WP Config turns WordPress constants on and off without opening wp-config.php.
Each switch writes a define() line into wp-config.php for you.
Find it under Utilities → WP Config in the DevKit sidebar.
How the switches work
- Each switch saves itself the moment you flip it. A toast confirms it, for example "Disable WP-Cron saved to wp-config.php."
- Switching a constant off writes
falseinstead of removing the line, so a constant is never left half-defined. - If wp-config.php cannot be updated, the switch goes back to where it was and the error is shown.
- Only the constant you flipped is written. Constants you never touch do not get a line in wp-config.php.
- A new line is added just above the line in wp-config.php that loads
wp-settings.php. A constant already defined in wp-config.php is changed in place.
Constants
Updates
- Skip new bundled themes (
CORE_UPGRADE_SKIP_NEW_BUNDLED): don't install new default themes when WordPress updates. - Disable automatic updates (
AUTOMATIC_UPDATER_DISABLED): turn off all automatic background updates.
Security
- Disable file editors (
DISALLOW_FILE_EDIT): turn off the plugin and theme file editors in wp-admin. - Disallow unfiltered HTML (
DISALLOW_UNFILTERED_HTML): stop every user, admins too, from posting unfiltered HTML.
Setup & maintenance
- Allow multisite setup (
WP_ALLOW_MULTISITE): show the Network Setup screen under Tools, the first step to a multisite. - Allow database repair (
WP_ALLOW_REPAIR): enablewp-admin/maint/repair.php, which anyone can open. Turn it off again once the repair is done.
Cron
- Disable WP-Cron (
DISABLE_WP_CRON): don't run WP-Cron on page loads (use a real cron job instead). - Alternate WP-Cron (
ALTERNATE_WP_CRON): run WP-Cron through a redirect, for hosts that block loopback requests.
Media
- Overwrite edited images (
IMAGE_EDIT_OVERWRITE): overwrite the original when editing an image, instead of keeping copies. - Media trash (
MEDIA_TRASH): move media to the trash instead of deleting it at once.
Network & errors
- Block external HTTP requests (
WP_HTTP_BLOCK_EXTERNAL): block outgoing HTTP requests (updates and APIs too) except to this site. - Disable fatal error handler (
WP_DISABLE_FATAL_ERROR_HANDLER): turn off WordPress's fatal error "recovery mode" handler.
Only constants where "not defined" behaves the same as false are listed.
DISALLOW_FILE_MODS, FORCE_SSL_ADMIN and WP_CACHE are left out on purpose, because one click on any of them can lock you out of the admin.
Locked switches
A switch is shown locked, and cannot be changed, when DevKit cannot safely rewrite the constant:
- Set outside wp-config.php: the constant is already on, but not from a
define()that DevKit can find in wp-config.php. - Set in wp-config.php with a non-literal value: the constant is defined in wp-config.php with a variable, a function call or another constant instead of
trueorfalse. Edit it by hand.
DevKit never claims a value it does not control.
wp-config.php is not writable
If the file cannot be written, a warning appears at the top:
wp-config.php is not writable. DevKit can show these constants but cannot save them until file permissions allow writes.
All switches are disabled until the file permissions allow writes.