manifest / performance / one-file-katana
One File Katana
A lightweight, single-file WP plugin to slash bloat and enhance stealth security. / WordPressの不要な出力を一振りで削ぎ落とし、軽量化とステルスセキュリティを実現。
by masato shibuya (Image-box Co., Ltd.) · github.com/ms13th-cyber/one-file-katana · website
★ 0stars
0forks
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/ms13th-cyber/one-file-katana/archive/refs/heads/main.zipReadme
One File Katana
A lightweight, single-file WordPress plugin designed to strip away unnecessary code and bolster your site's stealth security with a single "slash."
Key Features
- Extreme Bloat Removal (Stage 1): Eliminates heavy WP-native scripts including Emojis, oEmbed links, and newly targets Gutenberg-specific bloat (Global Styles CSS and SVG filters) to maximize page rendering speed.
- Stealth Security (Stage 2): Strips out version queries from JS/CSS and hides the
wp_generatortag. Now fully disables Author archives to prevent user enumeration through URL manipulation. - API Defense: Disables REST API user endpoints and Application Passwords to close modern unauthorized access routes.
- Entry Point Hardening: Fully disables XML-RPC and removes Pingback headers to mitigate DDoS risks.
- Resource Optimization (Stage 3): Disables the Heartbeat API in the admin dashboard to reduce server CPU load during editing.
- True Single-File Architecture: Now includes a built-in update checker within the single
.phpfile, eliminating external library dependencies while supporting GitHub-based updates.
Installation
- Upload the
one-file-katana.phpfile directly to your/wp-content/plugins/directory. - Activate the plugin through the 'Plugins' menu in WordPress.
- The plugin starts working immediately—no configuration screens required.
主な機能(日本語)
WordPressの不要な出力を「一振り」で削ぎ落とし、サイトの気配を消してセキュリティを向上させる、単一ファイル構成の超軽量プラグインです。
- 徹底的な軽量化 (Stage 1): 絵文字やoEmbedに加え、Gutenberg固有の不要なインラインCSS(Global Styles)やSVGフィルタを排除。現代のWP環境に最適化されたレンダリング速度を提供します。
- ステルス性能 (Stage 2): JS/CSSのバージョン情報除去に加え、投稿者(Author)アーカイブを完全に無効化。URLからのユーザー名特定を徹底的に防ぎます。
- API防御の強化: REST APIの制限に加え、アプリケーションパスワード機能も無効化。現代的な攻撃経路を遮断します。
- 攻撃窓口の閉鎖: XML-RPCの無効化とPingback情報の削除により、DDoSやブルートフォース攻撃のリスクを低減します。
- サーバー負荷の低減 (Stage 3): 管理画面のHeartbeat APIを制御し、編集中のバックグラウンド通信によるサーバー負荷を抑制します。
- 究極の単一ファイル構成: 外部ライブラリを一切使わず、独自のアップデート検知ロジックを統合。GitHub経由の更新通知を受け取りつつ、ファイル1つで完結する美学を追求しました。
インストール
one-file-katana.phpを/wp-content/plugins/にアップロードします。- 管理画面の「プラグイン」から有効化してください。
- 有効化した瞬間から、自動的にすべての最適化と隠蔽が適用されます。設定画面はありません。
開発者情報
- Author: masato shibuya (Image-box Co., Ltd.)
- Version: 1.1.5
- GitHub: https://github.com/ms13th-cyber/one-file-katana/
Read the full README on GitHub →
Releases
| Tag | Published |
|---|---|
| v1.1.6 | May 21, 2026 |
| v1.1.5 | May 7, 2026 |
| v1.1.4 | May 7, 2026 |
| v1.1.3 | May 7, 2026 |
| v1.1.2 | May 7, 2026 |
| v1.1.1 | May 7, 2026 |
| v1.1.0 | May 7, 2026 |
| v1.0 | May 1, 2026 |
These releases are tags only. The author does not attach a packaged zip, so there are no download counts to report.