Title: Npcink Site Toolbox
Author: Npcink
Published: <strong>August 24, 2026</strong>
Last modified: August 24, 2026

---

Search plugins

![](https://s.w.org/plugins/geopattern-icon/npcink-site-toolbox.svg)

# Npcink Site Toolbox

 By [Npcink](https://profiles.wordpress.org/muze233/)

[Download](https://downloads.wordpress.org/plugin/npcink-site-toolbox.3.3.2.zip)

 * [Details](https://wordpress.org/plugins/npcink-site-toolbox/#description)
 * [Reviews](https://wordpress.org/plugins/npcink-site-toolbox/#reviews)
 *  [Installation](https://wordpress.org/plugins/npcink-site-toolbox/#installation)
 * [Development](https://wordpress.org/plugins/npcink-site-toolbox/#developers)

 [Support](https://wordpress.org/support/plugin/npcink-site-toolbox/)

## Description

Npcink Site Toolbox is a utility plugin for WordPress site owners. Version 3.3.2
provides 56 registered modules: 55 opt-in modules and one always-loaded runtime 
module, plus three editor patterns and two dynamic blocks. Features cover site and
media settings, content and SEO, login and comment safeguards, China-focused integrations,
diagnostics, and maintenance.

#### Current features

 * Seven admin views: Overview, Site and Media, Content and Pages, SEO and Enhancements,
   China Ecosystem, Maintenance Tools, and About and Help.
 * Site and media: link, upload, image, admin-list, and optional CDN settings.
 * Content and SEO: comment controls, restricted content, reading tools, metadata,
   internal links, search health, and publishing statistics.
 * Security: login-attempt protection and anonymous author-enumeration protection.
 * China-focused integrations: ICP information, WeChat JSSDK, cookie notice, and
   optional object storage.
 * Maintenance: diagnostics, SEO checks, media health, and guarded database cleanup.
 * Admin experience: feature search, risk labels, change confirmation, secret-status
   handling, and responsive layouts.
 * Editor tools: three core-block patterns, a live site-statistics block, and a 
   GitHub project block with cached public repository metadata plus an optional 
   author-written summary.
 * Public source and reproducible build instructions: [GitHub repository](https://github.com/npcink/npcink-site-toolbox#readme).

#### Important behavior

All modules that contact a third party are disabled by default. An administrator
must explicitly enable the related module or manually run a connectivity check. 
The plugin does not send telemetry to its developer.

### External Services

No external service is contacted merely by activating the plugin.

#### GitHub project block

Only after a content author inserts this block and supplies a public repository 
URL does the server call GitHub’s “Get a repository” API on a cache miss. The endpoint
is formed from the submitted public owner and repository names. The author may also
save an optional custom project summary in the article; that summary is rendered
locally and is not sent to GitHub. The request sends the public owner/repository
identifier, the site server’s IP address, the plugin User-Agent, and normal HTTP
headers to retrieve the repository description, primary language, Stars, Forks, 
and archive status. Successful responses are cached locally for up to 12 hours and
failures for 30 minutes. No GitHub credentials, article content, custom summary,
plugin settings, visitor IP address, or visitor browser request is sent. [Service and endpoint documentation](https://docs.github.com/en/rest/repos/repos#get-a-repository),
[GitHub Terms of Service](https://docs.github.com/en/site-policy/github-terms/github-terms-of-service),
[GitHub General Privacy Statement](https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement).

#### WeChat JSSDK

When an administrator enables WeChat JSSDK and configures an AppID and AppSecret,
the server sends those credentials to the WeChat token API and later sends the access
token to the ticket API. On singular content, the visitor’s browser loads the remote
JSSDK and supplies the current URL, title, excerpt, and thumbnail URL for sharing.
[Service](https://developers.weixin.qq.com/doc/offiaccount/OA_Web_Apps/JS-SDK.html),
[terms](https://weixin.qq.com/cgi-bin/readtemplate?lang=zh_CN&t=weixin_agreement&s=default),
[privacy](https://weixin.qq.com/cgi-bin/readtemplate?lang=zh_CN&t=weixin_agreement&s=privacy).

#### Object storage

Before saving or enabling object storage, an administrator may explicitly run the
connection test. It sends the selected provider the current saved or draft credentials,
bucket, provider-specific endpoint or region, optional object-key prefix, signed
authorization data, and a short text payload. The payload writes or overwrites `
npcink-site-toolbox/connection-test.txt`, placed below the configured prefix when
one is present. The test object remains in the selected bucket; rerunning the test
overwrites the same object instead of creating more objects. The test does not require
a public media URL, save settings, or change the module’s enabled state.

When an administrator enables object storage and selects a provider, each new media
upload sends the file bytes, prefixed object key, bucket, provider-specific endpoint
or region, access-key identifier, and signed authorization data to that provider.
Local media files are retained. The configured public URL prefix is used only to
replace media URLs after every generated file uploads successfully. Saved credentials
and target settings remain in the local WordPress database; unsaved draft credentials
are used only for the administrator-triggered connection test. Providers: [Alibaba Cloud OSS](https://www.aliyun.com/product/oss)(
[terms](https://terms.aliyun.com/legal-agreement/terms/suit_bu1_ali_cloud/suit_bu1_ali_cloud201912232313_55403.html),
[privacy](https://terms.aliyun.com/legal-agreement/terms/suit_bu1_ali_cloud/suit_bu1_ali_cloud202107091605_49213.html));
[Tencent Cloud COS](https://cloud.tencent.com/product/cos) ([terms](https://cloud.tencent.com/document/product/301/1967),
[privacy](https://cloud.tencent.com/document/product/301/11470)); [Qiniu Kodo](https://www.qiniu.com/products/kodo)(
[terms](https://www.qiniu.com/agreements/user-agreement), [privacy](https://www.qiniu.com/agreements/privacy-right)).

#### Baidu Analytics

When its module is enabled and a site ID is saved, front-end pages load Baidu Analytics.
The visitor’s browser may send the page URL, referrer, IP address, User-Agent, and
data described by Baidu. [Service](https://tongji.baidu.com/), [terms](https://tongji.baidu.com/web/help/article?id=314&type=0),
[privacy](https://tongji.baidu.com/web/help/article?id=330&type=0).

#### DeepSeek diagnostic analysis

This optional action requires WordPress 7.0 or newer and a separately installed 
and connected DeepSeek Provider. The AI tab offers troubleshooting, performance 
analysis, maintenance-result interpretation, pending-setting risk explanation, and
before/after verification. Only after an administrator reviews the relevant allowlisted
snapshot or ordinary pending-setting paths and explicitly starts analysis does the
server send data through the WordPress AI Client. An administrator may ask up to
three follow-up questions under the same bounded allowlisted facts; each follow-
up resends the original facts, initial answer, and completed follow-up turns. This
temporary history exists only in the current browser page and is cleared by switching
modes or refreshing. Performance data is a one-time snapshot rather than monitoring
or load testing. Maintenance analysis may include aggregate database, SEO, media,
search-health, and object-storage configuration facts; raw search terms are excluded.
Setting analysis excludes every credential path and summarizes non-boolean strings
by empty/configured state and length rather than content. Verification baselines
remain only in the current browser page. The diagnostic allowlist excludes site 
URLs, file paths, database identities, users, content, comments, request logs, and
credentials. DeepSeek receives the server IP, normal HTTP headers, the prompt, and
the API credential managed by WordPress Connectors and the provider plugin. Npcink
Site Toolbox does not read that credential and does not persist goals, snapshots,
baselines, follow-up history, or AI responses. No suggested action is performed 
automatically. [DeepSeek](https://www.deepseek.com/), [terms](https://cdn.deepseek.com/policies/en-US/deepseek-open-platform-terms-of-service.html),
[privacy](https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html).

Google Search Console and Bing Webmaster Tools options only print administrator-
supplied verification meta tags. They do not make outbound requests. [Google service](https://search.google.com/search-console/about),
[Google terms](https://policies.google.com/terms), [Google privacy](https://policies.google.com/privacy);
[Bing service](https://www.bing.com/webmasters/about), [Microsoft terms](https://www.microsoft.com/servicesagreement),
[Microsoft privacy](https://privacy.microsoft.com/privacystatement).

### Source Code and Build

The public source matching this exact plugin release is published at tag [v3.3.2](https://github.com/npcink/npcink-site-toolbox/tree/v3.3.2).
The readable sources are in [vite/admin/src](https://github.com/npcink/npcink-site-toolbox/tree/v3.3.2/vite/admin/src)
and [vite/count/src](https://github.com/npcink/npcink-site-toolbox/tree/v3.3.2/vite/count/src),
with the build manifest at [vite/package.json](https://github.com/npcink/npcink-site-toolbox/blob/v3.3.2/vite/package.json).

Reproduce the Admin and Count assets with:

    ```
    git clone https://github.com/npcink/npcink-site-toolbox.git

    cd npcink-site-toolbox

    git checkout v3.3.2

    cd vite

    corepack enable

    pnpm install --frozen-lockfile

    pnpm run build
    ```

The generated files are written to `vite/admin/dist/` and `vite/count/dist/`.

The site-statistics and GitHub project block editor scripts are shipped as readable
source in `blocks/site-stats/index.js` and `blocks/github-project/index.js`; they
have no separate build step.

### Privacy Policy

Search Health can store search terms and counters in the local WordPress database.
Login protection, audit, and diagnostic features can store login failures, IP addresses,
actions, and diagnostic results locally when enabled. Site administrators are responsible
for an appropriate privacy notice and retention policy.

The plugin does not automatically upload this local data or telemetry to its developer.
Third-party requests occur only under the triggers documented in External Services.
Credentials used by this plugin are stored in WordPress options and are sent only
to the administrator-selected WeChat or object-storage provider when required for
authentication. DeepSeek credentials are managed by WordPress Connectors and the
separately installed provider plugin; Npcink Site Toolbox does not read or store
them.

## Blocks

This plugin provides 2 blocks.

 *   站点数据 展示文章、评论、分类和用户数量，并始终读取当前站点数据。
 *   GitHub 项目 展示公开 GitHub 仓库的描述、主要语言、Stars 和 Forks。

## Installation

 1. Install the ZIP through Plugins > Add Plugin > Upload Plugin, or copy the plugin
    directory to `/wp-content/plugins/`.
 2. Activate Npcink Site Toolbox from the Plugins screen.
 3. Open Plugins > Npcink Site Toolbox and enable only the features you need.

## FAQ

### Does it support multisite?

The current release targets single-site installations. Multisite behavior is not
guaranteed.

### Does it work with every theme?

No. Features that depend on theme markup are identified in the admin interface. 
Test them on a staging site before enabling them in production.

### What happens on uninstall?

Deactivate and delete the plugin. Its uninstall routine removes plugin options, 
scheduled tasks, temporary caches, comment moderation markers, and runtime-only 
attachment markers. It does not delete or rewrite media files, remote object-storage
objects, posts, comments, or terms. WebP recovery metadata is retained so an already
converted attachment does not lose the information needed to restore its original
JPEG; restore converted media before uninstalling if you want the plugin to perform
that rollback.

### Is it translation-ready?

Yes. Its text domain is `npcink-site-toolbox`.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Npcink Site Toolbox” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ Npcink ](https://profiles.wordpress.org/muze233/)

[Translate “Npcink Site Toolbox” into your language.](https://translate.wordpress.org/projects/wp-plugins/npcink-site-toolbox)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/npcink-site-toolbox/),
check out the [SVN repository](https://plugins.svn.wordpress.org/npcink-site-toolbox/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/npcink-site-toolbox/)
by [RSS](https://plugins.trac.wordpress.org/log/npcink-site-toolbox/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 3.3.2

 * Release date: 2026-08-21.
 * Escaped output returned by content, title, excerpt, and image filters according
   to its HTML context.
 * Replaced dynamic PHP gettext calls in module metadata and privacy disclosures
   with literal translation mappings.
 * Added release contracts for output filters, literal gettext arguments, and external-
   service disclosures.

#### 3.3.1

 * Release date: 2026-08-17.
 * Prefixed browser globals, localized objects, thumbnail AJAX actions, asset handles,
   nonce actions, and image-size names for WordPress.org compatibility.
 * Made the readable Admin and Count sources and reproducible build contract explicit
   in the public readme and release verifier.
 * Retired remote CDN URL rewriting, external connectivity checks, and automatic
   mirror-fix proposals; object-storage integrations are unchanged.
 * Added the latest official Plugin Check to the exact-ZIP release gate.

#### 3.3.0

 * Release date: 2026-08-13.
 * Added read-only DeepSeek diagnostics through the WordPress AI Client, with allowlisted
   previews, five analysis modes, and up to three temporary follow-up turns under
   the same facts.
 * Added an opt-in authenticated self-service comment REST API and browser fallback
   page; users can manage only their own comments with WordPress application passwords.
 * Hardened WordPress.org packaging, portable ZIP verification, Plugin Check evidence,
   and documentation-link governance.
 * Fixed activation through secondary switches in compound modules and loading of
   always-on modules on fresh installations.
 * Bounded search-health write rate, daily unique terms, overflow aggregation, and
   serialized storage size.
 * Upgraded ECharts and zrender to 6.1.0 and added production dependency auditing
   to CI.

#### 3.2.0

 * Release date: 2026-07-18.
 * Added editor patterns for resource downloads, article conclusions, and source/
   copyright notes.
 * Added a dynamic site-statistics block with live article, comment, category, and
   user counts.
 * Added a dynamic GitHub project block with cached public repository metadata, 
   an optional author-written summary, and a direct-link fallback.
 * Reused one statistics provider across the site-statistics block and legacy widget
   instead of duplicating count logic.
 * Kept the editor script as readable, build-free source so the block does not create
   another Vite target or Node dependency.
 * Unified long admin settings pages with accessible, search-aware secondary tabs
   while keeping compact views direct.
 * Added an overview guide with direct post and page editor links for using the 
   bundled patterns and dynamic blocks.
 * Grouped the dynamic blocks and bundled patterns under matching Npcink Site Toolbox
   inserter categories.
 * Unified pre-release PHP identifiers and plugin-owned storage keys under the Npcink
   Site Toolbox identity without compatibility shims.
 * Added a write-based object-storage connection test, provider-specific setup examples,
   and an explicit local-file retention notice.

#### 3.1.1

 * Release date: 2026-07-18.
 * Fixed configured Cookie notice text and now constructs the notice with safe DOM
   APIs.
 * Linked the ICP registration number to the configured lookup URL.
 * Rendered category, tag, and page restriction notices on the server and removed
   redundant front-end DOM replacement.
 * Added runtime coverage for compliance and restricted-content behavior.

#### 3.1.0

 * Release date: 2026-07-17.
 * Unified the public identity as Npcink Site Toolbox.
 * Aligned the plugin file, target WordPress.org slug, text domain, admin page, 
   REST namespace, and release ZIP with `npcink-site-toolbox`.
 * Added public-identity and release-package contract tests.
 * Kept internal `MaBox_*` classes, `MAGICK_MIXTURE_*` constant names, and existing
   option keys unchanged; no settings migration or reset is required.

#### 3.0.1

 * Release date: 2026-07-16.
 * Changed the public plugin name to Magick Toolbox and aligned the WordPress.org
   slug and text domain to `magick-toolbox`.
 * Completed the plugin header, documented external services and reproducible front-
   end builds, and removed screenshot captions that had no assets.
 * Restored TLS certificate verification for connectivity checks and aligned automatic
   mirror suggestions with the documented Loli.net defaults.
 * Kept existing runtime constants and option keys unchanged; this release does 
   not migrate or reset settings.

#### 3.0.0

 * 发布日期：2026-07-16
 * Pre-GA clean break：后台收口为七个语义化视图和 57 个注册模块
 * Registry 与配置 Schema 成为单一事实源，前端类型、敏感路径和搜索索引由契约生成
 * 敏感设置只返回配置状态，替换或清除必须显式提交；保存前展示真实差异与风险确认
 * 移除 AI Provider Runtime、不可信登录验证码、防爬虫/防水墙遗留、百度推送和无消费
   者 REST 表面
 * 统一管理 REST 客户端，重建加载、错误、空状态、键盘路径和移动端布局

#### 2.6.1

 * PHPStan 静态分析门禁（CI 与本地命令统一）
 * 搜索健康中心：开启 hotwords 后自动挂载主查询采集与无结果追踪
 * REST 搜索日志端点兼容 keyword 参数，移除 check_ajax_referer 依赖
 * 版本号同步到 2.6.1
 * Vite base 路径修复

#### 2.6.0

 * 修复百度推送模块语法错误（类体提前关闭）
 * 修复搜索增强模块语法错误（同模式）
 * 修复短代码运行器语法错误（PHP 标签混合）
 * 修复 PHP 8.2 废弃警告（${var}  {$var}）
 * 新增全量 PHP 语法检查脚本（bin/php-lint.sh）
 * 新增首次配置向导（3 场景：博客/企业/内容站）
 * 新增一键国内环境适配（检测 + 修复 Gravatar/Google Fonts/Ajax）
 * 体检中心新增”中国访问适配”评分项
 * 数据库清理、数据库导出移入高风险层级
 * SVG 上传移入进阶层级
 * 高风险功能默认折叠，开启前必须确认
 * 数据库清理必须先预览再执行
 * 修复登录安全 IP 锁定 IP 伪造风险
 * 诊断报告导出脱敏（隐藏 API Key/Secret）
 * 统一 Dashboard 双评分卡为后端诊断驱动
 * 新增”导出诊断报告并反馈”引导入口

#### 2.5.0

 * 新增站点体检中心（后端诊断评分 + 前端 Dashboard 展示）
 * 保存配置前新增 diff 确认弹窗，高风险变更标红提示
 * 支持按模块恢复默认值（9 个顶层模块）
 * 新增诊断报告导出（Markdown 格式）
 * 优化 3 个官方推荐配置方案（博客/企业/内容站）
 * 统一 REST response body 格式
 * 修复 saveOption 拼写错误

#### 2.4.0

 * 重构配置层架构，REST API 替代 Ajax
 * 添加 PHP Schema 校验
 * 添加审计日志中心
 * 添加频率限制器
 * 添加站点健康检测
 * 前端数据流优化
 * 稳定性整改

#### 2.3.0

 * 添加 AI 审核引擎

#### 2.2.0

 * 添加国内生态模块
 * 添加性能优化模块
 * 配置拆分管理

#### 2.1.0

 * 配置存储拆分
 * 添加批量替换功能
 * 添加数据库导出安全脱敏

#### 2.0.0

 * 全新 React 管理后台
 * 按需加载架构
 * Vite 构建工具迁移

## Meta

 *  Version **3.3.2**
 *  Last updated **3 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.3 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [optimization](https://wordpress.org/plugins/tags/optimization/)[performance](https://wordpress.org/plugins/tags/performance/)
   [security](https://wordpress.org/plugins/tags/security/)[toolbox](https://wordpress.org/plugins/tags/toolbox/)
 *  [Advanced View](https://wordpress.org/plugins/npcink-site-toolbox/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/npcink-site-toolbox/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/npcink-site-toolbox/reviews/)

## Contributors

 *   [ Npcink ](https://profiles.wordpress.org/muze233/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/npcink-site-toolbox/)

## Donate

Would you like to support the advancement of this plugin?

 [ Donate to this plugin ](https://www.npc.ink/)