Product Twenty Site Defaults

Product Twenty Site Defaults

Details
View on WordPress

Site Defaults makes a repeated fresh-site setup visible and deliberate:

  1. Choose an Agency, Business, Blog, or Development preset.
  2. Preview every proposed value beside the site’s current value.
  3. Apply the preset explicitly.
  4. Review future configuration drift and restore or accept each change.
  5. Customize cleanup and access policies without adding a second utility plugin.

The plugin does not add ads, telemetry, remote requests, or dashboard spam. It does not remove content or other plugins.

After a preset is applied, Site Defaults monitors its WordPress options. The plugin reports differences on its settings screen and in Site Health. When a setting needs review, a contextual Site Defaults notice appears throughout WordPress admin with a direct link to the configuration report. It is omitted from the Site Defaults page, where the full report is already visible.

Administrators remain in control: changes are never automatically reverted.

Cleanup policies can disable emoji assets, WordPress post embeds, XML-RPC, comments, author archives, attachment pages, public REST API user enumeration, and Application Passwords. They can also remove generator, shortlink, RSD, and WLW metadata and low-value dashboard widgets.

Integration-sensitive controls include clear cautions. The audited Agency, Business, and Blog presets disable XML-RPC while keeping Application Passwords available for modern REST API integrations and automation. Development leaves cleanup and access behavior at WordPress defaults.

User enumeration controls

Agency and Business reduce two common public user-enumeration paths: anonymous WordPress REST API user listing and public author archives, including the users sitemap.

Blog protects the REST API user listing while retaining author archives for publishing. Development leaves both behaviors at WordPress defaults.

These controls reduce common public user-enumeration paths; they do not guarantee that usernames or author identities cannot be discovered through published content, themes, plugins, feeds, caches, or other integrations.

The unified preset table shows every WordPress setting and cleanup behavior in one place. Choose a built-in preset, then use Customize this preset to make its Preset behavior column editable.

Unchanged values remain inherited from the selected preset. Applying the edited configuration saves it as Custom, records which preset it came from, and establishes the complete Custom configuration as the monitoring baseline.

Details

Plugin code:
product-twenty-site-defaults
Plugin version:
1.0.0
Outdated:
No
WP version:
6.6 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1
Total installations:
0
Last updated:
2026-09-03
Rating:
Times rated:
0
agency
configuration
defaults
settings
site-management