{"id":353071,"date":"2026-08-30T12:22:48","date_gmt":"2026-08-30T12:22:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/xo-magic-box-light\/"},"modified":"2026-08-30T12:22:33","modified_gmt":"2026-08-30T12:22:33","slug":"xo-magic-box-light","status":"publish","type":"plugin","link":"https:\/\/ro.wordpress.org\/plugins\/xo-magic-box-light\/","author":23548312,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"XO Magic Box Light","header_author":"XoDesignWorks","header_description":"Lightweight toolkit to clean and speed up WordPress: cleanup, performance, basic SEO and security. No bloat, no telemetry.","assets_banners_color":"998509","last_updated":"2026-08-30 12:22:33","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/xodesignworks.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":49,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"xodesignworks","date":"2026-08-30 12:22:33","revision":3672510}},"upgrade_notice":{"1.0.0":"<p>Initial public release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3672510,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3672510,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3672510,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3672510,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[3786,187460,187,247,600],"plugin_category":[52,54],"plugin_contributors":[278321],"plugin_business_model":[],"class_list":["post-353071","plugin","type-plugin","status-publish","hentry","plugin_tags-cleanup","plugin_tags-core-web-vitals","plugin_tags-optimization","plugin_tags-performance","plugin_tags-security","plugin_category-performance","plugin_category-security-and-spam-protection","plugin_contributors-xodesignworks","plugin_committers-xodesignworks"],"banners":{"banner":"https:\/\/ps.w.org\/xo-magic-box-light\/assets\/banner-772x250.png?rev=3672510","banner_2x":"https:\/\/ps.w.org\/xo-magic-box-light\/assets\/banner-1544x500.png?rev=3672510","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/xo-magic-box-light\/assets\/icon-128x128.png?rev=3672510","icon_2x":"https:\/\/ps.w.org\/xo-magic-box-light\/assets\/icon-256x256.png?rev=3672510","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>A dozen single-purpose plugins do what this one does \u2014 and most of them phone home. This one never does.<\/strong><\/p>\n\n<p>XO Magic Box Light is the maintenance layer nearly every WordPress site ends up needing: front-end performance, head cleanup, essential SEO, security hardening and the small tweaks you always apply anyway. Seven groups of switches in one fast admin screen, instead of a shelf of separate plugins each loading its own framework.<\/p>\n\n<p>Every feature is a self-contained module, and a module that is switched off <strong>loads no code at all<\/strong> \u2014 the things you leave off cost you nothing at runtime.<\/p>\n\n<p>There is no account, no subscription, no telemetry and <strong>not a single outbound request<\/strong>. Nothing in this plugin contacts any external server, ever.<\/p>\n\n<h4>It works alongside your cache plugin, not instead of it<\/h4>\n\n<p>A page cache makes WordPress send a page faster. This plugin makes the page itself lighter before anything caches it \u2014 fewer scripts, fewer third-party connections, less markup. The two jobs are different, so nothing here duplicates or fights your caching setup, and the dashboard <strong>detects other active cache and optimization plugins<\/strong> so you can see up front where features might overlap.<\/p>\n\n<h4>Faster pages<\/h4>\n\n<ul>\n<li>Remove jQuery Migrate, asset query strings, front-end Dashicons and unused block-library CSS.<\/li>\n<li>Minify HTML, safely: <code>pre<\/code>, <code>textarea<\/code>, <code>script<\/code>, <code>style<\/code> and <code>code<\/code> blocks are never touched.<\/li>\n<li>Defer JavaScript, with an exclusion list.<\/li>\n<li>Delay JavaScript until the first interaction, matched by keyword \u2014 ideal for analytics, chat widgets and trackers.<\/li>\n<li>Preconnect hints for third-party origins, handed to WordPress's own resource-hints pipeline, plus a preload list for your own critical assets.<\/li>\n<li>Speculative loading (prefetch\/prerender) for near-instant navigation, configured through core's own ruleset on WordPress 6.8+.<\/li>\n<li>Disable or relax Google Fonts, and force <code>font-display: swap<\/code>.<\/li>\n<li>Throttle the Heartbeat API, and send <code>Last-Modified<\/code> headers.<\/li>\n<\/ul>\n\n<h4>Better Core Web Vitals<\/h4>\n\n<ul>\n<li>Preload the featured image as the LCP candidate, with a proper responsive <code>srcset<\/code>.<\/li>\n<li>Adjustable above-the-fold lazy-load threshold, so the first images are not lazy-loaded.<\/li>\n<li>Stop generating registered image sizes you never use, on future uploads.<\/li>\n<li>Control big-image scaling and the maximum upload dimension.<\/li>\n<\/ul>\n\n<h4>Cleanup<\/h4>\n\n<ul>\n<li>Remove the generator meta tag, RSD\/WLW links, shortlink, REST and oEmbed head links, and the recent-comments inline style.<\/li>\n<li>Disable emojis, embeds and the feeds you do not use.<\/li>\n<li>Limit or disable post revisions; keep trashed items instead of auto-purging them.<\/li>\n<li>Scheduled database cleanup, plus an on-demand cleanup that shows you <strong>how many rows each type would remove before it removes anything<\/strong>.<\/li>\n<\/ul>\n\n<h4>Essential SEO<\/h4>\n\n<ul>\n<li>robots.txt editor.<\/li>\n<li>Noindex for paginated archives and post subpages.<\/li>\n<li>Noindex on staging and non-production environments, detected automatically.<\/li>\n<li>Attachment-page redirects and forced HTTPS, including a mixed-content fix.<\/li>\n<li><code>rel=\"noopener noreferrer\"<\/code> on external new-tab links, with optional <code>nofollow<\/code>.<\/li>\n<li>Disable the built-in search where a site does not need it.<\/li>\n<\/ul>\n\n<h4>Security hardening<\/h4>\n\n<ul>\n<li>Limit login attempts, and unify login error messages so they stop confirming valid usernames.<\/li>\n<li>Block user enumeration.<\/li>\n<li>Disable XML-RPC, application passwords and the built-in file editor.<\/li>\n<li>Security headers, <code>X-Powered-By<\/code> removal and <code>X-Pingback<\/code> removal.<\/li>\n<li>Comment spam honeypot \u2014 no captcha, no JavaScript, no external service, cache-safe.<\/li>\n<li>Password-protect the whole front end behind one shared password, for staging and private previews.<\/li>\n<\/ul>\n\n<h4>Tweaks you would otherwise install plugins for<\/h4>\n\n<ul>\n<li>Disable comments, the comment website field and self-pingbacks.<\/li>\n<li>Classic widgets, no remote block patterns, no block directory or Openverse.<\/li>\n<li>Local placeholder instead of Gravatar, so no visitor data reaches an avatar service.<\/li>\n<li>Clean up the admin bar and dashboard, remove rarely used widgets, show post and page IDs.<\/li>\n<li>Duplicate any post or page in one click.<\/li>\n<li>Auto-publish posts stuck on \"Missed schedule\".<\/li>\n<li>Choose whether WordPress emails you about every auto-update, only failures, or never.<\/li>\n<\/ul>\n\n<h4>Change things without holding your breath<\/h4>\n\n<ul>\n<li>Take a settings snapshot before risky changes, and restore it in one click.<\/li>\n<li>Curated one-click presets.<\/li>\n<li>Import and export the whole configuration.<\/li>\n<li>Conflict detection for other optimization and cache plugins.<\/li>\n<\/ul>\n\n<h4>What this plugin does not do<\/h4>\n\n<p>Being explicit saves everyone time:<\/p>\n\n<ul>\n<li>It is <strong>not a page cache<\/strong>. Use it together with your caching plugin.<\/li>\n<li>It does <strong>not<\/strong> minify or combine CSS and JavaScript, and does not generate critical CSS. HTML is the only thing minified here.<\/li>\n<li>It is <strong>not<\/strong> a full SEO suite. It handles indexing hygiene, not editorial SEO analysis.<\/li>\n<li>It is <strong>not<\/strong> a firewall or malware scanner. It hardens configuration; it does not police traffic.<\/li>\n<li>No backups, no SMTP delivery, no cookie banner, no image CDN.<\/li>\n<\/ul>\n\n<h4>Privacy<\/h4>\n\n<p>No telemetry, no analytics, no advertising, no remote account features, no licence checks, and no outbound HTTP requests of any kind. Everything happens on your own server. Settings live in a single autoloaded option; feature data lives in its own non-autoloaded rows so it never bloats the settings load.<\/p>\n\n<h4>Good fit for<\/h4>\n\n<ul>\n<li>Site owners replacing several small maintenance plugins with one.<\/li>\n<li>Agencies standardising client sites, with presets and export\/import.<\/li>\n<li>Shops and content sites working on Core Web Vitals.<\/li>\n<li>Shared hosting, where every avoided request matters.<\/li>\n<li>Cleaning up an inherited WordPress install.<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Install through <strong>Plugins \u2192 Add New<\/strong>, or upload the <code>xo-magic-box-light<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate <strong>XO Magic Box Light<\/strong> on the <strong>Plugins<\/strong> screen.<\/li>\n<li>Open <strong>XO Magic Box Light<\/strong> in the admin sidebar.<\/li>\n<li>Optionally apply the <strong>Recommended<\/strong> preset on the Dashboard tab for a safe baseline in one click.<\/li>\n<li>Take a snapshot before making broad changes, and check the conflict notice if you run a cache or optimization plugin.<\/li>\n<\/ol>\n\n<p>No account, API key or configuration file is required.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20it%20replace%20my%20cache%20plugin%3F\"><h3>Does it replace my cache plugin?<\/h3><\/dt>\n<dd><p>No, and it is not meant to. A cache plugin serves pages faster; this plugin makes the page lighter in the first place. Run both. The Dashboard flags other active cache and optimization plugins so you can spot overlapping features before enabling them.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20collect%20any%20data%20or%20phone%20home%3F\"><h3>Does the plugin collect any data or phone home?<\/h3><\/dt>\n<dd><p>No. There is zero telemetry, no licence or update server of its own, and no feature that contacts any external service. The plugin makes no outbound HTTP requests at all.<\/p><\/dd>\n<dt id=\"will%20enabling%20a%20lot%20of%20modules%20slow%20my%20site%20down%3F\"><h3>Will enabling a lot of modules slow my site down?<\/h3><\/dt>\n<dd><p>No. A disabled module never loads its code \u2014 <code>boot()<\/code> only runs for what you switch on, so there is no dormant overhead. Settings are read from a single autoloaded option.<\/p><\/dd>\n<dt id=\"what%20if%20i%20change%20a%20lot%20of%20settings%20and%20something%20breaks%3F\"><h3>What if I change a lot of settings and something breaks?<\/h3><\/dt>\n<dd><p>Use the Dashboard's safe mode: snapshot before you start, restore in one click if anything misbehaves. Presets are snapshotted automatically before they are applied.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%2C%20page%20builders%20and%20caching%20plugins%3F\"><h3>Does it work with WooCommerce, page builders and caching plugins?<\/h3><\/dt>\n<dd><p>Yes. It does not assume a theme or builder, and the conflict detector warns about common cache and optimizer plugins.<\/p><\/dd>\n<dt id=\"does%20the%20database%20cleanup%20delete%20anything%20without%20asking%3F\"><h3>Does the database cleanup delete anything without asking?<\/h3><\/dt>\n<dd><p>No. Each cleanup type shows its row count first, and nothing is removed until you click that type. Auto-drafts follow the same 7-day age rule WordPress core uses, so a post you are still writing is never touched.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20my%20data%20if%20i%20uninstall%3F\"><h3>What happens to my data if I uninstall?<\/h3><\/dt>\n<dd><p>Every option the plugin created, its snapshot and its login-lockout transients are removed on uninstall, on every site of a multisite network.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20multisite%3F\"><h3>Does it work on multisite?<\/h3><\/dt>\n<dd><p>It runs per site: every site in a network keeps its own settings, whether you activate it per site or network-wide. There is no network-admin settings screen, so each site is configured from its own admin. The conflict detector also takes network-activated plugins into account, and uninstalling removes the plugin's data from every site in the network.<\/p><\/dd>\n<dt id=\"is%20there%20a%20fuller%20version%3F\"><h3>Is there a fuller version?<\/h3><\/dt>\n<dd><p>Yes. XO Magic Box (the full edition) adds local WebP\/AVIF conversion, schema.org structured data and Open Graph, IndexNow, a redirect manager, 404 monitor, activity and mail logs, conditional per-page asset unloading with a live asset scanner, self-hosted Core Web Vitals monitoring, lazy-loaded video embeds, login-URL renaming, WooCommerce optimisation, WP-CLI commands, and Dashboard tools such as a database optimizer, serialization-safe search &amp; replace and a broken-link checker. Those features are marked with a \"Pro\" badge in this plugin's admin so you can see what they are. It is a separate, larger package \u2014 none of its code ships here.<\/p><\/dd>\n<dt id=\"how%20is%20the%20admin%20translated%3F\"><h3>How is the admin translated?<\/h3><\/dt>\n<dd><p>The plugin is fully internationalised and translations come from translate.wordpress.org, so WordPress downloads and applies the pack for your site language automatically. Contributions in any language are welcome there.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial public release: 67 modules across Performance, Media, Cleanup, SEO, Security, Tweaks and Tools.<\/li>\n<li>Modular core \u2014 one class per feature, a disabled module loads no code, all settings in a single autoloaded option.<\/li>\n<li>Performance: asset cleanup, safe HTML minification, defer and interaction-based delay for JavaScript, resource hints, speculative loading, font controls, Heartbeat throttling, <code>Last-Modified<\/code> headers, scheduled and on-demand database cleanup.<\/li>\n<li>Core Web Vitals: LCP featured-image preload with responsive <code>srcset<\/code>, lazy-load threshold, image-size management, upload-dimension limits.<\/li>\n<li>Cleanup: head and meta cleanup, emoji\/embeds\/feeds toggles, revision limits, trash retention.<\/li>\n<li>SEO: robots.txt editor, pagination and non-production noindex, attachment redirects, forced HTTPS, mixed-content fix, external-link attributes.<\/li>\n<li>Security: login-attempt limits, generic login errors, user-enumeration blocking, XML-RPC and application-password controls, file-editor lockdown, security headers, comment honeypot, front-end password gate.<\/li>\n<li>Tweaks: comments, classic widgets, remote patterns and block directory, local avatar placeholder, admin-bar and dashboard cleanup, post IDs, one-click duplicate, missed-schedule recovery, auto-update email control.<\/li>\n<li>Dashboard: conflict detector, curated presets, one-click snapshot and restore, settings import\/export.<\/li>\n<li>Zero telemetry and zero outbound HTTP requests.<\/li>\n<li>Fully internationalised, ready for community translations on translate.wordpress.org.<\/li>\n<\/ul>","raw_excerpt":"Speed up, clean up and harden WordPress from one admin. 67 modules instead of a dozen plugins. No telemetry, no external calls, no account.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/353071","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=353071"}],"author":[{"embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/xodesignworks"}],"wp:attachment":[{"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=353071"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=353071"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=353071"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=353071"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=353071"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=353071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}