wpBara Audit
wpBara Audit checks your WordPress site in one click and shows what needs attention: security, updates, performance and configuration. You get a clear score, a list of issues ordered by importance, and a report you can save as PDF.
The plugin only looks and never changes your site. The report is never stored – it exists only in the browser tab that generated it.
What you get
- A score that sets priorities – an overall score from 0 to 100% across Security, Updates, Performance and Configuration, with every issue that lowered it, the most serious first
- Plugins and themes checked live against WordPress.org – removed from the directory (often for a security issue, with the date and reason), no release in over a year or two, not tested with recent WordPress versions, updates waiting, and where each one gets its updates from
- Missing security releases – whether WordPress is missing a security release of its own version line, and when PHP and the database server stop, or stopped, receiving support
- What your site exposes – security headers, log files and configuration files that can be downloaded from a browser, usernames given away by the REST API, XML-RPC, and folder listings
- Mixed content, with the addresses – what the home page loads over plain http://, whether the browser blocks it, and http:// resources stored in your posts
- Database health – tables on MyISAM or below utf8mb4, heavy autoloaded options, expired transients, trash, spam and posts keeping more revisions than the limit
- A report ready to share – print it or save it as PDF
Who it is for
Site owners who want to know where their site stands, and agencies and freelancers who look after client sites. Use it before taking over a site, as a regular check-up, or to show a client what needs fixing and why.
Everything the audit checks
Security
- WordPress core: missing security releases of the installed version line, checked live against WordPress.org
- Plugins and themes: removed from WordPress.org, unmaintained, and where their updates come from
- HTTP security headers (HSTS, X-Content-Type-Options, X-Frame-Options, CSP)
- Public access to sensitive files: wp-config.php, .htaccess, .user.ini and log files in the WordPress folder, wp-admin and wp-content
- REST API user enumeration, XML-RPC, and folder listings in uploads
- Developer leftovers that should not be on a live site: phpinfo.php, .env, SQL dumps, .git folders
- PHP errors shown to visitors, secret keys in wp-config.php, and a user named “admin”
- End-of-life dates for PHP and the database server
- Forms that send visitor data over plain http://
Updates
- WordPress core, plugins and themes with pending updates
- Time since each plugin’s and theme’s last release, and plugins not tested with the last three WordPress versions
- Where each plugin and theme gets its updates from: WordPress.org, its author’s server, or unknown
- Whether the server can reach WordPress.org for updates at all
Performance
- Autoloaded options, with the largest ones listed
- Expired transients, trash, spam, auto-drafts and orphaned metadata
- Posts keeping more revisions than the revision limit
- Database size, overhead and tables on MyISAM
- OPcache, object cache and PHP limits
Configuration
- Key WordPress constants with the value actually in effect
- WordPress tables below utf8mb4, where emoji and some characters are cut off when saved
- Mixed content on the home page and in published posts
- The PHP error log: whether it has content and whether errors were written in the last seven days – the entries themselves are never read
- Search engine visibility and robots.txt, read the way crawlers read it
- Scheduled cron jobs, inactive plugins and unused themes
The report also lists system details, must-use plugins, file permissions, post types, taxonomies, permalinks and content statistics.
Safe and read-only
- Only administrators (the
manage_optionscapability) can run an audit - Every request is protected with a nonce, and every database query is a read-only SELECT
- The report is never stored on the server
- No personal data in the report: no logins, email addresses or registration dates
- No server paths, database name, database host or table prefix in the report
- No database tables, cron jobs or REST API endpoints of its own
- The only thing it writes is a one-hour cache of public WordPress.org answers, removed when the plugin is deleted
Third-party libraries
None. The plugin ships only its own code.
External services
The plugin connects to external services only while an audit is running, never in the background. No site content, credentials or personal data is sent.
Your own site. The audit requests pages and files from your own domain to read security headers, check which files are publicly reachable, test the REST API and XML-RPC, read robots.txt and check the home page for mixed content. These requests stay on your server and are limited to 20 seconds in total.
WordPress.org (api.wordpress.org). Used to check plugins, themes and WordPress core for updates, release dates and removal from the directory.
- The plugin and theme information APIs receive the folder name (slug) of each installed plugin and theme – including ones not from WordPress.org, since a removed plugin can only be recognised by asking. Plugins and themes whose Update URI points to another server are skipped. These requests carry no site address.
- The core version-check API is read without any parameters.
- A connectivity check calls the update endpoints with the same user agent WordPress core uses, which includes your WordPress version and site address.
- Answers are cached for one hour.
WordPress.org privacy policy: https://wordpress.org/about/privacy/
Support end dates for PHP and MySQL/MariaDB ship with the plugin and are not looked up online.
About wpBara
wpBara Audit is made by wpBara – taking care of your site. We look after WordPress sites every day: updates, security, backups and performance. If you would rather have someone handle what the report finds, we can help: https://wpbara.com/
