New Local Media logo New Local Media Work in Progress Open projects, products, and experiments.

Defaults That Explain Themselves

Keel adds 39 sane WordPress defaults for security, updates, privacy, content, media, email, UX, and performance — each one visible under Settings → Site Defaults and independently switchable. Nothing is hidden and deactivation returns WordPress to its prior behaviour.

The 0.6 release line closes a gap in WordPress core-update reporting. Keel asks WordPress.org whether the installed release is known to be vulnerable, names the patched tip on the site’s own release line, shows every offered release and marks the one core would choose. An authorized administrator can deliberately install the same-line patch through WordPress’s own upgrader with rollback enabled. The target and compatibility checks run again on the server, and nothing installs without a click.

The consistency is the point. Closing the REST API also removes the discovery link that advertises it; disabling comments also stops the comment feed and direct get_comments() queries. Where a trade is deliberate, Keel documents it instead of making a broader claim than the code can support.

Site Health reports the posture read-only: every default and its effective state, update operability, service failures, and traceable policy overlaps. If another plugin controls the same setting, Keel names the evidence it can establish and labels what it cannot attribute instead of guessing.

Repository Details

Owner
@dknauss
Source
dknauss/Keel
WordPress.org
WordPress.org
Latest release
v0.6.5
CI
GitHub Actions
Tests
PHP 7.4–8.5 CI; live WordPress 6.4–7.2-alpha single-site, multisite, and installer matrices
License
GPL-2.0-or-later
Try It! →
🛝 WordPress Playground
Last updated
Primary language
PHP
Stars
1
Keel for WordPress ⚓

Version 0.6.5: 39 individually switchable defaults, actionable Site Health reporting, multisite policy, and deliberate installation of same-line WordPress security patches.

Screenshot Gallery

Selected screenshots from Keel. Click any image to enlarge it.

See whether the installed WordPress release is vulnerable, which same-line release fixes it, what core would choose, and whether Keel can install the patch.
Inspect and independently switch every default under Settings → Site Defaults.
Read the exact privacy and failure behaviour of password breach screening.
Copy or review the site’s complete Keel posture from Site Health Info.

Documentation

Documentation links and descriptions for Keel.
Document Description
READMEWhat Keel does, how it is built, and how it compares to the alternatives.
Competitive Teardown MatrixNine of the most-installed “disable it” plugins measured by live HTTP and PHP probes rather than readme claims — including where Keel makes a deliberate trade.
WordPress Default SettingsEvery default Keel can set, what WordPress does without it, and why the opinion is worth having.
Environment DetectionHow Keel decides what is safe to seed on a given install, including multisite-aware behaviour.
RoadmapPlanned privacy, content-integrity, performance-observability, and update-operations releases.