Blue Coral – Site Audit, Performance, Admin Toolkit
Blue Coral – Site Audit, Performance, Admin Toolkit

Blue Coral – Site Audit, Performance, Admin Toolkit

0/5 (0 ratings) — active installs Updated Sep 11, 2026
Activity Logs list with filtering and pagination.

Activity Logs list with filtering and pagination.

Blue Coral – Site Audit, Performance, Admin Toolkit provides practical local tools for maintaining a WordPress site or network.

Features include:

  • Local Activity Logs with filtering, retention controls, and WordPress privacy export/erasure support.
  • Security Headers with static headers (HSTS, Referrer-Policy, and more), enable-gated CSP options with manual directive configuration, Subresource Integrity, and asset versioning.
  • Site Enhancements with default-off toggles for SVG uploads, XML-RPC, comments, feeds, embeds, emojis, and asset cleanups.
  • Maintenance Mode with role-based bypass and a 503 page.
  • Configuration export/import and Plugin Control for plugin visibility and blocked endpoints.
  • User and avatar utilities, and an API/MCP workspace for separately configured clients.
  • A Settings page with Enabled Features controls, data lifecycle choices, and Activity Logs guidance.
  • An extended BlueCoral build for managed client sites additionally provides CSP service templates, restricted file and database administration tools, and a client access workspace; these are not part of this WordPress.org package.

The core plugin does not transmit telemetry, credentials, database contents, personal data, or usage statistics to BlueCoral or another third party. When enabled, Activity Logs collect and store administrator and site activity locally in the WordPress database. Records can include a user ID and username when present, event metadata, and request metadata such as the request path and method, IP address, and user agent. Sensitive values are redacted, and raw actor email is not persisted. The Toolkit does not transmit Activity Log records to BlueCoral or another third party. Site owners configure Activity Log retention and can use WordPress privacy export and erasure tools. The Toolkit does not make a storage probe or request for Activity Log storage. CSP directives are configured manually by a site administrator. The optional MCP API is accessed only by a separately configured client that you choose.

External services

Core Toolkit functions do not require a third-party service or BlueCoral account. The Toolkit does not initiate requests to third-party services or load remote assets.

  • Security Headers provides manual CSP directive configuration. It has no default external hosts and loads no remote assets.
  • Activity Logs are stored in the WordPress database. The Toolkit does not make a storage probe or request for Activity Log storage.
  • The optional MCP endpoint is hosted by the WordPress site. It receives requests only from a client independently configured by the site administrator; it does not connect to a BlueCoral service.