PowerSuite Modular Admin Toolkit Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
PowerSuite Modular Admin Toolkit combines admin, security, media, SEO, cleanup, and workflow modules in a searchable Control Center with favorites and configuration import/export. Settings stay on your site; disabled modules do not run.
Optional Pro add-on
Optional PowerSuite Pro adds premium modules, code tools, AI, licensing, and white-label branding. Keep this free plugin active alongside Pro. Free updates come from WordPress.org; Pro updates come from wppowersuite.com.
Privacy
The free plugin makes no licensing requests. Enabled integrations, displayed avatars/logos, selected image imports, and explicitly submitted feedback can contact services as detailed below. Disabled modules do not contact these services. Alpine.js is bundled, not CDN-hosted.
External services
Email Delivery
Email Delivery uses configured PHP mail, SMTP, or an email provider. WordPress mail and Test email send subject, body, sender, recipients, reply-to, attachments, and authentication information through that connection.
Test connection uses configured credentials. SMTP connects/authenticates without sending mail. API checks request account, permission, domain, or sender information. Emailit and Bird request a recent message record; SendLayer requests a recent delivery-event record. Responses can expose existing account mail information. Netcore and turboSMTP POST synthetic send requests with intentionally invalid sender/recipient addresses and subject/body connection-test to check authentication, without customer messages or attachments. Maileroo only checks locally for a sending key; Test email verifies delivery.
For provider SMTP delivery, an empty host uses the default relay below; an entered host overrides it. The relay receives mail content and SMTP credentials. API User-Agent headers include plugin name/version. Servers receive connection information, including your server’s IP.
Connecting Gmail/Microsoft sends authorization code, application credentials, and callback URL to the provider’s token endpoint; later sends may refresh tokens there. Configured SES event webhooks fetch SNS signing certificates and verified subscription-confirmation URLs containing subscription tokens. Sender-domain health checks query your DNS resolver for domain records.
Delivery webhooks authenticate using provider signatures or configured secrets. Mailgun requires its HTTP Webhook Signing Key and HTTPS.
- Other SMTP host you enter: the email content goes to that host. Use that host’s own Terms and Privacy Policy.
- Amazon SES: regional
email.*.amazonaws.comAPI hosts,email-smtp.*.amazonaws.comSMTP hosts, plussns.amazonaws.com/sns.*.amazonaws.comcertificate and subscription URLs when delivery-event webhooks are enabled. Terms and Privacy. - SendGrid (Twilio): API
api.sendgrid.comorapi.eu.sendgrid.com; SMTPsmtp.sendgrid.net. Terms and Privacy. - Mailgun: API
api.mailgun.netorapi.eu.mailgun.net; SMTPsmtp.mailgun.orgorsmtp.eu.mailgun.org. Terms and Privacy. - Brevo: API
api.brevo.com; SMTPsmtp-relay.brevo.com. Terms and Privacy. - Google Gmail API:
accounts.google.com,oauth2.googleapis.com,gmail.googleapis.com, andwww.googleapis.com. Terms and Privacy. - Microsoft Graph:
login.microsoftonline.comandgraph.microsoft.com. Terms and Privacy. - Postmark: API
api.postmarkapp.com; SMTPsmtp.postmarkapp.com. Terms and Privacy. - Mailjet: API
api.mailjet.com; SMTPin-v3.mailjet.com. Terms and Privacy. - MailerSend: API
api.mailersend.com; SMTPsmtp.mailersend.com. Terms and Privacy. - SMTP2GO: API
api.smtp2go.com,us-api.smtp2go.com,eu-api.smtp2go.com, orau-api.smtp2go.com; SMTPmail.smtp2go.com. Terms and Privacy. - Resend: API
api.resend.com; SMTPsmtp.resend.com. Terms and Privacy. - Mandrill (Mailchimp): API
mandrillapp.com; SMTPsmtp.mandrillapp.com. Terms and Privacy. - SparkPost / Bird Email: classic SparkPost API keys use
https://api.sparkpost.comorhttps://api.eu.sparkpost.com; Bird platform API keys usehttps://us1.platform.bird.comorhttps://eu1.platform.bird.com. SMTP defaults aresmtp.sparkpostmail.comorsmtp.eu.sparkpostmail.com. Terms and Privacy. - Elastic Email: API
api.elasticemail.com; SMTPsmtp.elasticemail.com. Terms and Privacy. - SendLayer: API
console.sendlayer.com; SMTPsmtp.sendlayer.com. Terms and Privacy. - SMTP.com: API
api.smtp.com; SMTPsend.smtp.com. Terms and Privacy. - Netcore (formerly Pepipost):
https://emailapi.netcorecloud.netorhttps://apieu.netcorecloud.net. Terms and Privacy. - turboSMTP: API
api.turbo-smtp.comorapi.eu.turbo-smtp.com; SMTPpro.turbo-smtp.comorpro.eu.turbo-smtp.com. Terms and Privacy. - Maileroo:
smtp.maileroo.comfor both the HTTPS email API and SMTP relay. Terms and Privacy. - Emailit: API
api.emailit.com; SMTPsmtp.emailit.com. Terms and Privacy. - Mail.baby (InterServer): API
https://api.mailbaby.net; SMTPrelay.mailbaby.net. Terms and Privacy.
Email failure alerts: Slack and Discord
Enabled failure alerts send site name, provider name, and redacted error to your configured chat webhook after final delivery failure, at most once per 15 minutes. Errors may retain message-specific information; chat alerts exclude email bodies/attachments. Email alerts also use your selected mail connection and configured recipient, falling back to the admin email.
Slack uses hooks.slack.com: Terms and Privacy.
Discord uses discord.com or discordapp.com: Terms and Privacy.
A developer can explicitly allow another HTTPS webhook host. Review that recipient’s Terms and Privacy Policy before configuring it.
Customizer image imports
Importing Customizer settings with image downloads requests URLs from the import and creates Media Library attachments. Each host receives the URL, server IP, and HTTP request information. Hosts are arbitrary; review their Terms and Privacy Policy before importing.
Admin Logo images from configured hosts
Admin Logo displays configured admin-bar/menu image URLs. External hosts receive direct browser requests on settings previews and pages displaying the logo, including front-end admin bars: image URL, viewer IP, browser information, and policy-permitted referrer. Images are not copied into the Media Library. Hosts are arbitrary; review their Terms and Privacy Policy before configuring them.
Gravatar avatar images
Automattic’s Gravatar supplies default WordPress avatars. Enabled Local User Avatar prepares a profile-editor fallback; Remove Admin Bar Items requests avatars when replacing the account greeting. Unless another avatar filter overrides them, browsers request https://secure.gravatar.com/avatar/, sending the profile email’s hash, size/default/rating options, and initials if selected. Gravatar receives viewer IP, browser information, and policy-permitted referrer. The profile-editor fallback can render even with Show Avatars off, a local upload, or a hidden preview. Terms and Privacy.
Optional deactivation feedback
“Submit & Deactivate” stores feedback and a diagnostic snapshot locally (up to 50 records), including site/admin details, plugins/theme, enabled modules, browser/environment, and recent errors.
It sends PowerSuite your reason/comments, site URL/hash, administrator/submitting-user emails, plugin/WordPress/PHP/database versions, theme, installed/active plugins, enabled modules, license status (not key), browser/OS, language, user role, hosting/server, memory, cache/CDN, HTTPS, and cron information at https://wppowersuite.com/wp-json/licensor/deactivation-feedback to investigate issues and improve the plugin. Automatic diagnostics exclude raw errors, log excerpts, local user IDs, passwords, API keys, and license keys. The recipient receives server IP and normal HTTP information. Terms and Privacy.
Sharing is optional. “Skip & Deactivate” collects/sends nothing; opening/closing the dialog sends nothing. Developers can override/disable the recipient via constants/filters and must disclose replacement recipients and their Terms/Privacy before collecting feedback.
The separate “You may contact me by email about this feedback” checkbox defaults checked. Submissions include this yes/no preference; uncheck to decline follow-up. It neither sends email nor subscribes you to marketing. Skip sends no contact permission.
Google Sign-In
Enabled Google Sign-In requires your OAuth Client ID/Secret. Clicking sign-in opens https://accounts.google.com; after approval, your site sends authorization code, client ID/secret, and callback URL to https://oauth2.googleapis.com/token, then uses the access token at https://openidconnect.googleapis.com/v1/userinfo for email, display name, and profile-image URL to sign in/create a local account.
Social sign-in and its CAPTCHA gate use separate first-party HttpOnly browser-binding cookies, expiring after ten minutes and cleared on matching verification. They are not sent to providers or used for tracking. Use HTTPS in production.
Google avatar URL storage defaults enabled. While sign-in is enabled/configured, later avatar views can load saved images directly from their host, including for viewers not signing in; local uploads can override them. Hosts receive image URL, viewer IP, browser information, and policy-permitted referrer. Images are not copied into the Media Library. Disabling new URL storage does not remove saved URLs.
This service is provided by Google: Terms and Privacy.
Facebook and GitHub Sign-In
This plugin ships a shared OAuth HTTP helper that can request access tokens and user profiles from Facebook Graph and GitHub. Google Sign-In in this free plugin uses that helper. Facebook and GitHub sign-in modules ship in the separate Pro add-on; the helper that performs the token and profile requests is part of this plugin.
Requests require the matching module installed, enabled, and configured with your OAuth application. Choosing sign-in opens provider authorization with application ID, callback URL, permissions, and security state. After approval, your site exchanges authorization code/application credentials for an access token, then retrieves account ID, name, permitted email, and profile image to sign in/create a WordPress account. No WordPress password is sent. GitHub may request GET /user/emails with that token and user:email permission; see API documentation.
Facebook uses https://www.facebook.com for authorization and https://graph.facebook.com for token and profile requests: Terms and Privacy.
GitHub uses https://github.com for authorization and tokens, and https://api.github.com for profile and email requests: Terms and Privacy.
Google Analytics 4
Enabled Analytics Integration requires a GA4 Measurement ID. Default Consent Mode waits for a CMP’s analytics-storage consent or the wppsmodule_allow_analytics filter (default false) before requesting scripts/sending pageviews. Disabling Consent Mode allows immediate tracking unless that filter blocks it.
On each included front-end page view, the visitor’s browser requests https://www.googletagmanager.com/gtag/js and then sends the Measurement ID, page URL, and standard GA4 event data to Google Analytics (https://www.google-analytics.com / https://analytics.google.com).
This service is provided by Google: Terms and Privacy.
Google reCAPTCHA
This integration requires the separate Pro add-on. The free plugin’s admin script still contains the Test connection loader. Enabled reCAPTCHA loads https://www.google.com/recaptcha/api.js and related https://www.gstatic.com assets when you click Test connection. Protected front-end forms exchange browser tokens with Google; your site posts the token and secret key to https://www.google.com/recaptcha/api/siteverify for anti-spam verification.
This service is provided by Google: Terms and Privacy.
Cloudflare Turnstile
This integration requires the separate Pro add-on. The free plugin’s admin script still contains the Test connection loader. Enabled Turnstile loads https://challenges.cloudflare.com/turnstile/v0/api.js when you click Test connection. Protected front-end forms exchange browser tokens with Cloudflare; your site posts the token and secret key to https://challenges.cloudflare.com/turnstile/v0/siteverify for anti-spam verification.
This service is provided by Cloudflare: Terms and Privacy.
Bundled libraries and source code
Alpine.js 3.17.2 is bundled as minified production JavaScript from the official npm package. Source code, license, and build instructions are available at https://github.com/alpinejs/alpine.
SVG Upload includes svg-sanitize 1.0.0 (GPLv2 or later), with a prefixed PHP namespace to avoid plugin conflicts. Its source and license are available at https://github.com/darylldoyle/svg-sanitizer and in modules/svg-upload/includes/svg-sanitize. Sanitization runs locally. External resources, unsafe CSS and active content are removed; SVG files with ambiguous IDs, excessive complexity or invalid reference graphs are rejected.



