English · Português (Brasil)
A collection of PHP functions to paste into a WordPress theme's
functions.php (or into a functionality plugin, if you would rather
not edit the theme directly). It covers performance, technical SEO,
login security and image optimization, without an extra plugin for
each task.
functions.php: a set of standalone functions (disable XML-RPC, disable emoji, remove Heartbeat, clean up<head>, build a clean slug, count the words in a post, among others). Each block has a comment explaining what it does. Copy only the blocks that make sense for your project; you do not have to paste the whole file. Theword_count()function runsstrip_tags()before counting, so an HTML tag in the content is not counted as a word.recaptcha-v3-wp-login.php: adds reCAPTCHA v3 to the WordPress login screen without a plugin.image-optimization.php: automatically creates a WEBP version of every JPG and PNG image uploaded to the media library (credit to Rafael Oliveira for the original logic). It also allows SVG and WEBP uploads and definesALLOW_UNFILTERED_UPLOADS, so review that part before using it.
- Copy the contents of the file you want.
- Paste it into your theme's (or child theme's)
functions.php. Never paste it into the parent of a third-party theme, so the change survives updates. - For
recaptcha-v3-wp-login.php, define the two constants inwp-config.phpbefore pasting the function (see the section below). - Test on a staging site before going to production. Some functions (removing jQuery, removing Heartbeat) can break plugins that depend on them.
The file does not contain any key. This is on purpose, so no
credential leaks if the theme is kept in a public repository. Add this
to wp-config.php, before the /* That's all, stop editing! */ line:
define('RECAPTCHA_SITE_KEY', 'sua-site-key-aqui');
define('RECAPTCHA_SECRET_KEY', 'sua-secret-key-aqui');Keys are created at google.com/recaptcha/admin, choosing reCAPTCHA v3.
The login error messages in this file are in Brazilian Portuguese.
Do I have to paste the whole functions.php?
No. It is a collection of independent functions; use only the blocks
that make sense for your site.
Does it work with any theme?
The functions use standard WordPress hooks (add_action,
add_filter), so they work with any well-built theme. Some of them
(removing Jetpack-specific CSS and JS, for example) only have an effect
if the matching plugin is installed.
Is it safe to remove jQuery, Heartbeat and emoji from WordPress? On most sites yes, but test first: some third-party plugins depend on the global jQuery or on the Heartbeat API to work correctly.
Functions provided as is, to adapt to your project. This is not a plugin with a settings screen or automatic updates.
Bug reports and suggestions are welcome through GitHub Issues.
Lucas Ferraz is an SEO, website development and Generative Engine Optimization specialist and the founder of Lucas Ferraz SEO.
MIT. See LICENSE.