Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Disable unused WordPress features and remove bloat. 104 toggles for performance, security hardening, and WooCommerce — pure PHP, no .
The Off Switch is a WordPress plugin designed to help you disable unnecessary scripts and features that come with a standard WordPress installation. It allows you to manage what is loaded on your site, potentially improving performance and security by removing bloat that is not needed for most sites.
With a user-friendly interface, you can toggle various switches to disable specific scripts and features, such as emoji support, XML-RPC, and the Heartbeat API. This plugin suits WordPress users who want to optimise their site's performance and reduce unwanted overhead.
Best for: WordPress users looking to optimise site performance by removing unnecessary scripts.
What it does well
Where it falls short
The Off Switch provides a straightforward way to manage and disable unwanted WordPress features, making it suitable for those focused on site optimisation.
Abhishek Deshpande's own description of The Off Switch, lightly tidied.
WordPress prioritises backwards compatibility.
That’s a feature. It also means every install ships with things you didn’t ask for.
An emoji CDN script. An oEmbed script. A Windows Live Writer manifest (discontinued 2017).
Dashicons loaded for logged-out visitors. Heartbeat polling every 15 seconds.
A version tag that tells the world exactly which WordPress you’re running.
None of these are bugs. They’re just not needed on most sites.
Disable what you don’t need. Keep what you do.
The Off Switch lets you disable each one, individually.
A live counter shows how many switches are on. A sticky bar keeps Save, the filter, and state chips (All / On / Off / Changed / New) in reach while you scroll. Changed switches are highlighted until you save, and an “unsaved changes” pill shows exactly what you’ve flipped before you commit. Jump between sections with live per-section counts, or copy a WP-CLI command that replicates your whole configuration on another site.
Every switch card states what it removes, what it saves, and what to watch out for. All 104 switches were functionally verified against a live WordPress 7.0 install for this release.
<head>.<link rel="shortlink"> from <head> and HTTP headers. Search engines ignore it.?ver= from scripts, styles, and WP 6.5+ Script Modules so CDNs and proxies cache correctly.<link rel="https://api.w.org/"> from <head>. Safe to remove on standard sites.<link> tags from <head>. Modern browsers no longer act on them. Leave enabled if you publish an RSS feed.<link rel="dns-prefetch"> hints from <head>. Redundant when Emojis and Embeds are already disabled.<style> block in <head> whenever the Recent Comments widget is active. Remove it if your theme already styles the widget.type="text/javascript" and type="text/css" are redundant in HTML5.defer so scripts don’t block HTML parsing. jQuery is never deferred.<head> to just before </body>. jQuery is never moved.<head>. Turning the buffer off restores streamed output for faster TTFB and lower peak memory. Block themes are unaffected./?s=) to the homepage with a 301, preventing bots from triggering repeated database queries. Also removes search forms rendered via get_search_form(). Hardcoded forms in theme templates are not affected./wp-json/oembed/1.0/embed so other sites can embed your content via the oEmbed protocol. Remove it if you don’t want your content embeddable externally. Does not affect your ability to embed others’ content.<link rel="prev/next"> in <head> — two extra DB queries per page load. Google dropped support for these hints in 2019, and modern WordPress no longer outputs them; the switch matters on older installs.Other plugins for securing a site.
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...