Title: Scotty
Author: gfazioli
Published: <strong>zosun 27, 2024</strong>
Last modified: kɔnyasun 6, 2026

---

Search plugins

![](https://ps.w.org/scotty/assets/banner-772x250.jpg?rev=3495684)

![](https://ps.w.org/scotty/assets/icon-256x256.png?rev=3495684)

# Scotty

 By [gfazioli](https://profiles.wordpress.org/gfazioli/)

[Download](https://downloads.wordpress.org/plugin/scotty.2.2.1.zip)

[Live Preview](https://fon.wordpress.org/plugins/scotty/?preview=1)

 * [Details](https://fon.wordpress.org/plugins/scotty/#description)
 * [Reviews](https://fon.wordpress.org/plugins/scotty/#reviews)
 *  [Installation](https://fon.wordpress.org/plugins/scotty/#installation)
 * [Development](https://fon.wordpress.org/plugins/scotty/#developers)

 [Support](https://wordpress.org/support/plugin/scotty/)

## Description

Scotty is the all-in-one solution for controlling, cleaning, and optimizing your
WordPress site. With a modern React-based dashboard and a powerful feature suite,
Scotty empowers you to analyze and maintain your database, manage cron jobs, fine-
tune security, and control dozens of hidden WordPress settings — all from a single,
intuitive interface.

For full documentation, visit the [Scotty website](https://scotty-plugin.vercel.app).

### Cleaning

 * **Trash Management** — Delete post revisions, auto-drafts, trashed posts, unapproved/
   spam/trashed comments, orphaned metadata, and transient options in bulk or one
   by one.
 * **Duplicates Detection** — Identify and remove duplicate entries across post 
   meta, comment meta, user meta, and term meta tables.
 * **Orphan Cleanup** — Find and delete orphaned records in postmeta, commentmeta,
   usermeta, termmeta, and term relationships.

### Optimization

 * **Database** — View all database tables with engine, auto-increment, collation,
   and overhead info. Optimize tables and reset auto-increment values individually
   or in bulk.
 * **Disk Usage** — Overview of WordPress installation size breakdown: core, themes,
   plugins, uploads, and database.

### System

 * **Cron Manager** — View all scheduled cron jobs with next run time, schedule,
   interval, and arguments. Run, delete, search, sort, and bulk-manage cron jobs.
   Color-coded schedule badges and time-relative status indicators.
 * **Shortcode Registry** — Browse all registered shortcodes with their callback
   functions and callable status.

### WordPress Settings

Control dozens of WordPress settings organized in 6 tabs:

**General**

 * Enable/disable REST API and XML-RPC
 * Hide WordPress version from source code
 * Hide detailed login error messages
 * Disable email authentication
 * Disable the built-in file editor
 * Disable author archives (prevents user enumeration)
 * Disable Application Passwords

**Admin**

 * Show/hide admin footer credit and version
 * Show/hide the Welcome panel
 * Toggle visibility of Dashboard, Posts, Media, Pages, Comments, and Tools menu
   items
 * Disable update nags for non-admin users
 * Disable the periodic admin email verification prompt

**Writing**

 * Limit the number of post revisions
 * Disable self-pings
 * Configure auto-empty trash interval

**Reading**

 * Set custom excerpt length
 * Hide admin bar on frontend
 * Disable emoji scripts and styles
 * Disable embed scripts (wp-embed.js)
 * Disable jQuery Migrate on frontend
 * Disable RSS and Atom feeds

**Performance**

 * Disable Heartbeat API on frontend
 * Set custom Heartbeat interval
 * Remove Dashicons CSS from frontend for non-admin users

**Media**

 * Disable big image scaling (WordPress 5.3+)
 * Set custom JPEG compression quality

### Dashboard Widget

A compact dashboard widget on the WordPress Dashboard showing posts, comments, users,
and options breakdown with progress bars, plus database size and cron count at a
glance.

### Coming Soon

 * Multisite support
 * Database rename, truncate, drop, export, import
 * Database search and replace
 * Database backup
 * Scheduled auto-cleaning
 * Spotlight search (CMD+K)
 * And more…

## Screenshots

[⌊Overview Dashboard⌉⌊Overview Dashboard⌉[

Overview Dashboard

[⌊Trash Management⌉⌊Trash Management⌉[

Trash Management

[⌊Duplicates Detection⌉⌊Duplicates Detection⌉[

Duplicates Detection

[⌊Database Optimization⌉⌊Database Optimization⌉[

Database Optimization

[⌊Cron Manager⌉⌊Cron Manager⌉[

Cron Manager

[⌊Shortcode Registry⌉⌊Shortcode Registry⌉[

Shortcode Registry

[⌊WordPress General Settings⌉⌊WordPress General Settings⌉[

WordPress General Settings

[⌊WordPress Admin Settings⌉⌊WordPress Admin Settings⌉[

WordPress Admin Settings

[⌊WordPress Performance Settings⌉⌊WordPress Performance Settings⌉[

WordPress Performance Settings

[⌊WordPress Media Settings⌉⌊WordPress Media Settings⌉[

WordPress Media Settings

## Installation

 1. Upload the entire content of plugin archive to your `/wp-content/plugins/` directory.
 2. Activate the plugin through the ‘Plugins’ menu in WordPress (deactivate and reactivate
    if you’re upgrading).
 3. Done. Enjoy.

## FAQ

### 1. What is Scotty?

Scotty is a WordPress maintenance and optimization plugin with a modern React-based
dashboard. It helps you clean your database, manage cron jobs, control security 
settings, and optimize your site performance.

### 2. Do I have to back up before cleaning?

Yes, we strongly recommend backing up your database before performing any cleanup
operation.

### 3. Can I undo a cleanup operation?

No, cleanup operations are permanent. Always back up first.

### 4. Will disabling the REST API break my site?

Disabling the REST API will prevent unauthenticated access. Logged-in users will
still have access. Some plugins may require the REST API to function — test after
disabling.

### 5. Where can I find the documentation?

Full documentation, guides, and release notes are available at [scotty-plugin.vercel.app](https://scotty-plugin.vercel.app).

### 6. Can I request a new feature?

Yes! Please submit feature requests at [the support forum](https://wordpress.org/support/plugin/scotty/).

### 7. Can I report a bug?

Yes! Please report bugs at [the support forum](https://wordpress.org/support/plugin/scotty/).

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Scotty” is open source software. The following people have contributed to this 
plugin.

Contributors

 *   [ gfazioli ](https://profiles.wordpress.org/gfazioli/)

[Translate “Scotty” into your language.](https://translate.wordpress.org/projects/wp-plugins/scotty)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/scotty/), check out
the [SVN repository](https://plugins.svn.wordpress.org/scotty/), or subscribe to
the [development log](https://plugins.trac.wordpress.org/log/scotty/) by [RSS](https://plugins.trac.wordpress.org/log/scotty/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

### 2.2.1

 * Fix: every message in the Trash, Duplicates, Database, Cron and Shortcode views
   is now translatable as a whole sentence (some were English fragments glued to
   translated words, some were never extracted at all); plural forms are handled
   per language
 * Fix: the Database table headers (Name, Engine, Auto increment, Collation, Gain)
   are translated; reclaimable space is labelled KB
 * Performance: the Duplicates lists load up to eight times faster on large sites(
   6.2 s to 1.1 s for post meta on 300,000 rows) and show the first 1,000 rows instead
   of all of them
 * Fix: the colour scheme follows the system setting again until you flip the light/
   dark switch. Earlier versions saved “light” or “dark” on every visit, so the 
   automatic scheme never came back; Scotty now keeps its choice under its own key,
   which also stops it from sharing the setting with other Mantine-based plugins
 * Fix: a missing Fonts folder no longer shows a “Fonts: Timeout” badge in the Disk
   card, and an unreadable folder is labelled Unavailable rather than Timeout
 * Security: the Database tools list, optimize and reset only this site’s tables—
   on a database shared with another install, or on a multisite network, other installs’,
   other sites’ and network tables are out of reach (network admins keep the network
   tables)
 * Security: saved preferences keep only the settings Scotty knows, each with its
   expected type
 * Fix: Optimize and Reset Auto Increment report the database’s error instead of
   announcing success
 * Fix: values in the Trash and Duplicates lists show characters such as &, < and
   quotes as they are, instead of `&amp;`, `&lt;` and `&quot;`
 * Fix: the Disk chart includes the Fonts folder (WordPress 6.5+) in the chart and
   the total, and an empty folder shows 0 MB instead of a sentence
 * Fix: deleting a single orphan term relationship re-checks that it is still orphaned,
   so a live post’s category can never be removed from that list
 * Fix: disabling the REST API no longer logs a deprecation notice on every REST
   request (a filter WordPress retired in 4.7 is gone)
 * Chore: the licence is GPLv2 or later everywhere. The plugin header and this readme
   already said so, while `composer.json`, `package.json` and the `LICENSE` file
   said GPLv3; they now match
 * Fix: activating Scotty saves its default settings under its own name. Earlier
   versions wrote them to an options entry with an empty name, because activation
   ran before the plugin header had been read
 * Chore: WP Bones 2.1.2

### 2.2.0

 * Fix: “Run now” on the Cron page no longer removes the recurring schedule of the
   job it runs — the job runs at once and keeps its schedule
 * Fix: the “Scheduled Cron Jobs” counter (Overview and dashboard widget) counts
   jobs, not due times
 * Fix: duplicate meta cleanup (post, comment, term, user meta) runs as a single
   query, so a large group of duplicates can no longer leave rows behind or delete
   the wrong one
 * Fix: duplicate meta counters report the rows that will actually be removed (the
   row that is kept was counted too)
 * Fix: the Overview shows an error message instead of a blank page when its data
   cannot be loaded
 * Fix: deleting a single item from the Trash lists re-checks that it still is an
   auto-draft, a trashed post, an unapproved/spam/trashed comment or an unused term
   before removing it permanently
 * Security: the HTTP Basic Authentication handler is no longer enabled — Scotty
   never used it, and it accepted credentials on every request
 * Chore: update to Mantine UI 9, React 19 (now bundled with the plugin, WordPress
   still ships React 18) and react-router 7; WP Bones 2.0.6
 * Chore: bump “Tested up to” to WordPress 7.1
 * Chore: add PHPUnit and Jest test suites

### 2.1.1

 * Feature: add Spanish (es_ES), French (fr_FR), German (de_DE), and Brazilian Portuguese(
   pt_BR) translations alongside the existing Italian (it_IT) — 5 locales now bundled
 * Fix: Trash bulk actions dropdown now exposes a working “Delete” option (was hard-
   coded to non-functional Database actions)
 * Fix: deleting the “Oembed Post Meta” category no longer fails with Error 400 (
   missing AJAX handler)
 * Fix: deleting a single row inside “Oembed Post Meta” no longer fails with Error
   400 (missing meta_id alias in SELECT + missing AJAX handler)
 * Fix: escape underscores in oembed LIKE patterns (count/get/delete) so unrelated
   meta_keys can never be matched
 * Chore: bump “Tested up to” to WordPress 7.0
 * Chore: regenerate POT and per-locale PO/MO/JSON files (236 strings)

### 2.1.0

 * Feature: align build pipeline to WP Bones v2.0.3 — webpack auto-discovery, unified
   yarn scripts, drop gulp/babel/run-s
 * Feature: add name search box to the Shortcode view (matches the existing Cron
   view UX)
 * Feature: collapse long “Posts by type” legends to the top 5 entries with an aggregated“
   Others” bucket (#6)
 * Feature: replace the Options donut chart with a stacked progress bar for better
   2-segment readability (#7)
 * Fix: correct dashboard-widget enqueue handle after the v2 webpack output layout
   change
 * Fix: reorder withAdminAppsScript before withLocalizeScript so admin-app localize
   payloads are routed correctly
 * Chore: drop duplicated @types/* and typescript from runtime dependencies (moved
   to devDependencies only)

### 2.0.2

 * Feature: add Trash Summary card to Overview with total cleanable items, breakdown
   badges, and “Clean now” link
 * Feature: add Environment Info card to Overview showing PHP, WordPress, MySQL 
   versions, memory limit, max upload size, and server
 * Feature: add Documentation link button in Features dropdown menu
 * Feature: redesign footer with Docs and Report Issue links, WP Bones and Mantine
   UI credits with icons
 * Feature: add Database Size and Cron Jobs count to dashboard widget
 * Enhancement: add loading skeleton and error state to dashboard widget
 * Enhancement: translate all dashboard widget tooltip strings for i18n support
 * Enhancement: reduce dashboard widget bundle size by removing unused providers
   and CSS imports
 * Enhancement: add link to documentation website in readme.txt description and 
   FAQ
 * Enhancement: rewrite README.md with badges, links, features, tech stack, and 
   project structure
 * Fix: modal confirm title invisible in dark mode
 * Fix: WPBonesLogo component using wrong Mantine v8 size props (width/height instead
   of w/h)
 * Fix: dashboard widget “Open Scotty” link pointing to #trash instead of overview
 * Chore: regenerate translation files (POT, PO, MO, JSON) with all new strings (
   223 total, Italian 100%)

### 2.0.1

 * Security: restrict admin menu capability from ‘read’ to ‘manage_options’ to prevent
   subscriber access
 * Security: add integer type casting to all AJAX delete endpoints for defense-in-
   depth
 * Security: wrap remaining raw SQL queries with $wpdb->prepare() in duplicate meta
   deletion methods
 * Fix: replace non-functional EMPTY_TRASH_DAYS constant with wp_scheduled_auto_delete_period
   filter
 * Fix: replace impossible is_null() check with empty() after sanitize_text_field()
   in CronTrait
 * Fix: correct resetAutoIncrement() to accumulate results across multiple tables
 * Fix: resolve potential undefined array key when more than 13 data categories 
   exceed color palette
 * Fix: correct typo in OverviewAjaxServiceProvider ($commnets_count)
 * Performance: add ORDER BY and LIMIT 1000 to comment listing queries to prevent
   unbounded result sets
 * Enhancement: suppress deprecated WP_Debug_Data::get_sizes() notice in DiskTrait
 * Chore: align PHP version requirement to >=8.1 across composer.json, readme.txt,
   and scotty.php
 * Chore: update package.json version to match plugin version
 * Chore: update blueprint.json to use wordpress.org/plugins slug resource and target
   PHP 8.2
 * Chore: remove dead code (unused removeMenu method, empty PreferencesTrait, unreachable
   Ajax method)
 * Chore: standardize returnColumnsJson() visibility to private across all Ajax 
   service providers

### 2.0.0

Major release with security hardening, modernized stack, UI improvements, and new
features.

#### New Features

 * WordPress Settings: new Security options — disable file editor, author archives,
   Application Passwords
 * WordPress Settings: new Admin Menu options — toggle Media, Pages, Comments, Tools
   visibility
 * WordPress Settings: new Admin Notices options — disable update nags, admin email
   verification
 * WordPress Settings: new Writing options — disable self-pings, auto-empty trash
   with configurable days
 * WordPress Settings: new Reading options — disable emoji scripts, embed scripts,
   jQuery Migrate, RSS feeds
 * WordPress Settings: new Performance tab — Heartbeat control, Dashicons removal
   on frontend
 * WordPress Settings: new Media tab — disable big image scaling, custom JPEG quality
 * WordPress Settings: unified OptionsProvider with single fetch and shared Reset
   button
 * Cron: delete individual cron jobs with confirmation modal
 * Cron: bulk delete selected cron jobs
 * Cron: search/filter by hook name
 * Cron: sortable columns (hook name, next run, schedule)
 * Cron: row expansion showing signature, interval, and arguments
 * Cron: right-click context menu with Run and Delete actions
 * Cron: colored schedule badges (hourly, daily, weekly, one-time)
 * Cron: time-relative status indicators (overdue, soon, upcoming)
 * Overview: new Database Size quick card with link to Database section
 * Overview: new Scheduled Cron Jobs quick card with link to Cron section
 * Overview: clickable cards navigate to their corresponding section
 * Overview: refresh button to reload all overview data
 * Trash: bulk delete for unapproved, spam, and trashed comments
 * Trash: orphan term relationships listing, single and bulk delete
 * Duplicates: single and bulk delete for duplicate user meta and comment meta

#### Security

 * Fixed SQL injection in database optimize and auto-increment reset (table name
   whitelist)
 * Added schema validation and recursive sanitization for preferences update
 * Added esc_html() to all meta/option/comment values in JSON responses
 * Fixed hardcoded wp_posts table prefix in SQL subqueries
 * Added $wpdb->prepare() to all orphan detection queries
 * Sanitized cron hook_name and signature inputs
 * Fixed transient query missing prepared statement
 * Fixed XML-RPC error handler using PHP Error class instead of WP_Error
 * Standardized LIKE clause syntax across all queries
 * Fixed hardcoded commentmeta table prefix in orphan deletion

#### Bug Fixes

 * Fixed Disk overview showing NaN for timed-out directory calculations
 * Fixed Disk overview crash when WordPress size data contains error strings
 * Fixed division by zero in Options overview when option count is zero
 * Fixed OverviewCard pulsing indicator on arbitrary >50% values
 * Fixed admin bar removal running too early (before scripts are registered)
 * Fixed Reset to default not actually resetting options to defaults
 * Fixed each WordPress Settings tab creating a separate OptionsProvider (4 redundant
   fetches)
 * Fixed SWR mutate() not revalidating after bulk operations across all views
 * Fixed broken Refresh button in empty Trash/Duplicates view
 * Fixed Terms crash when excluded term IDs array is empty
 * Fixed translated strings interpolated in SQL (comments)
 * Fixed duplicate term meta deletion keeping wrong entry
 * Fixed Features popover Overview link not working
 * Fixed “Database Sneak Peak” typo (now “Sneak Peek”)
 * Fixed getOptions crash on undefined path segments when new options are not yet
   in database

#### Improvements

 * Migrated from npm to Yarn
 * Updated @wordpress/scripts from 27.9.0 to 31.7.0
 * Updated Mantine from 7.14.0 to 8.3.18
 * Updated all dependencies to latest compatible versions
 * Migrated to React 18 createRoot API (replaced deprecated wp.element.render)
 * Modernized tsconfig.json (es2020, react-jsx, bundler resolution)
 * Removed all unnecessary `import * as React` statements (30 files)
 * Removed deprecated MantineProvider withStaticClasses prop
 * Fixed Mantine 8 Image component rendering in header logo
 * Performance: replaced N+1 user queries with single count_users() call
 * Performance: removed repeated COUNT(*) subqueries in post/comment stats
 * Performance: added LIMIT 1000 to orphan detection queries
 * Removed esc_sql() mixing with prepare() in term relationships
 * Cleaned up dead code and unused imports across Cron, Shortcode, and Options components
 * Added error handling to Options/Preferences provider
 * Improved AJAX error throwing with structured status/statusText

### 1.1.0

 * Refactored code in TypeScript
 * Added internationalization support
 * Added total item count in Cron and Shortcode views
 * Added links in the left sidebar
 * Disabled admin notices for the Scotty view
 * Fixed unused terms view to enable deletion of unused terms

### 1.0.0

 * First public release

## Meta

 *  Version **2.2.1**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 8.1 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/scotty/)
 * Tags
 * [cleanup](https://fon.wordpress.org/plugins/tags/cleanup/)[database](https://fon.wordpress.org/plugins/tags/database/)
   [maintenance](https://fon.wordpress.org/plugins/tags/maintenance/)[optimization](https://fon.wordpress.org/plugins/tags/optimization/)
   [security](https://fon.wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://fon.wordpress.org/plugins/scotty/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/scotty/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/scotty/reviews/)

## Contributors

 *   [ gfazioli ](https://profiles.wordpress.org/gfazioli/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/scotty/)

## Donate

Would you like to support the advancement of this plugin?

 [ Donate to this plugin ](https://www.paypal.com/donate/?hosted_button_id=TBPD4R78VDMCJ)