PHPackages                             giantpeach/wp-sane-defaults - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Security](/categories/security)
4. /
5. giantpeach/wp-sane-defaults

ActiveWordpress-muplugin[Security](/categories/security)

giantpeach/wp-sane-defaults
===========================

WordPress mu-plugin that fixes common insecure and annoying defaults.

011PHP

Since Mar 4Pushed 2mo agoCompare

[ Source](https://github.com/Giant-Peach-Design/wp-sane-defaults)[ Packagist](https://packagist.org/packages/giantpeach/wp-sane-defaults)[ RSS](/packages/giantpeach-wp-sane-defaults/feed)WikiDiscussions main Synced 1mo ago

READMEChangelogDependenciesVersions (1)Used By (0)

WP Sane Defaults
================

[](#wp-sane-defaults)

WordPress mu-plugin that fixes common insecure and annoying defaults.

What it does
------------

[](#what-it-does)

**Security:**

- Disables the Users REST API endpoint for unauthenticated requests
- Disables XML-RPC entirely
- Removes the X-Pingback header
- Disables file editing via the admin
- Obscures login error messages to prevent user enumeration
- Disables author archives (redirects to homepage)
- Removes WordPress version from scripts, styles, and meta tags

**Performance/Cleanup:**

- Removes emoji scripts and styles
- Removes oEmbed discovery links
- Removes DNS prefetch for `s.w.org`
- Only loads comment-reply JS when actually needed
- Removes unnecessary meta tags (generator, WLW manifest, RSD link, shortlink, REST API link, feed links)
- Disables self-pingbacks
- Hides update nags for non-admin users

Installation
------------

[](#installation)

Drop `wp-sane-defaults.php` into `wp-content/mu-plugins/`.

Requirements
------------

[](#requirements)

- PHP 8.0+
- WordPress 6.0+

###  Health Score

21

—

LowBetter than 19% of packages

Maintenance61

Regular maintenance activity

Popularity6

Limited adoption so far

Community6

Small or concentrated contributor base

Maturity11

Early-stage or recently created project

 Bus Factor1

Top contributor holds 100% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

### Community

Maintainers

![](https://www.gravatar.com/avatar/e66b81ebd507f82992c477ab3e567933436d0a810a0886e6005b2e8b0fdf317a?d=identicon)[Giant Peach](/maintainers/Giant%20Peach)

---

Top Contributors

[![tom-gurney](https://avatars.githubusercontent.com/u/6736496?v=4)](https://github.com/tom-gurney "tom-gurney (4 commits)")

### Embed Badge

![Health badge](/badges/giantpeach-wp-sane-defaults/health.svg)

```
[![Health](https://phpackages.com/badges/giantpeach-wp-sane-defaults/health.svg)](https://phpackages.com/packages/giantpeach-wp-sane-defaults)
```

###  Alternatives

[defuse/php-encryption

Secure PHP Encryption Library

3.9k162.4M212](/packages/defuse-php-encryption)[roave/security-advisories

Prevents installation of composer packages with known security vulnerabilities: no API, simply require it

2.9k97.3M6.4k](/packages/roave-security-advisories)[mews/purifier

Laravel 5/6/7/8/9/10 HtmlPurifier Package

2.0k16.7M112](/packages/mews-purifier)[robrichards/xmlseclibs

A PHP library for XML Security

41278.1M118](/packages/robrichards-xmlseclibs)[bjeavons/zxcvbn-php

Realistic password strength estimation PHP library based on Zxcvbn JS

86917.5M63](/packages/bjeavons-zxcvbn-php)[enlightn/security-checker

A PHP dependency vulnerabilities scanner based on the Security Advisories Database.

33732.2M110](/packages/enlightn-security-checker)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
