{"id":353417,"date":"2026-08-27T10:11:18","date_gmt":"2026-08-27T10:11:18","guid":{"rendered":"https:\/\/en-za.wordpress.org\/plugins\/site-audit-technical-handover\/"},"modified":"2026-08-27T10:10:59","modified_gmt":"2026-08-27T10:10:59","slug":"versys-site-audit-technical-handover","status":"publish","type":"plugin","link":"https:\/\/pcm.wordpress.org\/plugins\/versys-site-audit-technical-handover\/","author":18561211,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.1","stable_tag":"1.0.1","tested":"7.0.4","requires":"6.5","requires_php":"8.0","requires_plugins":null,"header_name":"Versys Site Audit & Technical Handover","header_author":"Versys Media","header_description":"Audit an inherited WordPress site, inventory plugins and integrations, document technical setup, and generate a client handover report.","assets_banners_color":"","last_updated":"2026-08-27 10:10:59","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/versysmedia.com\/plugins\/site-audit-technical-handover\/","header_author_uri":"https:\/\/versysmedia.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":52,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.1":{"tag":"1.0.1","author":"versysmedia","date":"2026-08-27 10:10:59","revision":3668559}},"upgrade_notice":{"1.0.1":"<p>WordPress.org review-compliance update with distinctive naming, enqueued report assets, stronger input handling, and WordPress privacy-tool integration.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.1"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Site Audit Dashboard with operational-readiness score, documentation coverage, and open findings.","2":"WordPress plugin inventory with state, category evidence, dependencies, and technical documentation links.","3":"Audit finding detail with evidence, confidence, and recommended manual actions.","4":"Technical Documentation editor for components, integrations, licences, procedures, contacts, and notes.","5":"Printable Technical Handover Report generated from the latest site audit and documentation."}},"plugin_section":[],"plugin_tags":[272924,235819,20034,277815,40977],"plugin_category":[],"plugin_contributors":[277816],"plugin_business_model":[],"class_list":["post-353417","plugin","type-plugin","status-publish","hentry","plugin_tags-client-handover","plugin_tags-plugin-inventory","plugin_tags-site-audit","plugin_tags-technical-documentation","plugin_tags-website-maintenance","plugin_contributors-versysmedia","plugin_committers-versysmedia"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/versys-site-audit-technical-handover.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Versys Site Audit &amp; Technical Handover is a WordPress site audit and technical documentation plugin for agencies, freelancers, developers, site owners, and internal IT teams.<\/p>\n\n<p>Use it when you inherit, maintain, migrate, troubleshoot, or hand over an existing WordPress website and need a clear answer to four questions:<\/p>\n\n<ul>\n<li>What is installed and configured?<\/li>\n<li>What needs attention?<\/li>\n<li>Why do important components exist?<\/li>\n<li>What should the next administrator know before making changes?<\/li>\n<\/ul>\n\n<p>The plugin runs a local, on-demand website audit, stores an explainable inventory snapshot, provides structured Technical Documentation records, and generates a browser-printable Technical Handover Report.<\/p>\n\n<h4>How does it work?<\/h4>\n\n<ol>\n<li>Run the WordPress site audit.<\/li>\n<li>Review the detected environment, inventory, findings, and operational-readiness score.<\/li>\n<li>Add technical documentation for important plugins, themes, integrations, licences, procedures, and contacts.<\/li>\n<li>Generate a client or developer handover report from the latest audit and documentation.<\/li>\n<\/ol>\n\n<h4>What does the WordPress site audit check?<\/h4>\n\n<p>The on-demand audit inventories:<\/p>\n\n<ul>\n<li>WordPress, PHP, database, HTTPS, debug, cache, locale, and permalink environment details.<\/li>\n<li>Active, inactive, network-active, and must-use plugins.<\/li>\n<li>Active and inactive themes, including child-theme relationships.<\/li>\n<li>User role counts and administrator accounts.<\/li>\n<li>Recognised form and SMTP\/mail plugins without claiming delivery success.<\/li>\n<li>WP-Cron events and Action Scheduler counts when its public store API is available.<\/li>\n<li>Database size, largest tables, revisions, and transient row counts when database permissions allow.<\/li>\n<li>Conservative external-service signals using installed plugins and allow-listed option names.<\/li>\n<li>Child theme, Additional CSS, must-use plugin, and code-management plugin signals.<\/li>\n<\/ul>\n\n<h4>Technical Documentation<\/h4>\n\n<p>Create a permanent operational record inside WordPress for:<\/p>\n\n<ul>\n<li>Components and why they exist.<\/li>\n<li>Integrations and external services.<\/li>\n<li>Licences and renewal responsibility.<\/li>\n<li>Operating and maintenance procedures.<\/li>\n<li>Technical contacts and ownership.<\/li>\n<li>General implementation and handover notes.<\/li>\n<\/ul>\n\n<p>Detected plugins, must-use plugins, and themes can be linked to documentation records so a future administrator can understand their purpose before changing or removing them.<\/p>\n\n<p>Technical Documentation is not a password vault. The interface warns against storing credentials, and common credential-like patterns are redacted before storage.<\/p>\n\n<h4>Audit findings and operational readiness<\/h4>\n\n<p>Each finding includes severity, a plain-English explanation, evidence, confidence, a recommended manual action, first-seen and last-seen dates, and an acknowledgement state.<\/p>\n\n<p>The 0-100 operational-readiness score is an explainable convenience metric. Every deduction is shown. It is not a security, legal, compliance, or safety certification.<\/p>\n\n<h4>Technical Handover Report<\/h4>\n\n<p>Generate a standalone browser-printable report on explicit administrator request. The report combines the latest WordPress site audit, documented components, integrations, procedures, and selected findings into one technical handover document.<\/p>\n\n<p>Use the report for client handover, developer takeover, maintenance onboarding, internal IT documentation, migration preparation, or an inherited-site review.<\/p>\n\n<p>The report does not include automatically discovered secret values.<\/p>\n\n<h4>Privacy and data handling<\/h4>\n\n<ul>\n<li>No telemetry.<\/li>\n<li>No external SaaS dependency.<\/li>\n<li>No AI dependency.<\/li>\n<li>No remote calls during ordinary admin loads or audits.<\/li>\n<li>No credential values collected from integration settings.<\/li>\n<li>Audit snapshots can store administrator usernames, display names, email addresses, registration dates, and recognised last-login metadata locally in the WordPress database.<\/li>\n<li>Technical Documentation records can contain contact details and other information entered manually by administrators.<\/li>\n<li>This information is not sent to Versys Media or any third party by the plugin.<\/li>\n<li>Reports are generated only on explicit administrator action.<\/li>\n<li>WordPress privacy-policy suggested text is added for site administrators.<\/li>\n<li>Integrates with WordPress personal-data export and erasure tools for matching locally stored administrator and documentation data.<\/li>\n<\/ul>\n\n<h4>Non-destructive by design<\/h4>\n\n<p>Version 1 is read-mostly. It does not deactivate plugins, update software, clean the database, reschedule jobs, change users, or delete site components during an audit.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin ZIP through Plugins &gt; Add New &gt; Upload Plugin, or copy the <code>versys-site-audit-technical-handover<\/code> folder into <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate Versys Site Audit &amp; Technical Handover.<\/li>\n<li>Open Site Audit in the WordPress administration menu.<\/li>\n<li>Select Run first audit.<\/li>\n<li>Review the audit findings and inventory.<\/li>\n<li>Add important information under Technical Documentation.<\/li>\n<li>Open Handover Report when you need a printable technical handover.<\/li>\n<\/ol>\n\n<p>Only users with <code>manage_options<\/code> can access the plugin by default.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20does%20versys%20site%20audit%20%26%20technical%20handover%20do%3F\"><h3>What does Versys Site Audit &amp; Technical Handover do?<\/h3><\/dt>\n<dd><p>It audits the operational structure of a WordPress website, inventories important components, helps document why those components exist, and creates a technical handover report for future administrators, developers, agencies, clients, or site owners.<\/p><\/dd>\n<dt id=\"how%20do%20i%20audit%20an%20inherited%20wordpress%20website%3F\"><h3>How do I audit an inherited WordPress website?<\/h3><\/dt>\n<dd><p>Install the plugin, run the on-demand Site Audit, review the inventory and findings, document critical components and integrations, then generate the Technical Handover Report before making major changes.<\/p><\/dd>\n<dt id=\"what%20does%20a%20wordpress%20website%20audit%20include%3F\"><h3>What does a WordPress website audit include?<\/h3><\/dt>\n<dd><p>This plugin checks environment details, plugins, themes, users, forms and mail tooling, WP-Cron, Action Scheduler where available, database information, recognised integrations, and custom-code signals. It also creates evidence-based findings and an explainable operational-readiness score.<\/p><\/dd>\n<dt id=\"what%20is%20a%20wordpress%20technical%20handover%3F\"><h3>What is a WordPress technical handover?<\/h3><\/dt>\n<dd><p>A technical handover is a structured record of how a website is configured, which components and services matter, who owns or maintains them, what procedures should be followed, and what the next administrator needs to know.<\/p><\/dd>\n<dt id=\"can%20agencies%20use%20this%20for%20client%20website%20handovers%3F\"><h3>Can agencies use this for client website handovers?<\/h3><\/dt>\n<dd><p>Yes. Agencies and freelancers can audit a site, record component purpose and ownership, document procedures and licences, and generate a printable handover report for a client or another developer.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20change%20or%20clean%20the%20website%3F\"><h3>Does the plugin change or clean the website?<\/h3><\/dt>\n<dd><p>No. Version 1 is read-mostly and non-destructive. It does not deactivate or delete plugins, change themes, modify users, update software, reschedule cron events, retry actions, clean database tables, or remove revisions and transients.<\/p><\/dd>\n<dt id=\"is%20this%20a%20security%20scanner%3F\"><h3>Is this a security scanner?<\/h3><\/dt>\n<dd><p>No. It is an operational site audit, technical documentation, and handover tool. It does not replace a dedicated security product or professional security review.<\/p><\/dd>\n<dt id=\"does%20an%20overlap%20finding%20mean%20two%20plugins%20conflict%3F\"><h3>Does an overlap finding mean two plugins conflict?<\/h3><\/dt>\n<dd><p>No. Overlap findings use conservative metadata terms to identify active plugins in the same functional category. The evidence and confidence are shown and manual review is required.<\/p><\/dd>\n<dt id=\"does%20detecting%20an%20smtp%20plugin%20prove%20email%20delivery%20works%3F\"><h3>Does detecting an SMTP plugin prove email delivery works?<\/h3><\/dt>\n<dd><p>No. The audit records recognised mail-tool presence only. It does not send test mail or claim end-to-end delivery assurance.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20use%20ai%20or%20send%20site%20data%20to%20versys%20media%3F\"><h3>Does the plugin use AI or send site data to Versys Media?<\/h3><\/dt>\n<dd><p>No. Version 1 works locally without AI, telemetry, SaaS, or remote audit calls.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20store%20api%20keys%20or%20passwords%3F\"><h3>Does the plugin store API keys or passwords?<\/h3><\/dt>\n<dd><p>It does not read credential values from integration settings. Administrators are warned not to enter secrets in Technical Documentation, and common credential-like patterns are redacted before storage.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20data%20when%20the%20plugin%20is%20removed%3F\"><h3>What happens to data when the plugin is removed?<\/h3><\/dt>\n<dd><p>Deactivation always retains data. Uninstall retains data by default. An administrator can explicitly enable Delete all Versys Site Audit &amp; Technical Handover data on uninstall in the plugin settings.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Renamed the plugin and directory slug to a distinctive Versys-branded identity for WordPress.org review.<\/li>\n<li>Moved the printable report CSS and JavaScript into local enqueued asset files.<\/li>\n<li>Added suggested WordPress privacy-policy text for locally stored audit and documentation data.<\/li>\n<li>Added WordPress personal-data exporter and eraser integration for locally stored personal data.<\/li>\n<li>Tightened admin-view output escaping and attribute handling.<\/li>\n<li>Hardened admin input handling to process only allow-listed fields.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial WordPress.org candidate.<\/li>\n<li>Added on-demand environment, theme, plugin, user, forms\/email, cron, database, integration, and custom-code signal audits.<\/li>\n<li>Added structured Technical Documentation records and component relationships.<\/li>\n<li>Added evidence-based finding lifecycle and explainable operational-readiness score.<\/li>\n<li>Added explicit browser-printable Technical Handover Report.<\/li>\n<li>Added non-destructive data-retention controls and credential-like text redaction.<\/li>\n<\/ul>","raw_excerpt":"Audit an inherited WordPress site, inventory plugins and integrations, document technical setup, and generate a client handover report.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/353417","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=353417"}],"author":[{"embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/versysmedia"}],"wp:attachment":[{"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=353417"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=353417"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=353417"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=353417"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=353417"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/pcm.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=353417"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}