Description
Asset CleanUp Pro controls which CSS and JavaScript files and plugins load on each page of the site, disabling specific items or blocking entire plugins on the front end and in the admin dashboard, with rules for pages, taxonomies, archives, searches, authors, dates, and 404 pages. It is designed for anyone who manages sites with many active plugins that are only used on specific screens, and includes Critical CSS, loading controls, a test mode, and an overview screen for reviewing and removing applied rules.
Key Features of Asset CleanUp Pro
- CSS/JS Manager
Disables stylesheet and script files on individual pages or by page type. - Plugin Manager
Prevents entire plugins from loading where they are not needed, on the front end and in the dashboard. - Rules by content type
Applies separate optimizations for pages, taxonomies, archives, searches, authors, dates, and 404 pages. - Critical CSS and loading attributes
Configures critical CSS and resource loading parameters for each page. - Test Mode and Overview
Tests changes before exposing them to visitors and reviews or removes existing rules.
Benefits of Asset CleanUp Pro
- Reduced page weight
Each page loads only the files and plugins it actually uses. - Risk-free adjustments
Test Mode prevents breaking the site for visitors during configuration. - Centralized rules
The Overview screen displays optimizations applied to any page and lets you remove them. - Portable configuration
Importing and exporting rules makes it faster to replicate the same optimization on other sites.
Who Is Asset CleanUp Pro For?
- Anyone who maintains sites with dozens of active plugins that are only used on specific screens or sections.
- Anyone who needs to reduce CSS and JavaScript loading without modifying code or the theme.
- Anyone who manages multiple client sites and wants to apply and review the same optimization rules on each one.
How to Download Asset CleanUp Pro
Asset CleanUp Pro is available for download here on Ultrapack. After downloading the .zip file, install it under Plugins > Add New > Upload Plugin, select the file, and activate it; the plugin then appears in the admin dashboard menu, ready for you to configure the optimization rules.
Asset CleanUp Pro brings per-page control of CSS, JavaScript, and plugins together in a single dashboard, something that normally requires editing functions.php or installing several standalone plugins. This reduces repetitive work for anyone who needs to keep multiple sites optimized without relying on a developer for every adjustment.
Frequently asked questions
Is Asset CleanUp Pro – Performance WordPress Plugin GPL-licensed?
Yes. Asset CleanUp Pro – Performance WordPress Plugin is distributed under the GPL (GNU General Public License). You may legally use, modify and redistribute it on as many sites as you want.
Can I use Asset CleanUp Pro – Performance WordPress Plugin on multiple sites?
Yes. You can install Asset CleanUp Pro – Performance WordPress Plugin on as many sites as you want. Only automatic updates through Ultrapack Auto Updater have a limit: from 3 to 80 sites, depending on the plan.
How much does Asset CleanUp Pro – Performance WordPress Plugin cost at Ultrapack?
Asset CleanUp Pro – Performance WordPress Plugin costs US$2.99 as a single purchase, and it is also included in the subscription plans starting at US$12/mo (VIP I).
Does Asset CleanUp Pro – Performance WordPress Plugin include updates?
Yes. The current version of Asset CleanUp Pro – Performance WordPress Plugin is 1.2.8.2, published at Ultrapack on Sep 29, 2026. Subscribers update straight from the WordPress dashboard with UAU (Ultrapack Auto Updater).
Is Asset CleanUp Pro – Performance WordPress Plugin scanned before publication?
Yes. Every version of Asset CleanUp Pro – Performance WordPress Plugin goes through a malware scan (ClamAV and YARA rules, at UltraHub) before it is published.
What are the requirements for the plugin Asset CleanUp Pro – Performance WordPress Plugin?
Requires WordPress 4.7 or higher and PHP 5.6 or higher. Tested up to WordPress 7.1.
What changed in this version
Version 1.2.8.2 28 September 2026
- Added: Roll back Asset CleanUp Pro to an eligible previous version from "Tools" (plugin's menu) - "Rollback", with version selection and confirmation before installation. Existing settings are preserved.
- Security — Admin Bar: Fixed a reflected cross-site scripting (XSS) vulnerability in the admin bar by validating asset unload parameters and escaping dynamic output (CVE-2026-92236). Reported by 'Huseyn (mekhatai) Gadashov' via Wordfence.
- Security — Comment Content XSS: Completed the fix for the stored cross-site scripting via comment content (follow-up to CVE-2026-13354). The final cleanup of the plugin's temporary `data-wpacu-*` attributes on ` ` tags — previously two whole-document replacements — is now scoped to each ` ` tag and uses bounded, quote-aware patterns. Reported by 'crow' via Wordfence.
- Security — Front-end HTML Cleanup: Removed the last remaining whole-document replacement from the HTML cleanup step (it stripped `data-wpacu-style-handle` from ` ` tags); that cleanup now runs through the same tag-scoped methods. Found during the internal review that followed the report above. Every temporary-attribute cleanup is now confined to the tag it belongs to and cannot touch any other part of the page, including user-submitted content.
- = 1.2.8.1 = 15 September 2026 =
- New: Admin Bar transfer savings estimates for unloaded CSS/JS files and removed inline code, with AJAX-based measurements and Brotli/GZIP indicators.
- Improvement: Separate effective asset unloads from rules that had no effect on the current page, with inactive rules grouped by asset type.
- Improvement: The "CSS/JS Manager" and Admin Bar now explain when "Page Options" disable optimizations, including CSS/JS unload rules. Admin Bar warnings identify disabled features, while clearer descriptions, dimmed overridden options, and quick links make these settings easier to understand.
- Improvement — Debugging "/?wpacu_debug": Added temporary "Page Options" overrides without changing saved settings. Debugging controls now update their availability and distinguish global restrictions, Page Options overrides, and missing rules.
- Improvement — Debugging "/?wpacu_debug": Added per-file CSS/JS optimization details explaining content changes, unchanged results, exclusions, failures, and cache decisions. Multiple optimization reasons can be shown for the same file.
- Improvement — Overview: Added navigation entries for "Page Options" and "Special Settings", clarified page overrides, and dimmed redundant options.
- Fixed — Interface: Corrected "Overview" horizontal overflow and alignment
- Fixed — CSS Optimization: When an optimized stylesheet has a matching ` ` fallback, the fallback now uses the same optimized cache URL instead of retaining the original unminified URL.
- Fixed — CSS/JS Manager: Selecting “Remove bulk rule” or "Remove site-wide rule" now correctly removes the unload rules when saving changes.
- Fixed — Page Options: Fixed an issue where CSS/JS processing could still run on pages with "Disable all front-end optimizations" enabled. The plugin now checks the current page’s options before retaining the decision to allow optimizations, preventing unnecessary processing on excluded pages.
Version 1.2.8.0 9 September 2026
- Improvement: Reduced Google Fonts browser discovery traffic by running the collector for approximately 2% of public browsers while preserving duplicate protection for known configurations.
- Improvement: Made the Google Fonts discovery REST endpoint compatible with sites where WordPress pretty permalinks or REST rewrite rules are unavailable.
- Fixed: Browser discovery is now disabled by default, preventing discovery REST traffic on new or previously unsaved configurations until the feature is enabled.
Version 1.2.7.9 6 September 2026
- Added — Google Fonts: Added local hosting for Google Fonts, allowing detected stylesheets and font files to be downloaded, validated and served from the local cache.
- Added — Google Fonts: Added granular font removal, allowing specific Google Font families, weights and styles to be removed while keeping the remaining fonts unchanged.
Version 1.2.7.8 26 August 2026
- Improved — Live Debugging: Redesigned the frontend Live Debugging interface (`/?wpacu_debug`) with theme-independent styling, clearer temporary controls, searchable plugin selection, expandable request and performance details, unavailable-option indicators, and a responsive floating action bar.
- Improved — Data Compatibility: Hardened handling of legacy or unexpectedly formatted stored plugin data, preventing warnings or failures when settings and rules are already stored as arrays instead of JSON strings.
- Improved — Import/Export: Added stricter structural validation before importing settings and rules, preventing malformed configuration data from being partially imported.
- Improved — Plugin Icons: Improved WordPress.org plugin icon fetching and cache recovery so missing icons can be downloaded again instead of remaining permanently replaced by the default icon.
- Improved — Access Control: Access-control settings are now hidden from delegated plugin managers who are not permitted to manage plugin access.
- Fixed — Plugins Manager: Prevented taxonomy and archive requests, including WooCommerce product categories, from being misidentified as singular pages in Plugins Manager rules.
- Fixed — Overview: Prevented warnings and invalid links when saved rules reference deleted or unavailable taxonomies or taxonomy terms, while keeping the affected rules visible for review.
- Fixed — JavaScript Optimization: Prevented warnings when optional JavaScript optimization settings are unavailable or disabled.
- Security — Debugging Overrides: Hardened temporary query-string settings overrides with administrator authorization and nonce validation, and prevented request-scoped troubleshooting values from being accidentally persisted to the database.
- Compatibility — PHP 8.5: Avoided the deprecated `curl_close` call on modern PHP versions.
- Maintenance: Removed legacy CSS and obsolete browser-specific declarations and performed related internal cleanup.
Version 1.2.7.7 21 August 2026
- Added — Font Preload Audit: Added a browser-assisted audit for manually preloaded Local and Google Fonts. The audit checks representative pages in desktop and mobile viewports, identifies duplicate, invalid or unnecessary site-wide preloads and provides conservative cleanup recommendations without removing the fonts themselves.
- Added — Critical CSS: Added a global control directly in the Critical CSS Manager to temporarily pause or resume all Critical CSS output while preserving the existing rules.
- Added — Tools / Storage: Added a read-only Database Map showing where Asset CleanUp stores settings, optimization rules, metadata, transients and Pro-specific data.
- Improved — JavaScript Optimization: Improved handling of modern JavaScript, including module/nomodule scripts and scripts using integrity, nonce, crossorigin or referrerpolicy attributes, preventing unsafe combine, inline or Match Media transformations.
- Improved — Resource Loading: Hardened image attribute and lazy-loading rule validation, improved compatibility with rules saved by older versions and fixed edge cases where attributes such as `src` could be confused with `data-src`.
- Improved — CSS/JS Manager Settings: Redesigned the manager preferences area with clearer navigation and explanations, better-organized controls for management locations, access, list appearance and optimized-file cache settings.
- Improved — Settings and CSS/JS Manager: Added unsaved-change counters and persistent save areas, making modified settings and asset rules easier to review before saving.
- Improved — Dashboard Reliability: Improved AJAX validation, authorization and failure recovery across several Dashboard actions, including safer handling of invalid, expired or interrupted requests.
- Improved — Tools / Storage: Added a detailed overview of generated CSS/JavaScript storage, including directory paths, file counts, disk usage, write status and filtering between optimized assets and supporting files.
- Improved — Tools / Debugging: Redesigned the troubleshooting area with clearer diagnostic modes, copyable test URLs and protected PHP error-log downloads.
- Improved — Tools / Reset: Added more granular reset options for Critical CSS and front-end or Dashboard Plugins Manager rules, with clearer confirmation, deletion summaries and partial-failure reporting.
- Improved — Tools / Uninstall: Cleanup results are shown on the Plugins page and partial filesystem failures are reported instead of returning a false success. Plugin settings are not recreated after cleanup.
- Improved — Multisite Uninstall: Network-shared user access data and the Pro MU-plugin loader are preserved while Asset CleanUp Pro remains active on another site in the network.
- Fixed — Plugin Rules: Fixed request-context detection on sites using plain permalinks, preventing homepage, search, author, date and taxonomy requests from being incorrectly treated as the same context.
- Fixed — Multisite Plugins Manager: Improved detection and handling of network-active plugins across Plugins Manager rules and WPACU internal requests.
- Fixed — Dashboard CSS/JS Manager: No longer reports a false external redirect or fails to fetch assets when WordPress runs on a non-standard port (e.g. localhost:8888)
- Fixed — Usage Data Settings: Fixed an undefined variable warning in the usage-data disclosure panel.
- Fixed — CSS and JavaScript: Combining now works when minification is disabled.
- Fixed — Upgrade Compatibility: Recently introduced access-control settings now receive their correct disabled or empty-list defaults when upgrading from older versions, preventing blank fields or unexpectedly enabled checkboxes.
- Privacy — Dashboard Announcements: Remote announcements are now disabled by default and require an explicit administrator opt-in.
- Security — Remote Asset Handling: Further hardened remote asset retrieval and redirect validation, including safer handling of dynamically loaded resources and restricted redirect behavior.
- Security — Plugin Updater: Replaced remote PHP deserialization with native JSON collection validation.
Release notes published by the developer.
How to install
Automatic updates: this item is updated by the Ultrapack Auto Updater. With it installed, the new version shows up in your dashboard like any other WordPress update (how to set it up).
- Download the file
wp-asset-clean-up-pro.zip. - In the WordPress dashboard, go to Plugins > Add New > Upload Plugin.
- Select the file
wp-asset-clean-up-pro.zipand click Install Now. - Click Activate.
Requirements: Requires WordPress 4.7 or higher and PHP 5.6 or higher. Tested up to WordPress 7.1.
Stuck on a step? Open a ticket telling us which one you stopped at.

UAU Ready