WordPress website audit
A WordPress website audit that never asks for your password.
Send the address and one line about what worries you. One of the two owners reads your site from the outside, then writes back with what is broken, what each fix costs, and whether you need us at all.
Free, and read only. We look at what your site already shows the public.
Start the audit
Three fields. That is the whole form.
No card. No contract. We do not need your password.
What we check
What we look at
All of it from outside your site, using what any visitor or search engine can already reach.
01
Versions and published holes
Which WordPress core, theme and plugin versions you are running, and whether any of them appear in the public vulnerability databases.
02
What the internet can already see
User names leaking through the REST API, folders left browsable, log files sitting where anyone can read them, an SSL certificate running out.
03
Speed on a real phone
How long the page takes on a mid-range handset over mobile data, and which requests are holding it up.
04
Search visibility
Whether Google can reach and index the pages you care about, and what your titles, canonical tags and sitemap are telling it.
05
Checkout, if you sell
Whether the WooCommerce checkout loads, which gateway it hands off to, and whether anything in that path looks fragile.
06
The one question we ask you
Backups. No outside look can prove a backup exists, let alone that it restores. So we ask you.
Compare
How this differs from a free scanner
Free online scanners are useful for a first look. They stop being useful the moment you have to decide what to do about what they found.
| What you want | A free online scanner | A typical agency audit | DevsTeam |
|---|---|---|---|
| Who reads your site | Nobody | A junior, sometimes | One of the two owners |
| Needs your login | No | Usually | No |
| Ranked by what it costs you | No, by tool score | Sometimes | Yes |
| A price beside each fix | No | No | Yes |
| Says when you do not need them | No | No | Yes |
| Report another developer can act on | Rarely | Sometimes | Yes |
| What it costs | Free | Usually paid | Free |
Questions
Frequently asked questions
What is a WordPress website audit?
A written review of your site’s condition, covering software versions and known vulnerabilities, public exposure, speed, search visibility and, for shops, the checkout path. A person reads your site and writes the report, and every finding carries a fix and a price.
Do you need my login or admin access?
No. We read only what your site already shows the public, so there is nothing for you to set up and nothing of ours on your site.
How long does it take?
You get the write-up within two business days. We work Dhaka time, GMT plus six, so a site sent from the US or the UK is usually read overnight.
Is it really free? What is the catch?
It is free and there is no card. Some of the sites we read turn into work for us, and the ones that do pay for the ones that do not.
What can a free audit not detect?
Anything that needs access. Whether your backups restore, what is inside your database, whether core files have been altered, your PHP version if the server hides it, and quiet malware. Say so when you write if one of those is the thing that worries you, and we will quote the deeper version.
Do I have to use you for the fixes?
No. The report is yours, and it is written so another developer can act on it without ringing us first.
How often should you audit a WordPress site?
Twice a year for most business sites, and after any big change: a redesign, a host move, a new payment gateway. Sites on a care plan get this continuously, which is most of what a care plan is.
What happens if you find my site is already hacked?
You hear from us that same day, before the rest of the report is finished. If you want it dealt with, that is Emergency WordPress Support and Malware Removal, and we quote before touching anything.