sympress / base-mu-plugin
Shared WordPress must-use bootstrap and development utilities for SymPress websites.
Package info
github.com/SymPress/base-mu-plugin
Type:wordpress-muplugin
pkg:composer/sympress/base-mu-plugin
Requires
- php: ^8.5
- sympress/kernel: ^1.1.7
Requires (Dev)
- symfony/var-dumper: ^8.1
- sympress/qa: ^0.1.2
Suggests
- symfony/var-dumper: Enables optional development dump() and dd() integration.
- sympress/runtime: Installs WordPress and generates the MU loader; use ^1.2.5.
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-10-07 16:37:37 UTC
README
Shared must-use plugins for WordPress websites running the SymPress kernel.
The package extracts the common bootstrap from SymPress Starter and Demo.
The kernel entry is kernel.php, replacing app-starter.php.
Installation
Require sympress/base-mu-plugin in the website Composer project, together
with composer/installers, sympress/runtime:^1.2.5 and roots/wordpress.
The package is available on
Packagist. Install the
stable v1 release directly:
composer require sympress/base-mu-plugin:^1.0
Configure the website's MU-plugin installation path:
{
"require": {
"sympress/base-mu-plugin": "^1.0"
},
"extra": {
"installer-paths": {
"public/wp-content/mu-plugins/{$name}/": ["type:wordpress-muplugin"]
}
}
}
Runtime builds the MU loader. This package declares
extra.sympress-runtime.boots-kernel: true;
remove the previous app-starter.php or website site-bootstrap package so that
there is exactly one boot provider. With kernel-boot: true, Runtime detects this
package and skips its generated kernel starter. An explicit kernel-boot: false
also works because this package owns the boot.
Enable wp-config-autoload: true in the website's Runtime configuration.
The generated wp-config.php loads the website Composer autoloader and provides
its project directory through SYMPRESS_RUNTIME_PATH before loading MU plugins.
The shared bootstrap uses that explicit path. Copied and symlinked installations
use the same contract; custom Composer vendor directories are handled by Runtime.
When migrating Starter or Demo, remove the old Composer path repository for
packages/base-mu-plugins and replace the old package requirement with
sympress/base-mu-plugin. Composer resolves the shared package from Packagist;
no VCS repository entry is required.
For local development, use a Composer path repository pointing at this package
with options.symlink: true. Install into the same MU-plugin path. A production
Composer installation copies the package instead.
Behavior
frontend-performance.phpuses native browser/OS emoji fonts on public pages and embeds. It removes WordPress's emoji capability test, worker, fallback download and frontend emoji styles. Admin hooks and server-side email/feed conversion remain registered. Older systems may not render newly introduced emoji without WordPress's image fallback.kernel.phpbootsSiteKernelonce with the project directory supplied throughSYMPRESS_RUNTIME_PATH. Runtime loads the website dependencies first. Missing or invalid project paths and unloaded dependencies fail explicitly.000-error-reporting.phpretains notices and deprecations for logging, respectsWP_DEBUG_DISPLAYin development, and hides error output in production, REST, JSON, AJAX, XML-RPC, WP-CLI and installation requests. Existing error handlers and the WordPress debug log configuration remain in control.allowed-html-tags.phppermitssource[src,type]in post content and preserves existing allowed attributes and other sanitizer contexts.media-library.phpadds a file-size column to the Media Library list view. It reads the original attachment's storedfilesizemetadata, without scanning files or calculating the total size of generated thumbnails. Missing or invalid metadata displays a dash. Stored file sizes require WordPress 6.0 or newer.site-utilities.phpprovides the optional policies listed below. All are disabled by default; enable only the behavior the website needs.vardumper-integration.phpenables Symfony VarDumper only whenSYMPRESS_ENABLE_VARDUMPER=true, the WordPress environment islocalordevelopment, the request is outside wp-admin andsymfony/var-dumperis installed.dump()anddd()are supplied only when missing; existing helpers are preserved.dd()stops execution with HTTP 500 throughwp_die().
The package does not remove roles, comments, feeds, block styles or media pages. Those are website decisions. It does not modify content, users or WordPress salts.
Optional site utilities
Set a boolean constant in the website configuration or the matching environment
variable to true. Constants take precedence over environment variables; Dotenv
values in $_SERVER take precedence over $_ENV and the process environment.
Missing or invalid values keep the feature disabled. The matching WordPress
filter receives that boolean and may override it by returning true or false.
Filters are evaluated on init, after regular plugins and the website kernel
have loaded.
| Constant / environment variable | Filter | Effect when enabled |
|---|---|---|
SYMPRESS_DISABLE_DASHBOARD_NEWS |
sympress_disable_dashboard_news |
Removes the Events and News widget from the site dashboard |
SYMPRESS_DISABLE_AVATARS |
sympress_disable_avatars |
Disables WordPress avatar display through option_show_avatars |
SYMPRESS_DISABLE_TRACKBACKS |
sympress_disable_trackbacks |
Closes incoming pingbacks and trackbacks through pings_open; keeps comments unchanged |
SYMPRESS_REMOVE_GENERATOR |
sympress_remove_generator |
Removes the WordPress generator from wp_head; keeps feed generators |
SYMPRESS_REMOVE_RSD_LINK |
sympress_remove_rsd_link |
Removes the RSD discovery link from wp_head |
SYMPRESS_REMOVE_SHORTLINKS |
sympress_remove_shortlinks |
Removes the shortlink head tag and HTTP header; keeps shortlink APIs |
For example, in the website's .env:
SYMPRESS_DISABLE_DASHBOARD_NEWS=true SYMPRESS_DISABLE_TRACKBACKS=true
Or register a filter in website code before init:
add_filter('sympress_remove_generator', '__return_true');
Disabling avatars does not block plugins that request Gravatar directly. Closing incoming pings does not disable outgoing pings or close the XML-RPC endpoint. Feed discovery, REST discovery and oEmbed remain registered even when all head utilities are enabled. The package does not register an email shortcode.
Keep file-editor policy and revision limits in the website's Runtime configuration
(DISALLOW_FILE_EDIT and WP_POST_REVISIONS), and user-enumeration protection in
sympress/security. Mail delivery, account registration, password resets,
application passwords, image sizes, AI integrations, admin notices and update
policy remain website or deployment decisions.
For a real WordPress frontend check, run wp eval-file against
tests/site/frontend-performance-check.php in the website. The check reads the
homepage and validates retained admin/email/feed hooks without changing content.
Run wp eval-file tests/site/site-utilities-check.php from a source checkout to
check media rendering and opted-in utilities against real WordPress hooks. It
uses request-local metadata and hooks without writing content or options.
Development
PHP 8.5 or newer is required. Install dependencies and run composer qa for the
shared SymPress coding standard, PHPStan and PHPUnit. Tests cover installation
paths, copied/symlinked bootstraps, repeated boot, sanitizer merging and debug
output policies. Composer locks, generated files and local AI instructions are
excluded from Git.
Provenance and license
The bootstrap and utility behavior originate from
SymPress Starter
and SymPress Demo.
Starter is GPL-2.0-or-later; Demo's MIT permission and copyright notice are retained
in NOTICE. This package is distributed under GPL-2.0-or-later; see LICENSE.
The media-library and optional site-utility behavior adapts selected ideas from
WPExplorer MU-Plugins, also licensed
under GPL-2.0-or-later. Its attribution is retained in NOTICE.