
內容簡介
Deskmode Suite 是一款專為 WordPress 控制台設計的外掛,旨在改善使用者的管理體驗。它整合多項功能,讓使用者能夠自訂儀表板外觀、管理通知、追蹤活動紀錄,並提供網站健康狀況的詳細報告,提升工作效率。
【主要功能】
• 整合通知管理,減少干擾
• 自訂儀表板主題與顏色
• 提供使用者專屬的深色模式
• 活動紀錄追蹤,記錄多種事件
• 網站健康狀況評分與圖表
• 維護模式,避免搜尋引擎索引問題
外掛標籤
開發者團隊
原文外掛簡介
The dashboard is the part of your work that clients see every single day, and by
default it looks like everyone else’s. Deskmode Suite changes that, and adds the
tools you would otherwise install three separate plugins for.
Everything happens in the admin area. Your public site is never touched: no
changes to your theme, and no scripts added to the pages your visitors see.
Plugin notices & ADV: hide the admin notice clutter
Every plugin you install thinks its announcement deserves the top of your screen.
Ten plugins later the admin notices push your actual work below the fold, and the
one message that mattered is buried among the discount banners.
Deskmode Suite collects them into a single line with the count, and leaves your
screen to you. Open that line and you get every notice, in full, on a page of its
own: nothing is destroyed, only moved. Blocks containing an error stay exactly
where they are, because an announcement can wait and a failure cannot. Plugins you
actually want to hear from can be let through one by one.
If anything ever goes wrong, define( 'DESKSU_SHOW_NOTICES', true ); in
wp-config.php puts every notice back where WordPress had it, without needing the
dashboard.
Dashboard theme
Three accent colours, chosen from the admin bar on any screen. The colour flows
through the menu, buttons, panels and charts, so you pick it once. Where the
accent is used as a background, the text colour is calculated from the
background’s luminance rather than assumed, so it always clears the contrast
ratio the WCAG require.
Dark mode, per user
A floating button flips the whole dashboard, instantly and without a reload. The
preference belongs to each user rather than the site, so you can work in dark
while a colleague works in light. It steps back on two screens on purpose: the
theme customizer, where a dark frame would skew your reading of the colours you
are choosing, and Elementor, which forces a light background on its own panels.
Menu customizer
Drag items into order, rename them into words your client understands, change
the icon by clicking it, and hide the ones nobody needs. Counters for pending
updates and comments stay attached to their items and keep working. On the Menus
screen you also get two buttons per item, to remove one or to
duplicate a menu item
in a single click.
Activity log
Eighteen event types in one filterable table: sign-ins, failed logins, password
resets, accounts created and deleted, role changes, plugins activated, theme
switches, updates installed, content published or deleted. Each entry records the
user, the IP address and the time. Events go into a dedicated database table
indexed by timestamp, action and IP, rather than into an option row that
WordPress would load and rewrite on every request.
Site health and charts
A score out of a hundred with every reason spelled out: PHP version, HTTPS in the
admin, errors visible to visitors, an enabled file editor, the weight of
autoloaded options, pending updates, and the state of the database. Alongside it,
charts of your site’s build time over thirty days and of how the score moves. The
charts are SVG generated on the server, so there is no JavaScript library to
download and they work under strict content security policies.
Maintenance mode
A holding page while you work, served with the correct 503 status and a
Retry-After header, so search engines understand the site is temporarily down
rather than replacing your indexed pages with “back soon”. The login page stays
reachable, so you cannot lock yourself out.
Network tools
WHOIS over port 43, DNS records, SSL certificate expiry, and
IP lookup with country, ISP and
AS number, all from one screen. Useful when a login attempt
looks suspicious, or when a client asks why their certificate expired.
Login security
Three doors WordPress leaves open by default, each one a checkbox with the
reason spelled out. Disable XML-RPC, so xmlrpc.php stops accepting password
attempts from anyone who asks. Block user enumeration, so ?author=1, the REST
users routes, the sitemap and oEmbed stop handing out your usernames. Disable
application passwords, which otherwise let any user mint a credential that
authenticates over HTTP Basic.
Alongside them a security summary: the state of each protection in plain words,
plus two read-only checks on the site itself. Must-use plugins, which load on
every request and cannot be switched off from the Plugins screen. And executable
files sitting in the uploads folder, where nothing should ever be code. The scan
is capped and says so when the result is partial, rather than pretending it read
everything.
Clear about limitations
CPU time and memory per plugin are not shown, because from inside WordPress they
cannot be measured reliably. Database time is the slice that genuinely can be
measured, and that is the slice you get. Every module can also be switched off
from wp-config.php, without dashboard access, for when something goes wrong.
Deskmode Suite is built by 3WEB, an Italian company that
has been building and maintaining websites and servers since 1999. Full
documentation and a page for every feature are on the
Deskmode website.
What Deskmode Pro Suite adds
The free version is a complete plugin, not a trial: nothing here expires and
nothing is limited by a quota. If you look after sites for other people, these
are the tools the Pro version adds, and they are the reason it exists.
Login security – failed-attempt limits, blocklist and allowlist with CIDR notation, allowed login hours, and IP reputation scoring.
Geofencing – allow logins only from the countries you actually work in, either refusing the attempt or never rendering the login form at all.
Two-factor authentication – TOTP with any authenticator app, or codes by email, with recovery codes and a captcha on the login form.
Security email alerts – an email when a login is blocked, and when someone signs in from an address you have never seen before.
Hardening – REST API rate limiting, and moving wp-login.php to an address of your own.
Custom login page – your logo, your colours and your copyright on the page your clients see every day.
404 page and monitor – a branded 404 page with a search box, and a log of the addresses that trigger it, with hit counts and referrers.
Security summary widget – blocked attempts, failed logins and the countries they come from, summarised on the dashboard the moment you sign in.
Mail log – every email your site sends, with recipient, subject, outcome and the plugin behind it.
Backup and restore – database and files to your own S3-compatible storage or FTP, with credentials encrypted at rest.
Database cleanup – expired transients, largest tables and the heaviest autoloaded options, with only the safe things actually deleted.
Search and replace – serialization-aware, with a mandatory preview, for changing your site URL after a migration.
Menu per role – hide admin menu sections for specific roles, or deny access to them properly.
Twelve accent colours – twelve instead of three, across menus, buttons, charts and the login page.
Details, screenshots and pricing are on the
Deskmode Pro Suite page.
Deskmode Pro Suite is a separate download from our own site: there is no upgrade
path from within this plugin, and no account or licence key is needed to use the
free version.
External services
This plugin does not contact any external server on its own. Every request below
happens only after an explicit action by an administrator.
Network tools (WHOIS, DNS, SSL, IP and AS lookup)
These run only when you type an address or a domain into the Network Info screen
and press the lookup button. What is sent is the address or domain you typed, and
nothing else: no site content, no visitor data. The services involved are:
ip-api.com – IP geolocation: country, ISP and AS number for the address you
entered. Terms: https://ip-api.com/docs/legal – Privacy: https://ip-api.com/privacy
stat.ripe.net – autonomous system data, used when bgpview does not answer.
Terms: https://www.ripe.net/about-us/legal/terms-of-service/ –
Privacy: https://www.ripe.net/about-us/legal/ripe-ncc-privacy-statement/
api.hackertarget.com – how many domains share the address you entered.
Terms and privacy: https://hackertarget.com/privacy-policy/
rdap.org – domain registration data for the domain you entered.
Terms and privacy: https://about.rdap.org/
WHOIS servers of each registry, queried on port 43, for domain records not
available over RDAP. Only the domain you typed is sent.
openstreetmap.org – map tiles, loaded only when a lookup result is shown on
a map. Terms: https://osmfoundation.org/wiki/Terms_of_Use –
Privacy: https://osmfoundation.org/wiki/Privacy_Policy
Country lookup in the activity log (optional, off by default)
If you switch this on in the plugin settings, the IP addresses recorded in the
activity log are sent to ip-api.com to look up their country. The result is
cached. Nothing is sent while the option is off.
Terms: https://ip-api.com/docs/legal – Privacy: https://ip-api.com/privacy
Plugin maintenance check (optional)
Runs only when you press the scan button on the Site Health screen. The slugs of
your active plugins are sent to api.wordpress.org to check whether they are
still maintained. No site content and no personal data are sent.
Terms: https://wordpress.org/about/ – Privacy: https://wordpress.org/about/privacy/
No telemetry, no usage statistics and no site content are ever transmitted, and
the plugin does not phone home to its author. The fonts are bundled with the
plugin rather than loaded from Google Fonts, so no request leaves your site to
render the interface.
Known issues
Some popups belonging to third-party plugins may show light text in dark mode.
