Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

WordPress’s functions.php can add theme features and small customizations, but it is not a safe dumping ground for every snippet you find. Theme-specific behavior usually belongs in a child theme; functionality that should survive a theme change belongs in a plugin. Make a backup, test one change at a time, and keep a way to undo each edit.

The 46 ideas below are grouped by purpose. Some are straightforward presentation changes; others can affect security, email, search, uploads, or integrations. For risky changes, the safer choice is often not to add a snippet at all.

Choose the right place for the code

WordPress loads the functions.php file of the active theme. It can register theme features and connect custom functions to WordPress actions and filters, but it is tied to that theme. WordPress describes it as similar to a plugin in some ways, while recommending a plugin for functionality that should remain when the design changes. See the Theme Functions handbook and Custom Functionality handbook.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Code or change Best home
Theme supports, menus, sidebars, theme assets Child theme functions.php
SEO, redirects, forms, email, user workflows, or behavior that should persist across themes Small custom plugin
Short-lived experiments or individually switchable snippets Snippet manager, with code review and backup
Site-wide functionality that must load on a WordPress multisite network Network-activated plugin or carefully designed mu-plugin
CSS-only presentation change Site Editor, theme CSS, or child-theme stylesheet
Disable dashboard file editing wp-config.php

A child theme prevents parent-theme updates from overwriting your custom file, but it does not replace the parent’s functions.php: both files load. Put only your additions in the child file; copying parent functions into it can cause a fatal duplicate-function error. See WordPress’s child-theme guide. Block themes also have functions.php, but many design changes are better handled with theme.json, templates, patterns, or the Site Editor. Consult the Theme Handbook for the theme type you use.

Before adding any snippet

  1. Back up the site or test on staging, and note its WordPress and PHP versions.
  2. Put permanent theme-specific code in a child theme or use a plugin for behavior that should outlive the theme.
  3. Add one change at a time. Prefix your function names, handles, constants, and options—for example, acme_excerpt_length—to reduce naming collisions.
  4. Check PHP syntax before deployment, then test the relevant front-end and admin screens, logged-in and logged-out states, and mobile layout.
  5. Keep a known-good copy and record how to remove the change. If editing a file directly, use SFTP or your host’s file manager rather than relying on the built-in theme editor.

Use WordPress hooks rather than editing core files. An action runs your code at a particular point; a filter changes a value passed through WordPress. For input that can be changed by a user, check capabilities and nonces where appropriate, sanitize and validate input, and escape output. WordPress explains these practices in its plugin common-issues guidance.

Most examples below are intended as starting points, not universal drop-in solutions: theme markup, plugins, multisite settings, and integrations can change the result. For a child theme, add code without a second <?php if the file already begins with one. Avoid a closing ?> tag in PHP-only files; trailing whitespace can create output problems.

Theme setup and presentation

1. Enqueue a stylesheet and script

Use WordPress enqueue functions instead of hard-coding asset tags into a template. Put this in a theme file when the assets belong to that theme; for a child theme, use child-theme asset paths intentionally.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
add_action( 'wp_enqueue_scripts', 'acme_enqueue_assets' );
function acme_enqueue_assets() {
    wp_enqueue_style( 'acme-theme', get_theme_file_uri( 'assets/css/theme.css' ), array(), '1.0.0' );
    wp_enqueue_script( 'acme-theme', get_theme_file_uri( 'assets/js/theme.js' ), array(), '1.0.0', true );
}

Update the paths and version when the files change. WordPress documents asset enqueuing and theme path helpers.

2. Load a helper file

Split a growing theme file into smaller files. This loads a helper from the active theme or child theme, if present:

require_once get_theme_file_path( 'inc/helpers.php' );

Use get_parent_theme_file_path() only when you specifically want the parent theme’s file. A missing required file can cause a fatal error, so verify the path before deploying.

3. Remove the generator version output

This reduces one visible version disclosure in generated markup; it is not a security fix and does not replace timely updates, access controls, backups, or monitoring.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
remove_action( 'wp_head', 'wp_generator' );

4. Add a navigation-menu location

For a classic theme that has a template location ready to display it, register a menu location during theme setup:

add_action( 'after_setup_theme', 'acme_register_menus' );
function acme_register_menus() {
    register_nav_menus( array(
        'footer' => __( 'Footer Menu', 'acme-theme' ),
    ) );
}

The theme must also render that location, and a block theme may manage navigation in the Site Editor instead.

5. Register a widget-ready sidebar

This is for themes using the classic widget system; it will not create a block-theme area by itself.

add_action( 'widgets_init', 'acme_register_sidebar' );
function acme_register_sidebar() {
    register_sidebar( array(
        'name'          => __( 'Footer', 'acme-theme' ),
        'id'            => 'acme-footer',
        'before_widget' => '<section class="widget">',
        'after_widget'  => '</section>',
        'before_title'  => '<h2 class="widget-title">',
        'after_title'   => '</h2>',
    ) );
}

6. Change the excerpt length

This filter affects excerpts wherever the theme or a plugin uses the excerpt-length filter; test archive layouts for truncation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
add_filter( 'excerpt_length', 'acme_excerpt_length' );
function acme_excerpt_length( $length ) {
    return 30;
}

7. Change the “Read more” text

On classic themes that use the excerpt-more filter, this changes the trailing text. It does not disable feeds.

add_filter( 'excerpt_more', 'acme_excerpt_more' );
function acme_excerpt_more( $more ) {
    return '&hellip;';
}

8. Add odd/even post classes

Prefer the existing post-class system and add a class through its filter rather than relying on a global counter that can become inconsistent across queries. This example is for the main loop only and requires testing if a theme uses custom loops.

add_filter( 'post_class', 'acme_add_post_class' );
function acme_add_post_class( $classes ) {
    if ( is_main_query() && in_the_loop() ) {
        $classes[] = ( get_the_ID() % 2 ) ? 'acme-odd' : 'acme-even';
    }
    return $classes;
}

9. Link featured images to their posts

There is no universal filter that safely wraps every theme’s featured image. Update the relevant template to place the image output inside a post permalink, and ensure the link has an accessible name or accompanying title. Avoid editing parent-theme templates directly.

10. Add a dynamic copyright year

Place this in a template or shortcode-producing plugin, then escape the output in the appropriate context. Avoid adding raw PHP to a block’s content.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
echo esc_html( gmdate( 'Y' ) );

Use the site’s chosen timezone instead of UTC if the displayed year must follow local time.

Admin presentation and dashboard

11. Change the admin footer text

This is cosmetic and applies in the dashboard. Keep the copy concise and do not imply WordPress support or endorsement.

add_filter( 'admin_footer_text', 'acme_admin_footer' );
function acme_admin_footer( $text ) {
    return esc_html__( 'Managed by the site team.', 'acme-theme' );
}

12. Add a dashboard widget

Use a capability check inside the callback if the widget contains restricted information.

add_action( 'wp_dashboard_setup', 'acme_add_dashboard_widget' );
function acme_add_dashboard_widget() {
    wp_add_dashboard_widget( 'acme_notes', __( 'Site Notes', 'acme-theme' ), 'acme_render_dashboard_widget' );
}
function acme_render_dashboard_widget() {
    if ( current_user_can( 'manage_options' ) ) {
        echo '<p>' . esc_html__( 'Add your site-specific reminder here.', 'acme-theme' ) . '</p>';
    }
}

13. Remove the welcome panel

For a user-by-user removal, use the dashboard screen’s built-in panel controls where available. If applying a filter in a plugin, test against your WordPress version and user roles; hiding onboarding content can make the dashboard less useful to new editors.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

14. Change the admin-bar logo or branding

Admin branding is presentation only. Prefer a supported branding plugin or enqueue admin CSS from a plugin; avoid fragile selectors and tiny theme-relative images. Selector changes can break the customization, and branding must not obscure WordPress controls.

15. Change the dashboard background

Use an admin stylesheet enqueued by a plugin or child theme, scoped to the intended dashboard screen. Do not add global CSS that reduces contrast or hides controls.

16. Change the “Howdy” greeting

Changing a greeting is cosmetic and can depend on the current admin-bar markup. Use a maintained admin customization approach rather than replacing broad translation strings, which can affect unrelated screens.

17. Add a featured-image column to the Posts screen

This requires registering a custom admin column and rendering a thumbnail with capability-aware checks. It is better suited to a small plugin than a theme file because it changes editorial workflow, not site appearance. Test with custom post types and users who cannot edit all posts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

18. Restore classic widgets

Only do this if a required plugin or editorial workflow depends on the classic widgets screen. The classic-widget experience is legacy compatibility, not a general performance or security improvement. Prefer updating the dependent workflow where possible.

Content, feeds, and search

19. Add text to RSS entries

Feed output is consumed by external readers, so keep additions plain and avoid inserting untrusted HTML. Test both full-content and excerpt feeds and check for duplicate content.

20. Add featured images to RSS entries

Feed markup and support vary among feed readers. If adding an image, generate the markup using WordPress attachment APIs and escape URLs and attributes. Test the feed itself rather than assuming every reader displays the image.

21. Delay posts in RSS feeds

A delay can affect syndication and downstream integrations. If there is a legal or editorial embargo, use a publishing workflow that enforces it consistently rather than a feed-only delay that leaves the post public on the website.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

22. Exclude categories from RSS feeds

Filtering feed queries can omit content from subscribers and syndication partners. Confirm the intended category IDs and test category archives, feeds, and any external automation that consumes the feed.

23. Disable RSS feeds

Do not use an excerpt filter to disable feeds: it only changes excerpt text. If feeds genuinely need to be unavailable, implement that behavior in a plugin and return an intentional response for feed requests. First check whether subscribers, podcasting, syndication, or integrations rely on them; otherwise consider leaving feeds enabled.

24. Disable or replace site search

Blanket-disabling search can harm navigation and accessibility. Improve relevance, exclude selected content, or replace the search experience instead. For complex content sites, SearchWP is one commercial option; it is not necessary for every site.

25. Disable automatic linking of comment URLs

Consider spam and usability before changing comment output. If making this change, use a narrowly targeted filter and test with the active comment and anti-spam plugins; do not strip links from content indiscriminately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

26. Display a last-modified date

Show the modified date only when it helps readers and reflects meaningful editorial changes. A date alone is not proof that the article was substantively reviewed. Render the date in the theme template with the site’s timezone and an accessible time element.

27. Add an author-information box

Use the author profile APIs and escape profile fields when rendering. Show only information authors have chosen to publish, and check that the theme does not already include an author box.

28. Add author profile fields

Additional profile fields can expose personal data and need clear purpose, access controls, sanitization, and output escaping. Use a user-profile plugin or custom plugin when fields affect multiple themes or workflows.

29. Count registered users

Public user counts can disclose information and may be misleading on multisite or sites with spam and inactive accounts. If the count is for internal reporting, keep it in an admin-only view and define which users qualify instead of publishing a raw total.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Users, login, and permissions

30. Hide detailed login errors

Generic errors can reduce username disclosure, but they do not prevent password guessing. Pair any change with strong authentication, rate limiting, monitoring, and recovery procedures; ensure legitimate users still receive a useful sign-in experience.

31. Disable login by email

This can confuse users and break plugins or authentication integrations. WordPress supports email-based login by default; disable it only when policy requires usernames and after testing account recovery, membership, commerce, and identity-provider flows.

32. Remove the login-language selector

Do this only if the site’s users all share the same expected login language. Multilingual sites or international teams may rely on the selector.

33. Restrict dashboard access for selected users

Use capabilities, not role-name strings, because custom roles and multisite change role assignments. Even a capability-based redirect can break WooCommerce, membership, profile, AJAX, REST, or admin-post flows. Exempt required workflows and test with every affected role before deploying.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

34. Create a temporary recovery administrator

This is an emergency procedure, not a standing customization. Prefer hosting recovery tools or WP-CLI with an authenticated operator. If a temporary account must be created through code, use a unique strong password and controlled email, remove the code immediately, delete the temporary account when finished, and review logs. Never leave an admin-creation snippet active.

35. Disable selected new-user notification emails

Suppressing account notices can hide abuse or expected onboarding messages. Identify the exact recipient and workflow, then route or customize messages rather than disabling all notifications by default.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Media and uploads

36. Allow an additional upload file type

Adding an extension to an allowed list does not make the file safe. SVG can contain active markup; accept it only through a trusted, sanitizing workflow and restrict who can upload it. Validate both file type and content, and test server-side handling. Do not enable PSD uploads unless there is a defined operational need.

37. Normalize uploaded filenames to lowercase

Changing upload names can create collisions on case-insensitive storage and disrupt references. If normalization is required, preserve uniqueness, handle existing files, and test plugins that use attachment filenames. A media-management workflow is safer than an unreviewed global rename filter.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Editor and maintenance controls

38. Disable the block editor for selected content

Use a targeted compatibility rule only when a post type or plugin truly needs the classic editor. Test editing, revisions, meta boxes, REST-dependent plugins, and all user roles; do not disable the block editor site-wide merely to avoid learning its controls.

39. Restrict access to the block editor’s Code Editor

Code access should be governed by capabilities and the site’s editorial policy. Prefer role/capability configuration or a maintained editorial plugin over UI-only hiding, which may not be a security boundary.

40. Disable the plugin and theme file editor

This is sensible hardening on production sites, but define the constant in wp-config.php before WordPress loads:

define( 'DISALLOW_FILE_EDIT', true );

Keep a separate deployment and recovery route, since disabling the dashboard editor means it cannot be used to repair a PHP mistake.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

41. Disable automatic-update notification emails

Do not silence maintenance alerts unless another monitoring system reports failed and successful updates. Route or consolidate notifications instead; otherwise security and compatibility problems may go unnoticed.

42. Change the outgoing sender name or address

Changing visible mail headers does not authenticate a sender or guarantee delivery. Use an authenticated mail provider and configure domain authentication where required. WP Mail SMTP is one plugin-based option; changing headers alone is not a deliverability solution.

43. Remove WordPress update notices from email

Do not disable update alerts as a substitute for maintenance. If you already monitor updates centrally, tailor notifications narrowly and verify that the monitoring covers core, plugin, and theme updates.

Integration-sensitive changes

44. Disable XML-RPC only when you have confirmed it is unused

XML-RPC may be required by mobile apps, Jetpack, remote publishing, or third-party integrations. If the problem is abuse, consider narrower controls such as rate limiting or blocking only unwanted methods, then verify every integration. A blanket shutdown can silently break legitimate workflows.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

45. Repair the WordPress home and site URLs

Do not put repeated update_option() calls in functions.php: they can run on every request until the code is removed. Correct URL values through the dashboard, WP-CLI, hosting tools, or the documented configuration route, then remove any temporary repair code. Wrong URL settings can cause redirect loops, so keep a recovery path before changing them.

46. Use a safer pattern for persistent customizations

When a change needs settings, permissions, data cleanup, compatibility handling, or reuse across themes, build a small plugin rather than extending a theme file indefinitely. A snippets manager such as WPCode or its snippet library can make individual snippets easier to manage, but it cannot make unsafe code safe or replace testing, version control, and backups.

Recover if a snippet breaks the site

  • If the snippets manager has a safe mode or per-snippet disable control, use it first.
  • If the dashboard is unavailable, connect through your hosting file manager or SFTP and remove or rename the last-added code or plugin.
  • If a plugin snippet caused the failure, temporarily rename that plugin’s directory; if the active theme file caused it, switch temporarily to a default theme using an available hosting recovery method.
  • Check PHP error logs, remove the faulty change, and restore the last known-good backup if necessary.
  • After access returns, test the repaired site and remove any temporary recovery account or code.

Common clues include a white screen or fatal error after saving a snippet, a duplicate-function error after adding code to a child theme, and no visible change when the hook or template does not apply to the current theme. For a block theme, confirm that the feature is controlled by PHP rather than the Site Editor. If CSS or JavaScript appears unchanged, check the asset path and cache before changing the code again.

Final location check

Need Choose
Menu, sidebar, theme support, or theme asset Child theme or theme-specific plugin
Site behavior that should survive a theme change Custom plugin
One-off experiment with individual activation Snippet manager, with backup and review
Network-wide behavior Network-aware plugin or mu-plugin, tested on multisite
File editor restriction wp-config.php
Complex search, mail, commerce, or membership workflows A maintained plugin or purpose-built integration

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.