WP Manifestindependent plugin directory
manifest / multisite / wp-multisitetools

Multisite Multitools

A multitool plugin for Wordpress multisite installations. I was building a handful of niche one-off tool plugins for quality of life interface and security enhancements, and I rolled them into one plugin for convenience of management.

by Brad Salomons · github.com/8r4d/wp-multisitetools

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/8r4d/wp-multisitetools/archive/refs/heads/main.zip

Multisite Tools

A toolkit of network admin utilities for WordPress multisite.

Install

Copy this folder to wp-content/plugins/multisite-tools/ and Network Activate it from Network Admin › Plugins.

Settings

Network Admin › Settings › Multisite Multitools (also linked from the plugin's row on Network Admin › Plugins) has a tab for each module category (Network administration, Content & publishing, Sharing & SEO and Security & privacy), each listing its modules with a checkbox to switch them on or off network-wide. Each tab saves only its own modules. Modules are on by default, including newly added ones, until they're switched off. The exception is the hardening switches on the Security & privacy tab (Disable XML-RPC, Disable file editor, Hide WordPress version), which start off because they can change how sites behave.

The Site colours tab sets a colour for each active site, using the standard WordPress colour picker. The colour marks the site wherever the plugin lists sites: the Calendar, the Posts by Site widget, the Plugin and Theme usage columns, the Copy to site confirmation and, with the Toolbar site colours module, the admin toolbar. Sites without a custom colour get a default from a 10-colour palette based on their site ID, so a site has the same colour on every screen and for every user. Default in the picker clears a custom colour. Deleting a site removes its colour.

Modules

Plugin usage

Adds an Active On column to Network Admin › Plugins:

  • Network-wide: network-activated.
  • N sites: click to expand a list of the sites, each linking to that site's Plugins screen. Archived, spam and deactivated sites are labelled.
  • Not active on any site: installed but unused, so a candidate for removal.

The plugin-to-site map is cached in a site transient. It's cleared whenever any site's active_plugins or blogname changes or a site is added, removed or updated, and it expires after 12 hours as a fallback.

Theme usage

Adds an Active On column to Network Admin › Themes, listing the sites using each theme. A theme that's the parent of a child theme also shows Parent theme on N sites, since it can't be removed while those sites depend on it. Cached and invalidated the same way as Plugin usage, keyed on each site's stylesheet and template options.

Site overview

Adds Network Admin › Sites › Overview: a table of every active site with its last published post and next scheduled post (with "3 days ago" / "in 2 days"), counts of published, scheduled and draft posts and comments awaiting moderation (each linking to the filtered screen on that site), and its theme. Sites are flagged when they:

  • have missed a scheduled post,
  • are hidden from search engines (Settings › Reading › Search engine visibility),
  • have published nothing in 6 months, or
  • have comments to moderate.

A summary above the table counts each kind of problem, or says everything looks healthy. The figures are read fresh on each visit with two queries per 100 sites.

Network search

Adds Network Admin › Dashboard › Search (also in the toolbar under My Sites › Network Admin): search post and page titles across every active site, optionally including content, filtered by type and status. Results show the site (with its colour), type, status and date, newest first, with the match highlighted and Edit and View/Preview links. Up to 50 results per site are shown.

Toolbar site colours

Shows each site's colour (from the Site colours tab) in the admin toolbar:

  • a coloured bar down the left edge of every site in the My Sites menu, and
  • a 3px strip along the bottom of the toolbar on the site you're on, in the admin and on the front end, so it's obvious which site you're editing. Network Admin has no strip, since it isn't a site.

QueueBar

Adds a N Scheduled item to the admin toolbar on each site, for users who can edit posts, linking to that site's scheduled posts. It's hidden in Network Admin. It uses the same toolbar ID as the standalone QueueBar plugin, so having both active shows a single item.

It also adds a Posts by Site widget to Network Admin › Dashboard: a table of every active site (archived, spam and deactivated sites are left out) with its number of published, scheduled and draft posts, plus a totals row. Each count links to that site's filtered Posts screen. The counts are cached in a site transient that's cleared whenever a post changes status or is deleted on any site, a site's name changes, or a site is added, removed or updated, and it expires after an hour as a fallback.

Default author

Lets each site choose an author who is automatically assigned to newly created posts, so an admin can write while posts are attributed to a lower-privileged account (keeping the admin username off the front end). Set it per site under Settings › Default Post Author; the list shows that site's users who can edit posts.

Only new posts of type post are affected. If the post is being created with the current user (or no one) as author, the default author is used instead; an explicitly chosen other author is respected. Nothing happens if the chosen user has since been removed from the site.

It uses the same dpa_default_author option as the standalone Default Post Author plugin, so existing settings carry over. Deactivate the standalone plugin once this is enabled, or each site will get two settings pages.

Calendar

Adds Dashboard › Calendar in Network Admin and on every site, covering every site you can edit posts on (all active sites for super admins):

  • Month: a calendar grid of published and scheduled posts, colour-coded by site, with a site filter and a legend. Scheduled posts have a dashed outline; missed ones a red edge. Click a post for a popup with its site, status, date and author, plus Edit and View/Preview links.
  • Agenda: everything scheduled from now on, grouped by day ("Today", "Tomorrow", then dates), with any missed scheduled posts flagged at the top.

Posts appear at their own site's local date and time, since sites can be in different time zones. Only the post post type is shown (see MST_Calendar::POST_TYPES), drafts aren't included, and each site contributes at most 500 posts per view. Posts are read with one indexed query per 100 sites, so the page stays quick on large networks.

Copy to site

Adds a Copy to site… link to each post and page in the Posts and Pages lists. It opens a screen to choose the target site (any other active site you belong to, or any site for super admins), then creates a draft copy there with the same title, content, excerpt, categories and tags (created on the target if missing) and featured image (copied into the target's media library). You need to be able to create that kind of content on the target site.

Images and links inside the content are copied as-is, so they still point to the original site. If the featured image file can't be read (e.g. media is offloaded to S3), the copy is made without it and you're told. Custom fields and custom post types aren't copied. If the target site uses Default author, the copy gets that site's default author.

Missed schedule fixer

Publishes scheduled posts that WordPress missed. WP-Cron only runs on a site when that site gets a visit, so a quiet site can sit on an overdue post until someone happens by.

  • Scan: a visit to any site, at most every 5 minutes network-wide, checks every active site for posts more than a minute overdue (one UNION query per 100 sites) and pings each late site's wp-cron.php in the background, without slowing the visit.
  • Publish: whenever a site's cron runs (pinged or natural), it publishes up to 20 of its own overdue posts. This also catches posts whose scheduled event was lost, which cron alone never publishes. Publishing on the site itself means plugins active only on that site (auto-posters, newsletters) still see the post go live.

It still needs some traffic somewhere on the network, and the host must allow WordPress to make requests to its own sites (the same requirement as normal WP-Cron). Server cron is more reliable where available.

Social graph

Adds og:image and twitter:image meta tags (plus twitter:card set to summary_large_image) to single posts, pages and custom post types, so shared links on Threads, Facebook, X and others show a preview image. It uses the featured image, falling back to the site's default sharing image (set per site under Settings › Reading › Social sharing), then the site icon; if none exists, no tags are output.

It does nothing on sites running Yoast SEO, Rank Math, All in One SEO, SEOPress or The SEO Framework, which output these tags already. Use the mst_social_graph_skip filter to skip it in other cases.

Hide usernames

Closes the common ways a logged-out visitor can find login names:

  • ?author=N returns a 404 instead of redirecting to /author/<username>/.
  • The REST API /wp/v2/users endpoints return 401.
  • The users sitemap (wp-sitemap-users-1.xml) is removed.
  • author-<username> body classes and comment-author-<username> comment classes are dropped (the ID-based author-N class stays).
  • Failed logins say the username, email or password is incorrect, without saying which.

Logged-in users are unaffected, so the editor's author picker keeps working. Author archive URLs (/author/<slug>/) still use each user's nicename, which defaults to their username. There's no screen for changing it, but WP-CLI can: wp user update <id> --user_nicename=<new-slug>.

Hardening switches

Three small protections on the Security & privacy tab. They start off; switch on the ones you want.

  • Disable XML-RPC: xmlrpc.php returns 403, and the X-Pingback header and RSD link are removed. Bots use XML-RPC to guess passwords and send pingback spam. Don't switch this on if you use Jetpack or an app that publishes over XML-RPC.
  • Disable file editor: removes the theme and plugin file editors everywhere, the same as DISALLOW_FILE_EDIT, so a stolen admin login can't edit code.
  • Hide WordPress version: removes the generator tag from pages and feeds, and on the front end replaces ?ver=<WordPress version> on core scripts and styles with a hash of it, so caches still refresh after updates.

Adding a module

  1. Create includes/modules/class-mst-<slug>.php with a class that has a register() method and static label(), description() and category() methods. category() returns one of the keys in MST_Settings::categories() (add a new category there if none fits). Optionally add an enable() method to reset any state when the module is switched back on, and a static default_enabled() returning false for a module that should start off.
  2. Add '<slug>' => '<Class_Name>' to Multisite_Tools::MODULES in includes/class-multisite-tools.php.