Scope
Create a single versioned document holding the plugin advisories, so the guidance lives in one reviewable place alongside the approved plugin register.
Section 1 — Replaced natively in the starter theme/plugin
For each of these, state the plugin, the native replacement, and the caveat:
| Plugin |
Native replacement |
| Safe SVG |
upload_mimes gated on a capability + enshrined/svg-sanitize on upload |
| WP Mail SMTP, Change Mail Sender |
phpmailer_init from constants + sender fields in Settings → General |
| Cachebuster |
filemtime() asset versioning helper |
| Disable Emails |
pre_wp_mail short-circuit driven by wp_get_environment_type() |
| View Transitions |
native CSS @view-transition |
| Carousel Slider Block |
CSS scroll-snap with core blocks |
| GTM4WP, Google Site Kit |
container snippet and dataLayer output from the enhancement plugin |
| WPFront Scroll Top |
CSS plus a few lines of JS in the theme |
| Disable Comments RB |
core discussion settings |
| User Menus, Visibility Logic for Elementor |
block theme templates and template parts |
| Social Sharing Block |
pattern with plain share URLs, no JS |
| JWT Authentication for WP-API |
core Application Passwords |
| Yoast Duplicate Post |
row action plus wp_insert_post clone |
Section 2 — Gravity Forms usage advisory
- Gravity Forms is the approved platform for enquiry, application, quote and upload forms.
- It must not be used for elements rendered site-wide, newsletter sign-ups, or pop-ups. Its front-end payload is disproportionate for those cases and it degrades Core Web Vitals.
- Document the required alternative: a newsletter sign-up is a plain form posting to a REST route that calls the provider API; a pop-up is
<dialog> with minimal JS. Include a reference implementation for each so the advisory is actionable rather than only a prohibition.
Section 3 — Do not replace natively
State explicitly, with reasons, that these stay as plugins: Gravity Forms itself, Wordfence, User Switching, Yoast SEO, all payment gateways, WooCommerce Subscriptions, FacetWP, SearchWP, Sequential Order Numbers.
Section 4 — Hosting-stack advisories
- WP Rocket: the LightSpeed fleet already runs nginx FastCGI page caching and Cloudflare edge caching. A third page-cache layer is redundant and a stale-content risk. Approve for asset optimisation only, or not at all, on LightSpeed hosting.
- Accessibility Checker: run accessibility checks in CI (axe or pa11y in a GitHub Action) rather than as a production plugin.
- Redirection: prefer server-level redirects for migrations and bulk URL changes; use the plugin only where editors need to manage redirects themselves.
- Analytics: one tool owns each event. No duplicate purchase, checkout or form events across Site Kit, GTM, WooCommerce Google Analytics Pro and the Gravity Forms add-on.
Acceptance criteria
Definition of Ready (DoR)
Definition of Done (DoD)
Scope
Create a single versioned document holding the plugin advisories, so the guidance lives in one reviewable place alongside the approved plugin register.
Section 1 — Replaced natively in the starter theme/plugin
For each of these, state the plugin, the native replacement, and the caveat:
upload_mimesgated on a capability +enshrined/svg-sanitizeon uploadphpmailer_initfrom constants + sender fields in Settings → Generalfilemtime()asset versioning helperpre_wp_mailshort-circuit driven bywp_get_environment_type()@view-transitiondataLayeroutput from the enhancement pluginwp_insert_postcloneSection 2 — Gravity Forms usage advisory
<dialog>with minimal JS. Include a reference implementation for each so the advisory is actionable rather than only a prohibition.Section 3 — Do not replace natively
State explicitly, with reasons, that these stay as plugins: Gravity Forms itself, Wordfence, User Switching, Yoast SEO, all payment gateways, WooCommerce Subscriptions, FacetWP, SearchWP, Sequential Order Numbers.
Section 4 — Hosting-stack advisories
Acceptance criteria
block-plugin-scaffold/block-theme-scaffoldwhere the replacement is generator-specific code, or the official WordPress core documentation where the replacement is a WordPress core feature.Definition of Ready (DoR)
Definition of Done (DoD)