Ultra Web Hosting Performance Toolkit
by ultrawebhosting 0 (0 reviews)

Ultra Web Hosting Performance Toolkit

Optimize, secure, and speed up WordPress: trim front-end bloat, clean the database, block attacks and spam, and purge every cache in one click.

Ultra Web Hosting Performance Toolkit ranks #10,156 among WordPress.org plugins with 300+ active installations, is #271 of 1,518 in the Performance category, and was last updated Aug 14, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1
v5.3.2 Current Version v5.3.2
Updated 1 month ago Last Update on 14 Aug, 2026
Refreshed 12 hours ago Last Refreshed on
#271 of 1,518 in Performance Top 25% by installs
View on WordPress.org
Rank
#10,156
+16 this week
Active Installs
300+
-8.5%
KW Avg Position
N/A
No change
Downloads
1.8K
+5 today
Support Resolved
0%
No change
Rating
0%
Review 0 out of 5
0 (0 reviews)

Next Milestone 400

Total Progress 84%
300+ 400+
205
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 16 more installs to reach 400+

Rank Changes

10,146 10,168 10,190 10,212 10,234 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
10,037 10,295 10,553 10,810 11,068 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Current #10,156
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 20 30 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
0 10 20 30 31-08-2026 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

0.0
0 reviews
Overall 0%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Security History

Source: WPVulnerability

No known vulnerabilities on record for Ultra Web Hosting Performance Toolkit. Checked 1 month ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners and administrators who want to speed up, secure, and clean up their sites without juggling multiple plugins. It removes unused front-end scripts, blocks common attack and spam vectors, cleans database bloat, and clears every layer of caching from one button.

  • Removes unused front-end scripts
  • Twenty-one front-end optimizations
  • Brute-force login protection
  • Comment spam protection (honeypot, speed trap)
  • Disables XML-RPC and registration page
  • One-click cache purge (multiple plugins)
  • Database cleanup with live reporting
  • Site Health integration

Frequently Asked Questions

Common questions about Ultra Web Hosting Performance Toolkit

No. The cache-purge button calls each caching plugin's own flush routine, so it works alongside LiteSpeed Cache, WP Rocket, W3 Total Cache, and the others rather than replacing them.
No. If a dedicated security plugin (Wordfence, Solid Security, Sucuri, All-In-One WP Security, WP Cerber, Limit Login Attempts, LoginPress, Jetpack Protect, or Imunify Security) is active, The plugin defers login protection to it and shows a notice saying so.
Only if you tell it so. Under Visitor IP detection choose Cloudflare, and the forwarding header will be honoured for requests that genuinely arrive from a published Cloudflare range. The setting exists because that header can be forged by anyone when no proxy is present, which would let an attacker sidestep a lockout or lock out somebody else.
Open https://dash.cloudflare.com/profile/api-tokens while signed in to Cloudflare. Select Create Token, scroll to the bottom, and choose Create Custom Token. Give it a name you will recognise later. Under Permissions choose Zone, then Cache Purge, then Purge. That one permission is all this needs. Under Zone Resources choose Include, then Specific zone, then pick your domain from the list. That list shows domain names rather than IDs; the Zone ID is collected separately in step 7. Continue to summary, then Create Token, and copy the value straight away. Cloudflare only displays it once, but a lost token does not have to be recreated: open it later and choose Roll, which issues a fresh value while keeping the same name, permissions and zone. Back in the Cloudflare dashboard, select your domain and stay on the Overview page. In the right-hand column under the API heading is the Zone ID, a 32 character string, with a copy button. Both values are needed. A token limited to Cache Purge has no permission to list your zones, so the plugin cannot work out which zone your site belongs to on its own.
From another admin account, open Settings > Ultra Performance and click Unlock next to your IP in the lockout log. Otherwise the lockout clears on its own after fifteen minutes. You can also clear it with WP-CLI by deleting the ultraperf_lock_* and ultraperf_att_* transients for your IP.
It can. XML-RPC is required by the legacy WordPress mobile app and some Jetpack features. If you rely on those, turn off the Disable XML-RPC toggle. A comment from a real visitor was held for moderation. That is the link limiter working as designed: comments with more than two links are queued rather than rejected, so a genuine comment is never lost. Approve it from the Comments screen, or raise the limit with the ultra_spam_max_links filter. My CSS or JavaScript looks out of date after an update. If you turned on Remove Query Strings, some caching layers may be serving old files because the version string they used for cache-busting is gone. Clear all caches, and if it persists turn that toggle back off. This is why it ships off by default.
Yes. Deleting the plugin removes its settings, lockout log, and all of its transients, across every site on a multisite network. Deactivating leaves them in place so you can reactivate without reconfiguring.

Sign In / Register

You need to sign in or register to use this feature.