WordPress website audit

A WordPress website audit that never asks for your password.

Send the address and one line about what worries you. One of the two owners reads your site from the outside, then writes back with what is broken, what each fix costs, and whether you need us at all.

Free, and read only. We look at what your site already shows the public.

Start the audit

Three fields. That is the whole form.

No card. No contract. We do not need your password.

What we check

What we look at

All of it from outside your site, using what any visitor or search engine can already reach.

01

Versions and published holes

Which WordPress core, theme and plugin versions you are running, and whether any of them appear in the public vulnerability databases.

02

What the internet can already see

User names leaking through the REST API, folders left browsable, log files sitting where anyone can read them, an SSL certificate running out.

03

Speed on a real phone

How long the page takes on a mid-range handset over mobile data, and which requests are holding it up.

04

Search visibility

Whether Google can reach and index the pages you care about, and what your titles, canonical tags and sitemap are telling it.

05

Checkout, if you sell

Whether the WooCommerce checkout loads, which gateway it hands off to, and whether anything in that path looks fragile.

Compare

How this differs from a free scanner

Free online scanners are useful for a first look. They stop being useful the moment you have to decide what to do about what they found.

What you wantA free online scannerA typical agency auditDevsTeam
Who reads your siteNobodyA junior, sometimesOne of the two owners
Needs your loginNoUsuallyNo
Ranked by what it costs youNo, by tool scoreSometimesYes
A price beside each fixNoNoYes
Says when you do not need themNoNoYes
Report another developer can act onRarelySometimesYes
What it costsFreeUsually paidFree

Questions

Frequently asked questions

What is a WordPress website audit?

A written review of your site’s condition, covering software versions and known vulnerabilities, public exposure, speed, search visibility and, for shops, the checkout path. A person reads your site and writes the report, and every finding carries a fix and a price.

Do you need my login or admin access?

No. We read only what your site already shows the public, so there is nothing for you to set up and nothing of ours on your site.

How long does it take?

You get the write-up within two business days. We work Dhaka time, GMT plus six, so a site sent from the US or the UK is usually read overnight.

Is it really free? What is the catch?

It is free and there is no card. Some of the sites we read turn into work for us, and the ones that do pay for the ones that do not.

What can a free audit not detect?

Anything that needs access. Whether your backups restore, what is inside your database, whether core files have been altered, your PHP version if the server hides it, and quiet malware. Say so when you write if one of those is the thing that worries you, and we will quote the deeper version.

Do I have to use you for the fixes?

No. The report is yours, and it is written so another developer can act on it without ringing us first.

How often should you audit a WordPress site?

Twice a year for most business sites, and after any big change: a redesign, a host move, a new payment gateway. Sites on a care plan get this continuously, which is most of what a care plan is.

What happens if you find my site is already hacked?

You hear from us that same day, before the rest of the report is finished. If you want it dealt with, that is Emergency WordPress Support and Malware Removal, and we quote before touching anything.

Chat on WhatsApp