Search by

sympress / base-mu-plugin

brianvarskonst

Shared WordPress must-use bootstrap and development utilities for SymPress websites.

Package info

github.com/SymPress/base-mu-plugin

Type:wordpress-muplugin

pkg:composer/sympress/base-mu-plugin

Statistics

Installs: 19

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 1

v1.2.0 2026-10-07 15:35 UTC

This package is auto-updated.

Last update: 2026-10-07 16:37:37 UTC


README

Shared must-use plugins for WordPress websites running the SymPress kernel. The package extracts the common bootstrap from SymPress Starter and Demo. The kernel entry is kernel.php, replacing app-starter.php.

Installation

Require sympress/base-mu-plugin in the website Composer project, together with composer/installers, sympress/runtime:^1.2.5 and roots/wordpress. The package is available on Packagist. Install the stable v1 release directly:

composer require sympress/base-mu-plugin:^1.0

Configure the website's MU-plugin installation path:

{
    "require": {
        "sympress/base-mu-plugin": "^1.0"
    },
    "extra": {
        "installer-paths": {
            "public/wp-content/mu-plugins/{$name}/": ["type:wordpress-muplugin"]
        }
    }
}

Runtime builds the MU loader. This package declares extra.sympress-runtime.boots-kernel: true; remove the previous app-starter.php or website site-bootstrap package so that there is exactly one boot provider. With kernel-boot: true, Runtime detects this package and skips its generated kernel starter. An explicit kernel-boot: false also works because this package owns the boot.

Enable wp-config-autoload: true in the website's Runtime configuration. The generated wp-config.php loads the website Composer autoloader and provides its project directory through SYMPRESS_RUNTIME_PATH before loading MU plugins. The shared bootstrap uses that explicit path. Copied and symlinked installations use the same contract; custom Composer vendor directories are handled by Runtime.

When migrating Starter or Demo, remove the old Composer path repository for packages/base-mu-plugins and replace the old package requirement with sympress/base-mu-plugin. Composer resolves the shared package from Packagist; no VCS repository entry is required.

For local development, use a Composer path repository pointing at this package with options.symlink: true. Install into the same MU-plugin path. A production Composer installation copies the package instead.

Behavior

  • frontend-performance.php uses native browser/OS emoji fonts on public pages and embeds. It removes WordPress's emoji capability test, worker, fallback download and frontend emoji styles. Admin hooks and server-side email/feed conversion remain registered. Older systems may not render newly introduced emoji without WordPress's image fallback.
  • kernel.php boots SiteKernel once with the project directory supplied through SYMPRESS_RUNTIME_PATH. Runtime loads the website dependencies first. Missing or invalid project paths and unloaded dependencies fail explicitly.
  • 000-error-reporting.php retains notices and deprecations for logging, respects WP_DEBUG_DISPLAY in development, and hides error output in production, REST, JSON, AJAX, XML-RPC, WP-CLI and installation requests. Existing error handlers and the WordPress debug log configuration remain in control.
  • allowed-html-tags.php permits source[src,type] in post content and preserves existing allowed attributes and other sanitizer contexts.
  • media-library.php adds a file-size column to the Media Library list view. It reads the original attachment's stored filesize metadata, without scanning files or calculating the total size of generated thumbnails. Missing or invalid metadata displays a dash. Stored file sizes require WordPress 6.0 or newer.
  • site-utilities.php provides the optional policies listed below. All are disabled by default; enable only the behavior the website needs.
  • vardumper-integration.php enables Symfony VarDumper only when SYMPRESS_ENABLE_VARDUMPER=true, the WordPress environment is local or development, the request is outside wp-admin and symfony/var-dumper is installed. dump() and dd() are supplied only when missing; existing helpers are preserved. dd() stops execution with HTTP 500 through wp_die().

The package does not remove roles, comments, feeds, block styles or media pages. Those are website decisions. It does not modify content, users or WordPress salts.

Optional site utilities

Set a boolean constant in the website configuration or the matching environment variable to true. Constants take precedence over environment variables; Dotenv values in $_SERVER take precedence over $_ENV and the process environment. Missing or invalid values keep the feature disabled. The matching WordPress filter receives that boolean and may override it by returning true or false. Filters are evaluated on init, after regular plugins and the website kernel have loaded.

Constant / environment variable Filter Effect when enabled
SYMPRESS_DISABLE_DASHBOARD_NEWS sympress_disable_dashboard_news Removes the Events and News widget from the site dashboard
SYMPRESS_DISABLE_AVATARS sympress_disable_avatars Disables WordPress avatar display through option_show_avatars
SYMPRESS_DISABLE_TRACKBACKS sympress_disable_trackbacks Closes incoming pingbacks and trackbacks through pings_open; keeps comments unchanged
SYMPRESS_REMOVE_GENERATOR sympress_remove_generator Removes the WordPress generator from wp_head; keeps feed generators
SYMPRESS_REMOVE_RSD_LINK sympress_remove_rsd_link Removes the RSD discovery link from wp_head
SYMPRESS_REMOVE_SHORTLINKS sympress_remove_shortlinks Removes the shortlink head tag and HTTP header; keeps shortlink APIs

For example, in the website's .env:

SYMPRESS_DISABLE_DASHBOARD_NEWS=true
SYMPRESS_DISABLE_TRACKBACKS=true

Or register a filter in website code before init:

add_filter('sympress_remove_generator', '__return_true');

Disabling avatars does not block plugins that request Gravatar directly. Closing incoming pings does not disable outgoing pings or close the XML-RPC endpoint. Feed discovery, REST discovery and oEmbed remain registered even when all head utilities are enabled. The package does not register an email shortcode.

Keep file-editor policy and revision limits in the website's Runtime configuration (DISALLOW_FILE_EDIT and WP_POST_REVISIONS), and user-enumeration protection in sympress/security. Mail delivery, account registration, password resets, application passwords, image sizes, AI integrations, admin notices and update policy remain website or deployment decisions.

For a real WordPress frontend check, run wp eval-file against tests/site/frontend-performance-check.php in the website. The check reads the homepage and validates retained admin/email/feed hooks without changing content. Run wp eval-file tests/site/site-utilities-check.php from a source checkout to check media rendering and opted-in utilities against real WordPress hooks. It uses request-local metadata and hooks without writing content or options.

Development

PHP 8.5 or newer is required. Install dependencies and run composer qa for the shared SymPress coding standard, PHPStan and PHPUnit. Tests cover installation paths, copied/symlinked bootstraps, repeated boot, sanitizer merging and debug output policies. Composer locks, generated files and local AI instructions are excluded from Git.

Provenance and license

The bootstrap and utility behavior originate from SymPress Starter and SymPress Demo. Starter is GPL-2.0-or-later; Demo's MIT permission and copyright notice are retained in NOTICE. This package is distributed under GPL-2.0-or-later; see LICENSE. The media-library and optional site-utility behavior adapts selected ideas from WPExplorer MU-Plugins, also licensed under GPL-2.0-or-later. Its attribution is retained in NOTICE.