Polanger Admin Suite
The ultimate WordPress admin customization toolkit. Take full control of your WordPress dashboard.
Introduction
Polanger Admin Suite is a comprehensive WordPress plugin that gives you complete control over your WordPress admin area. Whether you're building sites for clients, managing a multisite network, or simply want a cleaner admin experience, this plugin has you covered.
Menu Manager
Hide, rename, reorder, and control access to any admin menu item with role-based visibility.
Admin Bar
Customize the admin bar with your logo, hide items, and add custom links with icons.
Login Page
Custom login URL, beautiful design options, and reCAPTCHA protection for security.
Activity Log
Track all admin actions with GDPR-compliant logging, email alerts, and CSV export.
Dashboard Widgets
Hide default widgets, auto-hide third-party widgets, and create custom branded widgets.
Custom Admin Menu
Create custom admin sidebar menus and submenus with internal/external targets and new-tab support.
Security & 2FA
Access control, two-factor authentication, recovery keys, and Super Admin protection.
Installation
Method 1: WordPress Admin Upload
- Download the plugin ZIP file from CodeCanyon
- Go to Plugins → Add New → Upload Plugin
- Choose the ZIP file and click Install Now
- After installation, click Activate Plugin
Method 2: FTP Upload
- Extract the plugin ZIP file
- Upload the
polanger-admin-menu-managerfolder to/wp-content/plugins/ - Go to Plugins in WordPress admin and activate the plugin
You'll find the plugin menu at Polanger in your WordPress admin sidebar.
Requirements
| Requirement | Minimum | Recommended |
|---|---|---|
| WordPress | 5.0+ | 6.0+ |
| PHP | 7.4+ | 8.0+ |
| MySQL | 5.6+ | 8.0+ |
| MariaDB | 10.0+ | 10.5+ |
Admin Bar
Customize the WordPress admin bar (toolbar) that appears at the top of your site.
Custom Logo
- Replace WordPress Logo - Upload your own logo (recommended: 20x20px or 40x40px)
- Custom Link URL - Set where the logo links to
- Hide Logo Submenu - Hide items like "About WordPress", "Documentation", etc.
Manage Admin Bar Items
The plugin automatically detects all admin bar items added by WordPress, themes, and plugins.
- Auto-Detection - Finds items from Elementor, WooCommerce, and other plugins
- Hide Items - Click the eye icon to hide any item
- Rename Items - Change the display text of any item
- Frontend Support - Manage items that only appear on the frontend
Custom Links
Add your own links to the admin bar with icons and optional submenus.
| Option | Description |
|---|---|
| Title | The text displayed in the admin bar |
| URL | Where the link goes when clicked |
| Icon | Choose from 200+ Dashicons |
| Target | Same window or new tab |
| Submenu | Add dropdown items under the main link |
Login Page
Secure and customize your WordPress login page with a custom URL, beautiful design, and reCAPTCHA protection.
Custom Login URL
Change the default wp-login.php URL to something unique for added security.
- Custom Slug - Use any URL like
/my-loginor/secure-access - Block Default URLs - Redirect
wp-login.phpandwp-adminto 404 - Permalink Support - Automatically handles trailing slashes based on your settings
After enabling a custom login URL, bookmark it immediately. If you forget the URL, you'll need to disable the plugin via FTP or phpMyAdmin.
Design Options
Create a beautiful, branded login experience with these customization options:
- Upload a custom logo from the Media Library
- Set a custom link URL for the logo
- Logo appears above the login form
- Solid Color - Single color background
- Gradient - Two-color gradient at 135°
- Image - Full-screen background image
- Primary Color - Buttons and accents
- Form Background - Login form card color
- Automatic hover state generation
reCAPTCHA Protection
Protect your login page from bots and brute force attacks with Google reCAPTCHA.
Checkbox reCAPTCHA - Users click "I'm not a robot" to verify.
- Visible verification checkbox
- May show image challenges
- Best for high-security requirements
Invisible reCAPTCHA - Score-based verification without user interaction.
- No user interaction required
- Scores requests from 0.0 to 1.0
- Requests below 0.5 are blocked
- Best for user experience
reCAPTCHA can be enabled for:
- Login Form
- Registration Form
- Lost Password Form
Activity Log
Track all administrative actions on your WordPress site. The Activity Log is GDPR/KVKK compliant and never stores sensitive data like passwords or email content.
Logged Events
| Category | Events |
|---|---|
| Login | Login, Logout, Failed Login Attempts |
| Plugins | Activated, Deactivated, Deleted, Updated |
| Themes | Theme Switched, Customizer Saved |
| Content | Created, Updated, Deleted, Trashed |
| Users | Created, Deleted, Role Changed, Password Changed |
| System | Site URL, Home URL, Admin Email, Permalinks |
Severity Levels
- Critical - Security-sensitive actions (URL changes, user deletion, password changes)
- Warning - Actions requiring attention (failed logins, plugin deactivation)
- Info - General activity (content changes, logins)
Log Viewer
View and filter logs with a powerful search interface:
- Search - Find by username, action, or object name
- Filter by Action - Show only specific event types
- Date Range - Filter by start and end dates
- Export CSV - Download logs for external analysis
- Pagination - 20 logs per page with navigation
Email Alerts
Get notified when critical events occur:
- Site URL or Home URL changed
- Admin email changed
- User deleted or role changed
- Plugin deleted
- Password changed
Privacy & Retention
- IP Logging - Optional, disabled by default for GDPR compliance
- Auto-Delete - Automatically delete logs after 7, 30, 60, or 90 days
- No Sensitive Data - Passwords, emails, and form content are never logged
Dashboard Widgets
Take control of the WordPress dashboard by managing widgets, hiding admin notices, and creating custom branded widgets.
Widget Visibility
Hide default WordPress dashboard widgets:
- Welcome Panel
- Quick Draft
- Activity
- WordPress Events and News
- Site Health Status
Auto-Hide Third-Party Widgets
Enable this feature to automatically hide all widgets added by plugins and themes. Use the whitelist to allow specific widgets.
When auto-hide is enabled, your dashboard stays clean even when new plugins are installed. Only whitelisted widgets will appear.
Admin Notices
Control the notices that appear at the top of admin pages:
- Hide All Notices - Remove all plugin and theme notices
- Super Admin Exception - Let Super Admins see all notices
- Dashboard Only - Show notices only on the main dashboard
- Log Hidden Notices - Track what notices were hidden
Custom Widgets
Create branded dashboard widgets for your clients or team:
| Option | Description |
|---|---|
| Title | Widget heading displayed on the dashboard |
| Position | Left column (Normal) or Right column (Side) |
| Content | Rich text editor with media support |
| Enabled | Toggle widget visibility |
Use Cases:
- Welcome message with agency branding
- Quick links to important pages
- Support contact information
- Training resources and documentation
Settings
Configure access control, two-factor authentication, and other plugin-wide settings.
Access Control
Restrict who can access and modify the plugin settings:
- Allowed Users - Select which administrators can access the plugin
- Access Levels - Full Access or Read-only for each user
- Super Admin Protection - Super Admin (ID 1) can never be locked out
- URL Blocking - Restricted users can't access plugin pages via direct URL
Read-only users can view all settings but cannot make changes. A banner is displayed and all forms are disabled.
Two-Factor Authentication (2FA)
Add an extra layer of security with email-based 2FA:
Setup Process
- Click "Send Test Email" to verify email delivery works
- Enable Two-Factor Authentication
- Select which roles require 2FA
- Save your recovery keys
Features
- 6-Digit Codes - Sent via email on each login
- Code Expiry - 5, 10, or 15 minutes
- Role-Based - Require 2FA for specific roles
- Recovery Keys - One-time use backup codes
- Super Admin Bypass - Super Admin is exempt to prevent lockouts
Miscellaneous
- Custom Footer Text - Replace "Thank you for creating with WordPress"
- Hide WordPress Version - Remove version number from admin footer
- Live Preview - See footer changes in real-time
Hooks & Filters
For developers who want to extend or customize the plugin behavior.
Menu Manager Hooks
| Hook | Priority | Description |
|---|---|---|
admin_menu |
9999 | Capture and modify menu items |
admin_init |
1 | URL access blocking |
menu_order |
- | Custom menu ordering |
Admin Bar Hooks
| Hook | Priority | Description |
|---|---|---|
admin_bar_menu |
999999 | Capture admin bar nodes |
wp_before_admin_bar_render |
1000-1002 | Apply customizations |
Login Page Hooks
| Hook | Description |
|---|---|
login_enqueue_scripts |
Load custom styles and scripts |
login_head |
Output custom CSS |
login_form |
Add reCAPTCHA to login form |
wp_authenticate_user |
Verify reCAPTCHA on login |
Database
The plugin stores settings in WordPress options and creates one custom table for activity logs.
Options
| Option Name | Description |
|---|---|
pdt_settings |
Main plugin settings |
pdt_menu_items |
Menu item configurations |
pdt_admin_bar_settings |
Admin bar settings |
pdt_login_page_settings |
Login page settings |
pdt_activity_log_settings |
Activity log settings |
pdt_dashboard_widgets_settings |
Dashboard widgets settings |
pdt_custom_admin_menus |
Custom Admin Menu Builder records |
pdt_active_addons |
Active addon flags for addon-managed modules |
pdt_general_settings |
General/security settings |
Activity Log Table
Table name: {prefix}_pdt_admin_logs
CREATE TABLE {prefix}_pdt_admin_logs (
id bigint(20) unsigned NOT NULL AUTO_INCREMENT,
user_id bigint(20) unsigned NOT NULL,
user_login varchar(60) NOT NULL,
action varchar(100) NOT NULL,
object_type varchar(50) DEFAULT NULL,
object_id bigint(20) unsigned DEFAULT NULL,
object_name varchar(255) DEFAULT NULL,
ip_address varchar(45) DEFAULT NULL,
user_agent varchar(255) DEFAULT NULL,
meta longtext DEFAULT NULL,
created_at datetime NOT NULL DEFAULT CURRENT_TIMESTAMP,
PRIMARY KEY (id),
KEY user_id (user_id),
KEY action (action),
KEY created_at (created_at)
);
Security
The plugin follows WordPress security best practices:
- Nonce Verification - All forms use WordPress nonces to prevent CSRF attacks
- Capability Checks - Only users with
manage_optionscan access the plugin - Input Sanitization - All user inputs are sanitized before storage
- Prepared Statements - Database queries use
$wpdb->prepare() - Super Admin Protection - Super Admin cannot be locked out of the plugin
- Read-Only Mode - Server-side enforcement prevents unauthorized changes
- GDPR Compliance - No sensitive data is logged, IP logging is optional
This plugin was designed with security as a primary concern. All features include safeguards to prevent accidental lockouts and unauthorized access.
Changelog
Version 1.4.1 Latest
- Improved: Activity Log export flow (CSV/JSON) output handling on Settings page for more consistent downloads
- Improved: Settings export callback visibility and
admin_initlifecycle compatibility - Improved: Activity Log query hardening with validated table-name usage and allowlisted
ORDER BYhandling - Improved: 2FA verification comparison updated with timing-safe hash validation (
hash_equals) - Improved: Activity Log IP resolution now prefers
REMOTE_ADDRand supports trusted-proxy based forwarded-header parsing - Improved: Settings input validation for
allowed_userswith strict array-type guards before normalization
Version 1.4.0
- Major update: All premium features are now available for free
- New: Full Admin Suite experience (menu, login, security, dashboard, activity log)
- New: Custom Admin Menu Builder
- New: Role-based access control improvements
- Improved: UI/UX across all modules
- Improved: Performance and stability
- Improved: Security layers and validation
- Fixed: Minor bugs and edge cases