PowerSuite Modular Admin Toolkit brings everyday site-management tools into one WordPress dashboard. Customize your admin area, manage content and media, configure login options, and connect WordPress email to your chosen provider.
The free plugin includes 90 modules. Search the Control Center, filter by category, save favorites, and enable the tools that fit your site. You do not need a PowerSuite account or license key to use the included free modules.
Use favorites for frequently accessed modules and the Quick Launcher to find tools without returning to the module list. Save configuration presets or import and export settings for repeatable setup. Keep exported configuration files private.
Disabled modules do not run their feature logic; the shared plugin dashboard and core still load as needed. Test changes on staging, especially when another plugin controls the same behavior. This toolkit does not replace site backups or a complete security solution.
External integrations may need a provider account, credentials, and a paid service plan. Review the service and privacy details below before enabling them.
WP PowerSuite Pro is a separate, paid add-on for sites that need additional tools. Install it alongside the free plugin to manage its modules in the same Control Center.
Explore features and purchase the separate Pro add-on: WP Powersuite Premium.
Examples of what the Pro add-on provides:
These features require the separately installed Pro add-on; their implementations are not included in this WordPress.org download. Pro cards in the free Control Center describe the add-on, not locked functionality bundled in the free plugin.
The free plugin works on its own. If you install Pro, keep this free plugin active alongside it. WordPress.org supplies free-plugin updates; Pro updates come from wppowersuite.com.
AI-assisted features require a supported provider connection. Provider accounts, API usage charges, and data policies are separate from the Pro purchase. Manual form building does not require an AI provider. Review the Pro add-on’s readme for its requirements and external-service disclosures.
The free plugin makes no licensing requests. Enabled integrations, displayed avatars/logos, selected image imports, and explicitly submitted feedback can contact services as detailed below. Disabled modules do not contact these services. Alpine.js is bundled, not CDN-hosted.
Email Delivery uses configured PHP mail, SMTP, or an email provider. WordPress mail and Test email send subject, body, sender, recipients, reply-to, attachments, and authentication information through that connection.
Test connection uses configured credentials. SMTP connects/authenticates without sending mail. API checks request account, permission, domain, or sender information. Emailit and Bird request a recent message record; SendLayer requests a recent delivery-event record. Responses can expose existing account mail information. Netcore and turboSMTP POST synthetic send requests with intentionally invalid sender/recipient addresses and subject/body connection-test to check authentication, without customer messages or attachments. Maileroo only checks locally for a sending key; Test email verifies delivery.
For provider SMTP delivery, an empty host uses the default relay below; an entered host overrides it. The relay receives mail content and SMTP credentials. API User-Agent headers include plugin name/version. Servers receive connection information, including your server’s IP.
Connecting Gmail/Microsoft sends authorization code, application credentials, and callback URL to the provider’s token endpoint; later sends may refresh tokens there. Configured SES event webhooks fetch SNS signing certificates and verified subscription-confirmation URLs containing subscription tokens. Sender-domain health checks query your DNS resolver for domain records.
Delivery webhooks authenticate using provider signatures or configured secrets. Mailgun requires its HTTP Webhook Signing Key and HTTPS.
email.*.amazonaws.com API hosts, email-smtp.*.amazonaws.com SMTP hosts, plus sns.amazonaws.com / sns.*.amazonaws.com certificate and subscription URLs when delivery-event webhooks are enabled. Terms and Privacy.api.sendgrid.com or api.eu.sendgrid.com; SMTP smtp.sendgrid.net. Terms and Privacy.api.mailgun.net or api.eu.mailgun.net; SMTP smtp.mailgun.org or smtp.eu.mailgun.org. Terms and Privacy.api.brevo.com; SMTP smtp-relay.brevo.com. Terms and Privacy.accounts.google.com, oauth2.googleapis.com, gmail.googleapis.com, and www.googleapis.com. Terms and Privacy.login.microsoftonline.com and graph.microsoft.com. Terms and Privacy.api.postmarkapp.com; SMTP smtp.postmarkapp.com. Terms and Privacy.api.mailjet.com; SMTP in-v3.mailjet.com. Terms and Privacy.api.mailersend.com; SMTP smtp.mailersend.com. Terms and Privacy.api.smtp2go.com, us-api.smtp2go.com, eu-api.smtp2go.com, or au-api.smtp2go.com; SMTP mail.smtp2go.com. Terms and Privacy.api.resend.com; SMTP smtp.resend.com. Terms and Privacy.mandrillapp.com; SMTP smtp.mandrillapp.com. Terms and Privacy.https://api.sparkpost.com or https://api.eu.sparkpost.com; Bird platform API keys use https://us1.platform.bird.com or https://eu1.platform.bird.com. SMTP defaults are smtp.sparkpostmail.com or smtp.eu.sparkpostmail.com. Terms and Privacy.api.elasticemail.com; SMTP smtp.elasticemail.com. Terms and Privacy.console.sendlayer.com; SMTP smtp.sendlayer.com. Terms and Privacy.api.smtp.com; SMTP send.smtp.com. Terms and Privacy.https://emailapi.netcorecloud.net or https://apieu.netcorecloud.net. Terms and Privacy.api.turbo-smtp.com or api.eu.turbo-smtp.com; SMTP pro.turbo-smtp.com or pro.eu.turbo-smtp.com. Terms and Privacy.smtp.maileroo.com for both the HTTPS email API and SMTP relay. Terms and Privacy.api.emailit.com; SMTP smtp.emailit.com. Terms and Privacy.https://api.mailbaby.net; SMTP relay.mailbaby.net. Terms and Privacy.Enabled failure alerts send site name, provider name, and redacted error to your configured chat webhook after final delivery failure, at most once per 15 minutes. Errors may retain message-specific information; chat alerts exclude email bodies/attachments. Email alerts also use your selected mail connection and configured recipient, falling back to the admin email.
Slack uses hooks.slack.com: Terms and Privacy.
Discord uses discord.com or discordapp.com: Terms and Privacy.
A developer can explicitly allow another HTTPS webhook host. Review that recipient’s Terms and Privacy Policy before configuring it.
Importing Customizer settings with image downloads requests URLs from the import and creates Media Library attachments. Each host receives the URL, server IP, and HTTP request information. Hosts are arbitrary; review their Terms and Privacy Policy before importing.
Admin Logo displays configured admin-bar/menu image URLs. External hosts receive direct browser requests on settings previews and pages displaying the logo, including front-end admin bars: image URL, viewer IP, browser information, and policy-permitted referrer. Images are not copied into the Media Library. Hosts are arbitrary; review their Terms and Privacy Policy before configuring them.
Automattic’s Gravatar supplies default WordPress avatars. Enabled Local User Avatar prepares a profile-editor fallback; Remove Admin Bar Items requests avatars when replacing the account greeting. Unless another avatar filter overrides them, browsers request https://secure.gravatar.com/avatar/, sending the profile email’s hash, size/default/rating options, and initials if selected. Gravatar receives viewer IP, browser information, and policy-permitted referrer. The profile-editor fallback can render even with Show Avatars off, a local upload, or a hidden preview. Terms and Privacy.
“Submit & Deactivate” stores feedback and a diagnostic snapshot locally (up to 50 records), including site/admin details, plugins/theme, enabled modules, browser/environment, and recent errors.
It sends WP PowerSuite your reason/comments, site URL/hash, administrator/submitting-user emails, plugin/WordPress/PHP/database versions, theme, installed/active plugins, enabled modules, license status (not key), browser/OS, language, user role, hosting/server, memory, cache/CDN, HTTPS, and cron information at https://wppowersuite.com/wp-json/licensor/deactivation-feedback to investigate issues and improve the plugin. Automatic diagnostics exclude raw errors, log excerpts, local user IDs, passwords, API keys, and license keys. The recipient receives server IP and normal HTTP information. Terms and Privacy.
Sharing is optional. “Skip & Deactivate” collects/sends nothing; opening/closing the dialog sends nothing. Developers can override/disable the recipient via constants/filters and must disclose replacement recipients and their Terms/Privacy before collecting feedback.
The separate “You may contact me by email about this feedback” checkbox defaults checked. Submissions include this yes/no preference; uncheck to decline follow-up. It neither sends email nor subscribes you to marketing. Skip sends no contact permission.
Enabled Google Sign-In requires your OAuth Client ID/Secret. Clicking sign-in opens https://accounts.google.com; after approval, your site sends authorization code, client ID/secret, and callback URL to https://oauth2.googleapis.com/token, then uses the access token at https://openidconnect.googleapis.com/v1/userinfo for email, display name, and profile-image URL to sign in/create a local account.
Social sign-in and its CAPTCHA gate use separate first-party HttpOnly browser-binding cookies, expiring after ten minutes and cleared on matching verification. They are not sent to providers or used for tracking. Use HTTPS in production.
Google avatar URL storage defaults enabled. While sign-in is enabled/configured, later avatar views can load saved images directly from their host, including for viewers not signing in; local uploads can override them. Hosts receive image URL, viewer IP, browser information, and policy-permitted referrer. Images are not copied into the Media Library. Disabling new URL storage does not remove saved URLs.
This service is provided by Google: Terms and Privacy.
This plugin ships a shared OAuth HTTP helper that can request access tokens and user profiles from Facebook Graph and GitHub. Google Sign-In in this free plugin uses that helper. Facebook and GitHub sign-in modules ship in the separate Pro add-on; the helper that performs the token and profile requests is part of this plugin.
Requests require the matching module installed, enabled, and configured with your OAuth application. Choosing sign-in opens provider authorization with application ID, callback URL, permissions, and security state. After approval, your site exchanges authorization code/application credentials for an access token, then retrieves account ID, name, permitted email, and profile image to sign in/create a WordPress account. No WordPress password is sent. GitHub may request GET /user/emails with that token and user:email permission; see API documentation.
Facebook uses https://www.facebook.com for authorization and https://graph.facebook.com for token and profile requests: Terms and Privacy.
GitHub uses https://github.com for authorization and tokens, and https://api.github.com for profile and email requests: Terms and Privacy.
Enabled Analytics Integration requires a GA4 Measurement ID. Default Consent Mode waits for a CMP’s analytics-storage consent or the wppsmodule_allow_analytics filter (default false) before requesting scripts/sending pageviews. Disabling Consent Mode allows immediate tracking unless that filter blocks it.
On each included front-end page view, the visitor’s browser requests https://www.googletagmanager.com/gtag/js and then sends the Measurement ID, page URL, and standard GA4 event data to Google Analytics (https://www.google-analytics.com / https://analytics.google.com).
This service is provided by Google: Terms and Privacy.
This integration requires the separate Pro add-on. The free plugin’s admin script still contains the Test connection loader. Enabled reCAPTCHA loads https://www.google.com/recaptcha/api.js and related https://www.gstatic.com assets when you click Test connection. Protected front-end forms exchange browser tokens with Google; your site posts the token and secret key to https://www.google.com/recaptcha/api/siteverify for anti-spam verification.
This service is provided by Google: Terms and Privacy.
This integration requires the separate Pro add-on. The free plugin’s admin script still contains the Test connection loader. Enabled Turnstile loads https://challenges.cloudflare.com/turnstile/v0/api.js when you click Test connection. Protected front-end forms exchange browser tokens with Cloudflare; your site posts the token and secret key to https://challenges.cloudflare.com/turnstile/v0/siteverify for anti-spam verification.
This service is provided by Cloudflare: Terms and Privacy.
Alpine.js 3.17.2 is bundled as minified production JavaScript from the official npm package. Source code, license, and build instructions are available at https://github.com/alpinejs/alpine.
SVG Upload includes svg-sanitize 1.0.0 (GPLv2 or later), with a prefixed PHP namespace to avoid plugin conflicts. Its source and license are available at https://github.com/darylldoyle/svg-sanitizer and in modules/svg-upload/includes/svg-sanitize. Sanitization runs locally. External resources, unsafe CSS and active content are removed; SVG files with ambiguous IDs, excessive complexity or invalid reference graphs are rejected.