Title: Blue Coral &#8211; Site Audit, Performance, Admin Toolkit
Author: Nguyen Le
Published: <strong>September 1, 2026</strong>
Last modified: September 1, 2026

---

Search plugins

![](https://ps.w.org/bluecoral-admin-toolkit/assets/banner-772x250.png?rev=3675712)

![](https://ps.w.org/bluecoral-admin-toolkit/assets/icon-256x256.png?rev=3675712)

# Blue Coral – Site Audit, Performance, Admin Toolkit

 By [Nguyen Le](https://profiles.wordpress.org/nguyenrom/)

[Download](https://downloads.wordpress.org/plugin/bluecoral-admin-toolkit.1.8.19.zip)

 * [Details](https://wordpress.org/plugins/bluecoral-admin-toolkit/#description)
 * [Reviews](https://wordpress.org/plugins/bluecoral-admin-toolkit/#reviews)
 *  [Installation](https://wordpress.org/plugins/bluecoral-admin-toolkit/#installation)
 * [Development](https://wordpress.org/plugins/bluecoral-admin-toolkit/#developers)

 [Support](https://wordpress.org/support/plugin/bluecoral-admin-toolkit/)

## Description

Blue Coral – Site Audit, Performance, Admin Toolkit provides practical local tools
for maintaining a WordPress site or network.

Features include:

 * Local Activity Logs with retention controls and privacy export/erasure support.
 * Security Headers, CSP helpers, and security-related site enhancements.
 * Maintenance Mode, configuration export/import, and Plugin Control tools.
 * User and avatar utilities, and an API/MCP workspace for separately configured
   clients.

The core plugin does not transmit telemetry, credentials, database contents, personal
data, or usage statistics to BlueCoral or another third party. When enabled, Activity
Logs collect and store administrator and site activity locally in the WordPress 
database. Records can include a user ID and username when present, event metadata,
and request metadata such as the request path and method, IP address, and user agent.
Sensitive values are redacted, and raw actor email is not persisted. The Toolkit
does not transmit Activity Log records to BlueCoral or another third party. Site
owners configure Activity Log retention and can use WordPress privacy export and
erasure tools. The Toolkit does not make a storage probe or request for Activity
Log storage. CSP directives are configured manually by a site administrator. The
optional MCP API is accessed only by a separately configured client that you choose.

### External services

Core Toolkit functions do not require a third-party service or BlueCoral account.
The Toolkit does not initiate requests to third-party services or load remote assets.

 * Security Headers provides manual CSP directive configuration. It has no default
   external hosts and loads no remote assets.
 * Activity Logs are stored in the WordPress database. The Toolkit does not make
   a storage probe or request for Activity Log storage.
 * The optional MCP endpoint is hosted by the WordPress site. It receives requests
   only from a client independently configured by the site administrator; it does
   not connect to a BlueCoral service.

## Screenshots

[⌊Activity Logs list with filtering and pagination.⌉⌊Activity Logs list with filtering
and pagination.⌉[

Activity Logs list with filtering and pagination.

[⌊Site Enhancements settings.⌉⌊Site Enhancements settings.⌉[

Site Enhancements settings.

[⌊Maintenance Mode controls.⌉⌊Maintenance Mode controls.⌉[

Maintenance Mode controls.

[⌊Plugin Control tools.⌉⌊Plugin Control tools.⌉[

Plugin Control tools.

[⌊Toolkit settings.⌉⌊Toolkit settings.⌉[

Toolkit settings.

## Installation

 1. Upload the `bluecoral-admin-toolkit` folder to the `/wp-content/plugins/` directory,
    or install the ZIP through **Plugins > Add New > Upload Plugin**.
 2. Activate **Blue Coral – Site Audit, Performance, Admin Toolkit** through the Plugins
    screen.
 3. Open **Blue Coral > Settings** to configure Toolkit features.

## FAQ

### Does the plugin send data to BlueCoral?

No. The core plugin operates locally in the WordPress installation and does not 
send telemetry, analytics, credentials, database contents, or Activity Log records
to BlueCoral or another third party. When enabled, Activity Logs collect and store
administrator and site activity locally in the WordPress database. See the Description
section for the local record categories, retention controls, privacy tools, and 
optional MCP integration.

### Which third-party components are bundled?

The package includes enshrined/svg-sanitize under the MIT License. Its maintained
source is https://github.com/darylldoyle/svg-sanitizer.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Blue Coral – Site Audit, Performance, Admin Toolkit” is open source software. The
following people have contributed to this plugin.

Contributors

 *   [ Nguyen Le ](https://profiles.wordpress.org/nguyenrom/)

[Translate “Blue Coral – Site Audit, Performance, Admin Toolkit” into your language.](https://translate.wordpress.org/projects/wp-plugins/bluecoral-admin-toolkit)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/bluecoral-admin-toolkit/),
check out the [SVN repository](https://plugins.svn.wordpress.org/bluecoral-admin-toolkit/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/bluecoral-admin-toolkit/)
by [RSS](https://plugins.trac.wordpress.org/log/bluecoral-admin-toolkit/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.8.19

 * Updated WordPress.org compatibility metadata to WordPress 7.1 and added release
   validation to prevent metadata drift.

#### 1.8.18

 * Hardened request, server, upload, SQL identifier, and output handling for WordPress.
   org security compliance.

#### 1.8.17

 * Removed Plugin Control behavior that could change WordPress update decisions.

#### 1.8.16

 * Removed a deferred database-maintenance integration from this WordPress.org candidate
   and retained the free Security Headers and Activity Logs settings.

#### 1.8.15

 * Improved Activity Log detail rendering and pagination compatibility, and removed
   a retired direct sign-in route.

#### 1.8.14

 * Verified the distributed package uses database-backed Activity Logs and excludes
   obsolete restricted integration, filesystem, installer, external CSP-source, 
   output-buffer, and global-configuration behavior.

#### 1.8.12

 * Updated the public display name for WordPress.org review while preserving the`
   bluecoral-admin-toolkit` directory, settings, hooks, and REST routes.

#### 1.8.11

 * Updated Activity Log disclosures.

#### 1.8.10

 * Added complete external-service disclosures and corrected Activity Log translation
   domains for WordPress.org review.

#### 1.8.8

 * Renamed the public package identity and preserved existing Toolkit settings, 
   option keys, actions, and REST routes for compatibility.
 * Clarified local-data and optional integration disclosures for WordPress.org review.

#### 1.8.7

 * Removed the redundant Plugin URI header for WordPress.org submission compliance.

#### 1.8.6

 * Consolidated bundled dependencies under `vendors/` and renamed the plugin to 
   Blue Toolkit.

#### 1.8.5

 * Added WordPress.org readme, Toolkit license, and third-party source/license notices.
 * Fixed the Toolkit coding-standard violation.

## Meta

 *  Version **1.8.19**
 *  Last updated **4 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.3 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [activity logs](https://wordpress.org/plugins/tags/activity-logs/)[administration](https://wordpress.org/plugins/tags/administration/)
   [maintenance mode](https://wordpress.org/plugins/tags/maintenance-mode/)[Security Headers](https://wordpress.org/plugins/tags/security-headers/)
   [site management](https://wordpress.org/plugins/tags/site-management/)
 *  [Advanced View](https://wordpress.org/plugins/bluecoral-admin-toolkit/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/bluecoral-admin-toolkit/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/bluecoral-admin-toolkit/reviews/)

## Contributors

 *   [ Nguyen Le ](https://profiles.wordpress.org/nguyenrom/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/bluecoral-admin-toolkit/)