as signocore-toolkit-4.0.0.zip. Hidden files and folders such as .git, Markdown files, a few development config files, Composer's development packages and files listed in a .distignore file are left out.
Debug notice
When WP_DEBUG is on in wp-config.php, every admin screen shows "Signocore Toolkit: Debugging is enabled. Please disable it in production environments." Dismissing it only hides it until the next page load. Turn WP_DEBUG off on your live site to remove it.
While WP_DEBUG is on, the Toolkit also makes PHP report every error. Errors are shown on the page unless WP_DEBUG_DISPLAY is false, and they are never printed into AJAX, REST API, XML-RPC or WP-CLI responses, where they would break the editor and background requests.