Select one or more tags, then press “Search Plugins”

Find Plugin with any / all of the selected criteria
Search Plugin

Npcink Site Toolbox Wordpress Plugin - Rating, Reviews, Demo & Download

Npcink Site Toolbox Wordpress Plugin - Rating, Reviews, Demo & Download
No ratings yet
Free
Follow for free plugins, new theme releases and theme news

Plugin Description

Npcink Site Toolbox is a utility plugin for WordPress site owners. Version 3.3.2 provides 56 registered modules: 55 opt-in modules and one always-loaded runtime module, plus three editor patterns and two dynamic blocks. Features cover site and media settings, content and SEO, login and comment safeguards, China-focused integrations, diagnostics, and maintenance.

Current features

  • Seven admin views: Overview, Site and Media, Content and Pages, SEO and Enhancements, China Ecosystem, Maintenance Tools, and About and Help.
  • Site and media: link, upload, image, admin-list, and optional CDN settings.
  • Content and SEO: comment controls, restricted content, reading tools, metadata, internal links, search health, and publishing statistics.
  • Security: login-attempt protection and anonymous author-enumeration protection.
  • China-focused integrations: ICP information, WeChat JSSDK, cookie notice, and optional object storage.
  • Maintenance: diagnostics, SEO checks, media health, and guarded database cleanup.
  • Admin experience: feature search, risk labels, change confirmation, secret-status handling, and responsive layouts.
  • Editor tools: three core-block patterns, a live site-statistics block, and a GitHub project block with cached public repository metadata plus an optional author-written summary.
  • Public source and reproducible build instructions: GitHub repository.

Important behavior

All modules that contact a third party are disabled by default. An administrator must explicitly enable the related module or manually run a connectivity check. The plugin does not send telemetry to its developer.

External Services

No external service is contacted merely by activating the plugin.

GitHub project block

Only after a content author inserts this block and supplies a public repository URL does the server call GitHub’s “Get a repository” API on a cache miss. The endpoint is formed from the submitted public owner and repository names. The author may also save an optional custom project summary in the article; that summary is rendered locally and is not sent to GitHub. The request sends the public owner/repository identifier, the site server’s IP address, the plugin User-Agent, and normal HTTP headers to retrieve the repository description, primary language, Stars, Forks, and archive status. Successful responses are cached locally for up to 12 hours and failures for 30 minutes. No GitHub credentials, article content, custom summary, plugin settings, visitor IP address, or visitor browser request is sent. Service and endpoint documentation, GitHub Terms of Service, GitHub General Privacy Statement.

WeChat JSSDK

When an administrator enables WeChat JSSDK and configures an AppID and AppSecret, the server sends those credentials to the WeChat token API and later sends the access token to the ticket API. On singular content, the visitor’s browser loads the remote JSSDK and supplies the current URL, title, excerpt, and thumbnail URL for sharing. Service, terms, privacy.

Object storage

Before saving or enabling object storage, an administrator may explicitly run the connection test. It sends the selected provider the current saved or draft credentials, bucket, provider-specific endpoint or region, optional object-key prefix, signed authorization data, and a short text payload. The payload writes or overwrites npcink-site-toolbox/connection-test.txt, placed below the configured prefix when one is present. The test object remains in the selected bucket; rerunning the test overwrites the same object instead of creating more objects. The test does not require a public media URL, save settings, or change the module’s enabled state.

When an administrator enables object storage and selects a provider, each new media upload sends the file bytes, prefixed object key, bucket, provider-specific endpoint or region, access-key identifier, and signed authorization data to that provider. Local media files are retained. The configured public URL prefix is used only to replace media URLs after every generated file uploads successfully. Saved credentials and target settings remain in the local WordPress database; unsaved draft credentials are used only for the administrator-triggered connection test. Providers: Alibaba Cloud OSS (terms, privacy); Tencent Cloud COS (terms, privacy); Qiniu Kodo (terms, privacy).

Baidu Analytics

When its module is enabled and a site ID is saved, front-end pages load Baidu Analytics. The visitor’s browser may send the page URL, referrer, IP address, User-Agent, and data described by Baidu. Service, terms, privacy.

DeepSeek diagnostic analysis

This optional action requires WordPress 7.0 or newer and a separately installed and connected DeepSeek Provider. The AI tab offers troubleshooting, performance analysis, maintenance-result interpretation, pending-setting risk explanation, and before/after verification. Only after an administrator reviews the relevant allowlisted snapshot or ordinary pending-setting paths and explicitly starts analysis does the server send data through the WordPress AI Client. An administrator may ask up to three follow-up questions under the same bounded allowlisted facts; each follow-up resends the original facts, initial answer, and completed follow-up turns. This temporary history exists only in the current browser page and is cleared by switching modes or refreshing. Performance data is a one-time snapshot rather than monitoring or load testing. Maintenance analysis may include aggregate database, SEO, media, search-health, and object-storage configuration facts; raw search terms are excluded. Setting analysis excludes every credential path and summarizes non-boolean strings by empty/configured state and length rather than content. Verification baselines remain only in the current browser page. The diagnostic allowlist excludes site URLs, file paths, database identities, users, content, comments, request logs, and credentials. DeepSeek receives the server IP, normal HTTP headers, the prompt, and the API credential managed by WordPress Connectors and the provider plugin. Npcink Site Toolbox does not read that credential and does not persist goals, snapshots, baselines, follow-up history, or AI responses. No suggested action is performed automatically. DeepSeek, terms, privacy.

Google Search Console and Bing Webmaster Tools options only print administrator-supplied verification meta tags. They do not make outbound requests. Google service, Google terms, Google privacy; Bing service, Microsoft terms, Microsoft privacy.

Source Code and Build

The public source matching this exact plugin release is published at tag v3.3.2. The readable sources are in vite/admin/src and vite/count/src, with the build manifest at vite/package.json.

Reproduce the Admin and Count assets with:

git clone https://github.com/npcink/npcink-site-toolbox.git

cd npcink-site-toolbox

git checkout v3.3.2

cd vite

corepack enable

pnpm install --frozen-lockfile

pnpm run build

The generated files are written to vite/admin/dist/ and vite/count/dist/.

The site-statistics and GitHub project block editor scripts are shipped as readable source in blocks/site-stats/index.js and blocks/github-project/index.js; they have no separate build step.

Privacy Policy

Search Health can store search terms and counters in the local WordPress database. Login protection, audit, and diagnostic features can store login failures, IP addresses, actions, and diagnostic results locally when enabled. Site administrators are responsible for an appropriate privacy notice and retention policy.

The plugin does not automatically upload this local data or telemetry to its developer. Third-party requests occur only under the triggers documented in External Services. Credentials used by this plugin are stored in WordPress options and are sent only to the administrator-selected WeChat or object-storage provider when required for authentication. DeepSeek credentials are managed by WordPress Connectors and the separately installed provider plugin; Npcink Site Toolbox does not read or store them.

Screenshots

No screenshots provided


Reviews & Comments