wpBara Audit

Description

wpBara Audit checks your WordPress site in one click and shows what needs attention: security, updates, performance and configuration. You get a clear score, a list of issues ordered by importance, and a report you can save as PDF.

The plugin only looks and never changes your site. The report is never stored – it exists only in the browser tab that generated it.

What you get

  • A score that sets priorities – an overall score from 0 to 100% across Security, Updates, Performance and Configuration, with every issue that lowered it, the most serious first
  • Plugins and themes checked live against WordPress.org – removed from the directory (often for a security issue, with the date and reason), no release in over a year or two, not tested with recent WordPress versions, updates waiting, and where each one gets its updates from
  • Missing security releases – whether WordPress is missing a security release of its own version line, and when PHP and the database server stop, or stopped, receiving support
  • What your site exposes – security headers, log files and configuration files that can be downloaded from a browser, usernames given away by the REST API, XML-RPC, and folder listings
  • Mixed content, with the addresses – what the home page loads over plain http://, whether the browser blocks it, and http:// resources stored in your posts
  • Database health – tables on MyISAM or below utf8mb4, heavy autoloaded options, expired transients, trash, spam and posts keeping more revisions than the limit
  • A report ready to share – print it or save it as PDF

Who it is for

Site owners who want to know where their site stands, and agencies and freelancers who look after client sites. Use it before taking over a site, as a regular check-up, or to show a client what needs fixing and why.

Everything the audit checks

Security

  • WordPress core: missing security releases of the installed version line, checked live against WordPress.org
  • Plugins and themes: removed from WordPress.org, unmaintained, and where their updates come from
  • HTTP security headers (HSTS, X-Content-Type-Options, X-Frame-Options, CSP)
  • Public access to sensitive files: wp-config.php, .htaccess, .user.ini and log files in the WordPress folder, wp-admin and wp-content
  • REST API user enumeration, XML-RPC, and folder listings in uploads
  • Developer leftovers that should not be on a live site: phpinfo.php, .env, SQL dumps, .git folders
  • PHP errors shown to visitors, secret keys in wp-config.php, and a user named “admin”
  • End-of-life dates for PHP and the database server
  • Forms that send visitor data over plain http://

Updates

  • WordPress core, plugins and themes with pending updates
  • Time since each plugin’s and theme’s last release, and plugins not tested with the last three WordPress versions
  • Where each plugin and theme gets its updates from: WordPress.org, its author’s server, or unknown
  • Whether the server can reach WordPress.org for updates at all

Performance

  • Autoloaded options, with the largest ones listed
  • Expired transients, trash, spam, auto-drafts and orphaned metadata
  • Posts keeping more revisions than the revision limit
  • Database size, overhead and tables on MyISAM
  • OPcache, object cache and PHP limits

Configuration

  • Key WordPress constants with the value actually in effect
  • WordPress tables below utf8mb4, where emoji and some characters are cut off when saved
  • Mixed content on the home page and in published posts
  • The PHP error log: whether it has content and whether errors were written in the last seven days – the entries themselves are never read
  • Search engine visibility and robots.txt, read the way crawlers read it
  • Scheduled cron jobs, inactive plugins and unused themes

The report also lists system details, must-use plugins, file permissions, post types, taxonomies, permalinks and content statistics.

Safe and read-only

  • Only administrators (the manage_options capability) can run an audit
  • Every request is protected with a nonce, and every database query is a read-only SELECT
  • The report is never stored on the server
  • No personal data in the report: no logins, email addresses or registration dates
  • No server paths, database name, database host or table prefix in the report
  • No database tables, cron jobs or REST API endpoints of its own
  • The only thing it writes is a one-hour cache of public WordPress.org answers, removed when the plugin is deleted

Third-party libraries

None. The plugin ships only its own code.

External services

The plugin connects to external services only while an audit is running, never in the background. No site content, credentials or personal data is sent.

Your own site. The audit requests pages and files from your own domain to read security headers, check which files are publicly reachable, test the REST API and XML-RPC, read robots.txt and check the home page for mixed content. These requests stay on your server and are limited to 20 seconds in total.

WordPress.org (api.wordpress.org). Used to check plugins, themes and WordPress core for updates, release dates and removal from the directory.

  • The plugin and theme information APIs receive the folder name (slug) of each installed plugin and theme – including ones not from WordPress.org, since a removed plugin can only be recognised by asking. Plugins and themes whose Update URI points to another server are skipped. These requests carry no site address.
  • The core version-check API is read without any parameters.
  • A connectivity check calls the update endpoints with the same user agent WordPress core uses, which includes your WordPress version and site address.
  • Answers are cached for one hour.

WordPress.org privacy policy: https://wordpress.org/about/privacy/

Support end dates for PHP and MySQL/MariaDB ship with the plugin and are not looked up online.

About wpBara

wpBara Audit is made by wpBara – taking care of your site. We look after WordPress sites every day: updates, security, backups and performance. If you would rather have someone handle what the report finds, we can help: https://wpbara.com/

Installation

From your WordPress dashboard

  1. Go to Plugins -> Add New Plugin
  2. Search for wpBara Audit
  3. Click Install Now, then Activate

Manual installation

  1. Download the plugin zip file from this page
  2. Go to Plugins -> Add New Plugin -> Upload Plugin, choose the zip file and click Install Now – or unzip it and upload the wpbara-audit folder to /wp-content/plugins/ over FTP
  3. Activate the plugin through the Plugins menu in WordPress

Running an audit

  1. Go to Tools -> wpBara Audit
  2. Click Generate report – the report is displayed in the admin panel and can be saved as PDF
  3. After use you can deactivate and delete the plugin – deleting it clears its cache as well

FAQ

How is this different from Site Health?

Site Health, built into WordPress, covers the basics: core and PHP versions, pending updates, HTTPS, loopback requests, caching and scheduled events. wpBara Audit does not repeat those checks. It looks at what they leave out – plugins removed from WordPress.org, missing security releases, files the site exposes, mixed content, database health – and turns everything into one score with priorities and a report you can share.

Does the plugin fix anything?

No. It checks and reports, and never changes your site. Every issue in the report says what is wrong, so you or your developer can decide how to fix it.

Will it slow down my site?

No. The audit runs only when you click Generate report, and nothing runs in the background. Requests to your own site during an audit are limited to 20 seconds in total.

Is any data stored after the report is generated?

The report is not. It lives only in the browser tab that generated it and is gone when you close or refresh the page – nothing about it is written to the database or to disk.

The plugin does keep one cache, of public product data and holding no information about your site: what wordpress.org answers about your plugins, themes and WordPress releases, stored for one hour so that running the audit twice in a row does not query the directory twice. Lookups that fail are never stored. The end-of-life dates for PHP and your database server are not looked up at all – they ship with the plugin.

Who can generate a report?

Only users with the manage_options capability, which by default means administrators only.

How do I get the best-looking PDF?

In the print dialog, choose A4 paper, turn off headers and footers, and leave the scale at 100%. The page margins are set by the plugin; the headers and footers are your browser’s own, and only you can switch them off – a web page is not allowed to do it for you. In Chrome they are under “More settings”, in Firefox under “Margins and Header and Footer”.

What happens when I deactivate or delete the plugin?

Deactivating leaves the lookup cache in place, and it expires on its own within an hour. Deleting the plugin removes it immediately. Nothing else is left behind, because nothing else was stored.

How do I report a bug?

Please open a topic in this plugin’s support forum on WordPress.org. Tell us your WordPress and PHP versions and what you expected to see. Do not post a full report of a client’s site – a screenshot of the part that looks wrong is enough.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“wpBara Audit” is open source software. The following people have contributed to this plugin.

Contributors

Translate “wpBara Audit” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.0.6

  • Faster and more reliable on slow sites: all requests to the site itself share a 20-second limit, and checks that do not fit are shown as not checked instead of the audit failing
  • Mixed content is checked on the home page and in post content, reported as two separate parts
  • New “Update source” column in the plugin and theme tables: WordPress.org, the author’s server, or unknown
  • Log files are found by name (error_log, debug.log, php.error.log and the like) and checked for public access
  • The PHP error log lowers the score only when errors were written in the last seven days
  • Revisions are judged by the posts that keep more of them than the revision limit
  • Fixed: wp-config.php was reported as leaked on servers that run it as PHP, which exposes nothing
  • Fixed: REST API, XML-RPC and uploads checks that could not run are shown as not checked
  • Removed: the “Conflicting plugins” check, which relied on a fixed list and was too imprecise to act on
  • Information findings are listed after warnings and no longer counted as alerts
  • The printed report has a new cover with the wpBara Audit logo

1.0.5

  • Plugins and themes are checked live against WordPress.org, including ones removed from the directory, with the date and reason
  • New “Last release” column, and flags for plugins not tested with recent WordPress versions
  • WordPress core updates tell a missing security release apart from a newer major version
  • Mixed content is read from what the browser actually loads, with the effect of each resource
  • robots.txt is read the way crawlers read it
  • Database checks cover WordPress’s own tables and no longer count what a healthy site always has
  • Many fixes to avoid false alarms and false “all clear” results

1.0.4

  • End-of-life dates for PHP and database servers ship with the plugin; no third-party service is contacted
  • Fixed: the REST API check on sites with plain permalinks or a custom REST prefix

1.0.3

  • Themes are checked against WordPress.org like plugins
  • The PHP error log section no longer reads log entries into the report
  • Accessibility and reduced-motion improvements

1.0.2

  • Printing and saving as PDF are done by the browser, which fixes a hang in Firefox

1.0.1

  • Initial release.