Signocore Toolkit is one free plugin with no license key. Most modules start working the moment you activate it, so read What changes when you activate it before you install it on a live site.
Install the plugin
- Check that your site runs a supported WordPress and PHP version on the platform support page. On a PHP version that is too old, the plugin does not start and shows a notice with the version it needs instead.
- Download the zip file from https://download.signocore.com/signocore-toolkit.
- In WordPress, go to Plugins → Add New Plugin and click Upload Plugin.
- Choose the zip file and click Install Now.
- Click Activate Plugin.
Where the settings live
A Signocore Toolkit menu appears near the bottom of the admin sidebar. It is only visible to administrators. The Settings link under the plugin's name on the Plugins screen opens the General tab.
| Tab | What you set there |
|---|---|
| Overview | Nothing: status cards for maintenance mode, login protection, the mail log, the activity log, cron jobs and the environment, plus recent activity |
| General | Cookie consent, performance and the login screen branding |
| Security | Hidden login page, login protection, XML-RPC, RSS feeds, SVG uploads and automatic updates |
| Maintenance | Maintenance and coming soon mode |
| Blog | Default featured image and related content |
| Social | Which post types get share buttons |
| Shop | WooCommerce options. Only shown when WooCommerce is active |
| Dev Tools | Environment, mail log and activity log settings, plus the log, transient, cron and system status screens |
Each tab saves on its own, so click Save Changes before you switch to another tab.
What changes when you activate it
These modules are on from the start and change your site without any setup:
- Cookie banner: visitors see a consent banner, and Google Consent Mode defaults are set to denied for analytics and advertising. See Cookie consent and Consent Mode.
- Security headers: frontend pages are sent with a Content-Security-Policy, a Referrer-Policy and, on HTTPS sites, a Strict-Transport-Security header. The policy can block scripts that rely on
eval()and forms that submit to another domain. See Security hardening. - XML-RPC: apps and services that log in over XML-RPC stop working, and the site no longer accepts pingbacks.
- REST API: the media endpoint at
/wp-json/wp/v2/mediaonly answers users who can edit posts. - Login protection: an IP address is blocked for 30 minutes after 5 failed logins within 15 minutes. Failed logins show one generic error instead of saying whether the username or the password was wrong. See Login protection.
- Login screen: the login screen gets the Signocore design, and users who have never picked an admin color scheme get the Signocore scheme. Under General → Login Screen, choose Your site for your logo or site icon and your theme's accent color, or WordPress default to keep the original. Neither of those changes the admin color scheme.
- Performance: WordPress keeps at most 10 revisions per post, and the frontend loses the emoji scripts, the embed script, jQuery Migrate and the heartbeat. jQuery moves to the footer where possible. See Performance and media.
- Uploads: new file names are cleaned up, editors and administrators can upload SVG files (sanitized on upload), and WordPress no longer creates its two largest image sizes.
- Logs: the mail log stores a copy of every email the site sends for 30 days, and the activity log records logins and changes, including IP addresses, for 90 days. See Developer tools.
- Share buttons: on the Kadence and Signocore Slate themes, blog posts get social share buttons.
- Admin: the Posts menu is renamed Blog Posts, the admin bar shows the environment and, for administrators, page statistics, a maintenance mode menu and Optimize WP, and Settings → Reading gets an Environment field.
- Production sites: when the environment is production and search engines are allowed, public pages are sent with browser cache headers.
These stay off until you turn them on: the hidden login page, RSS feed removal, maintenance mode, your own automatic update rules, lockout email notifications and blocking of outgoing emails.
Note: On a production site with no
favicon.icofile in its root, the Toolkit creates one the first time a browser asks for it. It converts your site icon when you have set one and the server has the PHP Imagick extension. It copies a Signocore icon only when the site has no site icon. To use your own icon, upload afavicon.icofile to the site root yourself.
First things to check
- Go to Signocore Toolkit → Security and add your own IP address under Trusted IP Addresses, so you cannot lock yourself out. The Your IP Address box on the same tab shows the address the Toolkit sees.
- Open your site in a private browser window, check the cookie banner and click through a few pages.
- Open the browser console on pages with forms, maps, video embeds and checkout, and look for Content Security Policy errors. See Security hardening for how to adjust it.
Updates
Signocore Toolkit updates from Signocore's own update server, not from WordPress.org. New versions appear under Dashboard → Updates and on the Plugins screen, and you install them like any other plugin update.
- The plugin asks the update server for a new version at most every 12 hours. To check right away, click Check again on Dashboard → Updates.
- The update check sends your site's PHP and WordPress version numbers, and a new version is only offered when your site meets its requirements. A site on an older version stays on its current release and keeps working. See platform support.
- After an update, the plugin runs its upgrade routine once: it updates its settings and database tables where needed and clears its own cached data.
Deactivate or delete the plugin
Deactivating Signocore Toolkit switches every module off: the banner, the headers, login protection and the rest. It also clears the plugin's cached data, which lifts current login blocks unless the site keeps its cache in a persistent object cache such as Redis, and removes its scheduled cleanup tasks. Your settings, the mail log and the activity log stay in the database, so everything is back when you activate the plugin again.
Deleting the plugin from the Plugins screen removes all of its data:
- every Toolkit setting, including the Environment field under Settings → Reading
- the mail log and the activity log, with their database tables
- the data it stored per user, such as the admin color scheme choice
- its cached data and scheduled tasks
Important: Deleting cannot be undone. If you want to keep the mail log or the activity log, or reinstall later with the same settings, deactivate the plugin instead.