Editors and the Admin Experience

Some of the Hardening module's toggles have nothing to do with attackers. They're about the experience of the people inside your site: the editor building next month's course, the member working through this week's lesson, the server keeping up with both. Call it cleanup, call it sanity, but the same screen holds these controls, and they're worth setting deliberately.

The editor's dashboard

Hand an editor account to a content manager and WordPress greets them with WordPress Events and News, Quick Draft, update notices for plugins they can't update, and a periodic nag to verify the admin email address. None of it is theirs.

  • Hide update nags removes update notices for anyone who can't install updates. Updates still exist; only admins see them. Your editor stops asking "should I click update?" and your admin stops coming back to find out what was clicked.
  • Remove dashboard widgets strips the news and quick-draft widgets for non-admins. Fewer outbound calls to WordPress.org, less noise, faster load.
  • Disable admin email nag permanently silences the "verify your admin email" prompt that WordPress resurrects no matter how many times it's dismissed. The email address on file doesn't change; the nag just stops.
  • Disable site health emails stops automated "WordPress detected an issue" emails. If you monitor uptime elsewhere, these are duplicates; the Site Health screen inside the admin keeps working for manual checks.

The editor's block library

The block editor ships with browsing screens for the block and pattern directories on WordPress.org: thousands of third-party blocks, one click away, each a plugin you didn't vet. Disable block/pattern directories removes the browsing screens while leaving locally installed blocks alone. If your editors keep mysteriously finding new blocks, this is how you make the block library yours again.

The member's page weight

Two toggles shave the frontend:

  • Disable emoji scripts removes the script that converts emoji into images, about 30KB plus a request to WordPress.org on every page. Modern browsers render emoji natively; members lose nothing visible and every page gets lighter.
  • Throttle Heartbeat API slows WordPress's background polling from as fast as every 15 seconds to once every 60. Members who leave your site open in a tab stop generating a request every 15 seconds per tab. On hosting billed by requests, this toggle quietly pays for itself. Admin features like post locking are unaffected; the throttle targets the frontend.

The toggles to think twice about

Two in this section carry warnings because they trade a real convenience for a real gain:

  • Remove jQuery Migrate drops a compatibility shim (~10KB) that older themes and plugins need. If anything on your frontend was built for jQuery before 3.0 and never updated, it breaks. Enable, then walk your key pages with the browser console open.
  • Disable autosave turns off the editor's 60-second draft recovery. The use case is real: an autosave can overwrite carefully arranged content with a half-finished state. But the default is on for a reason, and the cost is a content team that must remember to save manually or lose work on a browser crash. Only enable this if your editors have asked for it, and tell them when you do.

None of these will stop a hacker. They'll make the site you run smaller, faster, and less littered with WordPress's defaults, which on a long project is its own kind of security.