{"id":365187,"date":"2026-09-16T05:08:17","date_gmt":"2026-09-16T05:08:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/debloater\/"},"modified":"2026-09-17T10:09:55","modified_gmt":"2026-09-17T10:09:55","slug":"hakeemify-debloater","status":"publish","type":"plugin","link":"https:\/\/fa.wordpress.org\/plugins\/hakeemify-debloater\/","author":23561497,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.10.0","stable_tag":"0.10.0","tested":"7.1.1","requires":"6.5","requires_php":"8.1","requires_plugins":null,"header_name":"Hakeemify Debloater","header_author":"Hakeemify","header_description":"Audits a WordPress site against the facts, then applies only the changes you approve \u2014 each with its own risk level, a recovery point taken first, and an automatic rollback if verification fails.","assets_banners_color":"112036","last_updated":"2026-09-17 10:09:55","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/scornik\/debloater","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":80,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.10.0":{"tag":"0.10.0","author":"hakeemify","date":"2026-09-17 10:09:55","revision":3700037},"0.9.0":{"tag":"0.9.0","author":"hakeemify","date":"2026-09-16 05:08:05","revision":3697920}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3697915,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3697915,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3697925,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3697925,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.10.0","0.9.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3697915,"resolution":"1","location":"assets","locale":"","width":1227,"height":802},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3697915,"resolution":"2","location":"assets","locale":"","width":1252,"height":1668},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3697915,"resolution":"3","location":"assets","locale":"","width":909,"height":833}},"screenshots":{"1":"The dashboard: a score out of 100 for Database, Admin and Assets, never averaged into one number, and what the scan found, with the Fix safe issues button.","2":"One finding in full: what was found, why it matters, the evidence with the fact each value came from, the risk, the confidence, and what the change would and would not do.","3":"The report after a change: each score before and after, and what was measured on the site before and after, as counts rather than time."}},"plugin_section":[],"plugin_tags":[57949,3786,263747,187,247],"plugin_category":[52,54],"plugin_contributors":[280992],"plugin_business_model":[],"class_list":["post-365187","plugin","type-plugin","status-publish","hentry","plugin_tags-bloat","plugin_tags-cleanup","plugin_tags-debloat","plugin_tags-optimization","plugin_tags-performance","plugin_category-performance","plugin_category-security-and-spam-protection","plugin_contributors-hakeemify","plugin_committers-hakeemify"],"banners":{"banner":"https:\/\/ps.w.org\/hakeemify-debloater\/assets\/banner-772x250.png?rev=3697925","banner_2x":"https:\/\/ps.w.org\/hakeemify-debloater\/assets\/banner-1544x500.png?rev=3697925","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/hakeemify-debloater\/assets\/icon-128x128.png?rev=3697915","icon_2x":"https:\/\/ps.w.org\/hakeemify-debloater\/assets\/icon-256x256.png?rev=3697915","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/hakeemify-debloater\/assets\/screenshot-1.png?rev=3697915","caption":"The dashboard: a score out of 100 for Database, Admin and Assets, never averaged into one number, and what the scan found, with the Fix safe issues button."},{"src":"https:\/\/ps.w.org\/hakeemify-debloater\/assets\/screenshot-2.png?rev=3697915","caption":"One finding in full: what was found, why it matters, the evidence with the fact each value came from, the risk, the confidence, and what the change would and would not do."},{"src":"https:\/\/ps.w.org\/hakeemify-debloater\/assets\/screenshot-3.png?rev=3697915","caption":"The report after a change: each score before and after, and what was measured on the site before and after, as counts rather than time."}],"raw_content":"<!--section=description-->\n<p>Most optimisation plugins ask you to trust a switch. Debloater asks you to read\na finding.<\/p>\n\n<p>It scans your site, records what it found, and shows you each change it could\nmake: what the change does, what it might break, how confident it is, and how\nto get back. Nothing is applied until you confirm it, and every apply takes a\nrecovery point first. After applying, it checks your site, and if the check\nfinds a page broken it puts everything back.<\/p>\n\n<h4>What it does<\/h4>\n\n<p><strong>Scans, and records facts.<\/strong> Which core features are loading, how many\nrevisions and expired transients you have, what your autoloaded options weigh,\nwhich of your plugins do the same job, and what your admin shows. Each scan is\nstored with the facts it read.<\/p>\n\n<p><strong>Explains every finding.<\/strong> Each finding names the facts it came from, so you\ncan disagree with it and leave it alone.<\/p>\n\n<p><strong>Scores each area separately, and says what it covers.<\/strong> The Debloat Score\nis three scores out of 100 \u2014 Database, Admin and Assets \u2014 and they are not\naveraged into one number. None is a speed measurement. Each counts what your\nsite has that Debloater offers to change, and not what WordPress does out of\nthe box: a fresh install scores 100. Something it reports but cannot change for\nyou, such as two plugins doing the same job or XML-RPC being on, is listed as a\nfinding and costs nothing. Each finding that costs points says how many. When\neverything left in an area is behind deleting data \u2014 which Fix Safe Issues never\ndoes \u2014 the score says what is left and offers to review deleting it. If any\ncheck in an area could not run, that area is shown as not scored, with the\nreason, rather than as clean.<\/p>\n\n<p><strong>Reads your admin as you.<\/strong> Findings about the admin come from a request the\nscan makes to your dashboard, signed in as the person scanning, and describe\nwhat that person sees. The dashboard has 30 seconds to answer a scan started\nfrom the dashboard, and 120 seconds from WP-CLI. From WP-CLI, run the scan with\n    --user=; without it, the admin is not read and the scan\nsays so.<\/p>\n\n<p><strong>Plans before it acts.<\/strong> You get a preview: every change, its risk level, what\nit touches, and the recovery point that will be taken. The same scan and the\nsame profile always produce the same plan.<\/p>\n\n<p><strong>Takes a recovery point first.<\/strong> Before anything changes, the current\nconfiguration is captured. Before rows are deleted, the rows themselves are\ncaptured, and the deletion does not run unless that capture completed.<\/p>\n\n<p><strong>Verifies, then rolls back if it has to.<\/strong> After applying, Debloater requests\nyour front page, a post, your dashboard and your REST API, and if one of them\nfails, it puts everything back and tells you what failed. It also requests the\nlogin page, and warns rather than rolling back if that looks wrong. When you\napply from the dashboard, it also asks a fresh request whether each change\nloaded, and puts everything back if one did not. From WP-CLI the same checks run\nas the administrator you name with <code>--user=&lt;an administrator&gt;<\/code>, and a failure\nputs everything back there too. Without <code>--user<\/code>, or on a site that cannot make\nrequests to itself, these checks cannot run; the change stays, and Debloater\nreports which checks could not run.<\/p>\n\n<p><strong>Diagnoses a request.<\/strong> Pick a page \u2014 the home page, a post, the shop, the\ncart, the checkout, the dashboard, or any address on your site \u2014 and Debloater\nrequests it once with its profiler switched on. It records how long the request\ntook, its peak memory, how many database queries it ran and how long they took,\nand how long it waited on other servers, and turns what crossed a threshold\ninto findings: a slow or repeated query pattern, a plugin with a large share of\nthe time, a request that waited on other servers. Every finding says what it\ncould not observe. A diagnosis changes nothing, is one request rather than a\nspeed score, and is never added to the Debloat Score. If a cache answered the\nrequest instead of your site, it says so and records no figures. The most\nrecent 20 diagnoses are kept.<\/p>\n\n<p><strong>Connects what it measured to what it can change.<\/strong> A diagnosis of a page\nrecords the scripts and stylesheets it printed. Where one of Debloater's\nchanges removes something it printed \u2014 the emoji script, jQuery Migrate, the\ncart-fragments script off the shop \u2014 the finding names that change and says\nwhether it is offered on your site, decided from your last scan exactly as\nevery other change is. Review it, apply it the usual way, then diagnose the same\npage again to see the observed change.<\/p>\n\n<p><strong>Adds nothing to a page when nothing is selected.<\/strong> With no changes selected,\na front-end page loads none of Debloater's change handlers and makes no query\nto Debloater's own data.<\/p>\n\n<h4>Three profiles<\/h4>\n\n<ul>\n<li><strong>Safe<\/strong> \u2014 changes rated safe or low risk. This is what the \"Fix Safe\nIssues\" button applies.<\/li>\n<li><strong>Performance<\/strong> \u2014 Safe, plus changes rated medium risk.<\/li>\n<li><strong>Maximum<\/strong> \u2014 every change rated safe to high risk.<\/li>\n<\/ul>\n\n<p>Every change carries a declared risk. Debloater raises it one level when\nsomething on your site depends on what the change touches, and on any host it\ndoes not recognise (it recognises WP Engine, Kinsta, SiteGround and LiteSpeed\nservers). On an unrecognised host that means the front-end changes are rated\nhigh, so Performance leaves them out and only Maximum includes them. The host\ndoes not raise a database change that deletes nothing \u2014 clearing expired\ntransients, or stopping large options from loading on every request \u2014 because\nnothing a host does changes what those rows are. Nor does it raise a change\nwhose finding already read what the host did: the revision limit, which the\nscan reads as it is actually in effect. When a change is left out of a plan\nbecause its risk was raised, the preview says why.<\/p>\n\n<p>Stopping the Dashicons icon font from loading for visitors is rated on evidence.\nThe scan reads the pages it fetched as a visitor, and the stylesheets they load\nfrom your site, for any use of the font. If none uses it, the change is low risk\nand Fix Safe Issues can include it; if any does, or a stylesheet could not be\nread, it is medium, and the finding says which. Pages outside the sample, and\nicons added by JavaScript after a page loads, are not seen.<\/p>\n\n<p>None of the three profiles includes a change that deletes rows or a change to\nthe admin. Those are chosen one at a time, from their findings.<\/p>\n\n<h4>What it can change<\/h4>\n\n<p>Twenty-six changes at present, across WordPress core (emoji scripts, embeds,\nthe generator tag, RSD and shortlink headers, jQuery Migrate, heartbeat\ninterval, revision limits, self-pingbacks, Dashicons for guests), the admin\n(dashboard widgets, the welcome panel, the news widget, plugin notices), the\ndatabase (expired transients, auto-drafts, orphaned meta, old revisions, spam\ncomments, trash, autoloaded options), WooCommerce (cart fragments and block\nstyles loaded only where they are needed, admin analytics, marketplace\nsuggestions) and Elementor (Google Fonts).<\/p>\n\n<h4>What it will not do<\/h4>\n\n<ul>\n<li>No admin notices and no dashboard widget.<\/li>\n<li>No telemetry, no analytics, no AI.<\/li>\n<li>No requests to other sites, except one optional request to wordpress.org\ndescribed under \"External services\". The requests Debloater makes on its own\nare to your own site: to sample your pages and read your dashboard during a\nscan, to check your site after a change, and to request the page you ask it\nto diagnose.<\/li>\n<li>No blocking of requests to other servers. A diagnosis reports them; what to\ndo about them is yours to decide.<\/li>\n<li>No claim that your site got faster. Debloater records before-and-after counts\nand leaves the conclusion to you.<\/li>\n<li>Recovery points, verification and rollback are all in this free plugin, and\nnone of them needs a licence.<\/li>\n<\/ul>\n\n<h4>External services<\/h4>\n\n<p><strong>Plugin release dates, from wordpress.org.<\/strong> Only when a scan asks for it \u2014\n    wp debloater scan --check-plugin-updates, or the <code>check_plugin_updates<\/code>\nparameter of the REST scan endpoint; the dashboard never does \u2014 Debloater asks\n    https:\/\/api.wordpress.org\/plugins\/info\/1.2\/ for the last-updated date of each\ninstalled plugin, one request per plugin, so it can tell you which look\nabandoned. Each request names the plugin's slug, and its user agent names this\nsite's address. Nothing else about your site is sent. The dates are cached, and\nthe choice is not remembered: the next scan does not ask unless told to. This\nis WordPress's own API; see the\n<a href=\"https:\/\/wordpress.org\/about\/privacy\/\">wordpress.org privacy notice<\/a>.<\/p>\n\n<p>The rules Debloater reasons with ship inside the plugin and are never fetched.\nA newer set arrives when you update the plugin.<\/p>\n\n<p>Nothing else leaves your server.<\/p>\n\n<h4>WP-CLI<\/h4>\n\n<pre><code>wp debloater scan --user=&lt;an administrator&gt;\nwp debloater findings\nwp debloater preview --profile=safe\nwp debloater apply --profile=safe --yes\nwp debloater rollback --yes\nwp debloater status\nwp debloater diagnose --user=&lt;an administrator&gt; [--type=checkout] [--deep]\nwp debloater diagnosis [&lt;id&gt;]\n<\/code><\/pre>\n\n<p>Exit codes: 0 applied and verified, 1 error, 2 rolled back, 3 applied with\nwarnings. <code>diagnose<\/code> exits 0 when something was measured and 1 when nothing\nwas.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate.<\/li>\n<li>Open <strong>Hakeemify Debloater<\/strong> in the admin menu.<\/li>\n<li>Run a scan.<\/li>\n<li>Read the findings. Apply what you agree with.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20speed%20up%20my%20site%3F\"><h3>Will this speed up my site?<\/h3><\/dt>\n<dd><p>It removes work your site is doing. Whether that is measurable depends on what\nyour site was doing to begin with. Debloater records before-and-after counts \u2014\nrequests, bytes, rows \u2014 on each change, and never reports a change as making\nyour site faster.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20a%20change%20breaks%20something%3F\"><h3>What happens if a change breaks something?<\/h3><\/dt>\n<dd><p>After applying, Debloater requests your front page, a post, your dashboard and\nyour REST API. If one of them fails, it restores the previous state and reports\nwhat failed. From WP-CLI, pass <code>--user=&lt;an administrator&gt;<\/code> so the checks that\nneed a signed-in user can run. If your site cannot make requests to itself, or\nthe change was applied from WP-CLI without <code>--user<\/code>, those checks are reported\nas not run and the change stays in place.<\/p><\/dd>\n<dt id=\"can%20i%20undo%20a%20change%20later%3F\"><h3>Can I undo a change later?<\/h3><\/dt>\n<dd><p>Yes. Every apply creates a recovery point. You can roll back any of them from\n\"Changes &amp; recovery\" on the dashboard, or with <code>wp debloater rollback<\/code>.<\/p><\/dd>\n<dt id=\"does%20it%20delete%20anything%3F\"><h3>Does it delete anything?<\/h3><\/dt>\n<dd><p>Only when you choose a change that deletes rows. Those changes are never part\nof \"Fix Safe Issues\" or the other two profiles. The finding shows how many rows\nthe scan counted. Before rows are deleted they are copied into a recovery point,\nand if that copy does not complete, nothing is deleted.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20uninstall%3F\"><h3>What happens when I uninstall?<\/h3><\/dt>\n<dd><p>The changes Debloater applied stop, and it forgets which changes were applied:\nif you install it again, it starts with nothing applied rather than turning them\nback on. Rows a change deleted are not put back by uninstalling; roll the change\nback first if you want them.<\/p>\n\n<p>It deletes the files that hold recovery points larger than 8 MB, so those can no\nlonger be restored, and removes anything an older version left under\n    wp-content\/. Exports you wrote under <code>wp-content\/uploads\/debloater\/<\/code> are left\nin place. Its database tables and other settings are kept, including smaller\nrecovery points and the scan history, so after installing it again you can still\nsee what was changed and roll it back. A rollback puts the site back as it was\njust before that change, so changes applied before it come back on too. There is\nno setting to remove them on uninstall.<\/p><\/dd>\n<dt id=\"where%20does%20debloater%20write%20files%3F\"><h3>Where does Debloater write files?<\/h3><\/dt>\n<dd><p>The changes you apply are stored in your database, not written as PHP files,\nand nothing is added to must-use plugins.<\/p>\n\n<p>Two things are written as files, both of them data, under\n    wp-content\/uploads\/debloater\/:<\/p>\n\n<ul>\n<li>A recovery point larger than 8 MB is stored in <code>backups\/<\/code>.<\/li>\n<li><code>wp debloater export<\/code> and <code>wp debloater profile export<\/code> write their JSON\nthere, with a random suffix on the file name.<\/li>\n<\/ul>\n\n<p>That folder gets an <code>.htaccess<\/code> refusing web access, which Apache honours; on\nNginx or another server, add your own rule to refuse\n    wp-content\/uploads\/debloater\/. <code>--file=-<\/code> prints an export to standard output\ninstead, and a file path is refused.<\/p><\/dd>\n<dt id=\"does%20it%20phone%20home%3F\"><h3>Does it phone home?<\/h3><\/dt>\n<dd><p>No. There is no telemetry, licensing call or usage reporting. The requests it\nmakes on its own go to your own site. The one request to wordpress.org happens\nonly when you ask for it, and is described under \"External services\".<\/p><\/dd>\n<dt id=\"is%20it%20compatible%20with%20my%20caching%20plugin%3F\"><h3>Is it compatible with my caching plugin?<\/h3><\/dt>\n<dd><p>Debloater does not cache anything. Its command-line end-to-end check runs on a\nsite with WooCommerce, Elementor, Contact Form 7, Rank Math and LiteSpeed Cache\nactive.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.10.0<\/h4>\n\n<ul>\n<li>Diagnose a request: one page, requested once with a profiler on. Records request time, peak memory, database queries and their time, and time spent waiting on other servers, and reports what crossed a threshold as findings.<\/li>\n<li>Every diagnosis finding says what it could not observe. Diagnoses change nothing and are never part of the Debloat Score.<\/li>\n<li>A request answered by a cache is reported as such, with no figures, instead of as measurements of the page.<\/li>\n<li>New WP-CLI commands <code>wp debloater diagnose<\/code> and <code>wp debloater diagnosis<\/code>, and REST routes to run, list and read diagnoses.<\/li>\n<li>A diagnosis of a page names the Debloater change that removes what it printed, when there is one, and whether your last scan offers it. After applying, diagnose the same page again to see the observed change.<\/li>\n<li>The WooCommerce block styles change is no longer offered on stores where WooCommerce loads those styles on every page for its notices; it removed nothing there.<\/li>\n<\/ul>\n\n<h4>0.9.0<\/h4>\n\n<ul>\n<li>Initial public release.<\/li>\n<li>Scans the site and records what it found: core features, the database, the admin as you see it, and the pages a visitor downloads.<\/li>\n<li>Explains every finding with the facts it came from, its risk and its confidence, and scores Database, Admin and Assets separately.<\/li>\n<li>Fix Safe Issues applies only low-risk changes that delete nothing. Every other change is reviewed and applied one at a time.<\/li>\n<li>Takes a recovery point before every change, checks the site afterwards, and puts everything back if a check fails, from the dashboard or from WP-CLI.<\/li>\n<li>Every step is also a WP-CLI command, including scan, preview, apply, verify and rollback.<\/li>\n<\/ul>","raw_excerpt":"Scan, fix and undo site bloat: audits your site against the facts, applies only what you approve, with a recovery point and automatic rollback.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/365187","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=365187"}],"author":[{"embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/hakeemify"}],"wp:attachment":[{"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=365187"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=365187"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=365187"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=365187"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=365187"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/fa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=365187"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}