Title: wpBara Audit
Author: wpbara
Published: <strong>September 30, 2026</strong>
Last modified: September 30, 2026

---

Search plugins

![](https://ps.w.org/wpbara-audit/assets/banner-772x250.png?rev=3721593)

![](https://ps.w.org/wpbara-audit/assets/icon-256x256.png?rev=3721593)

# wpBara Audit

 By [wpbara](https://profiles.wordpress.org/wpbara/)

[Download](https://downloads.wordpress.org/plugin/wpbara-audit.1.0.6.zip)

 * [Details](https://pcm.wordpress.org/plugins/wpbara-audit/#description)
 * [Reviews](https://pcm.wordpress.org/plugins/wpbara-audit/#reviews)
 *  [Installation](https://pcm.wordpress.org/plugins/wpbara-audit/#installation)
 * [Development](https://pcm.wordpress.org/plugins/wpbara-audit/#developers)

 [Support](https://wordpress.org/support/plugin/wpbara-audit/)

## Description

wpBara Audit checks your WordPress site in one click and shows what needs attention:
security, updates, performance and configuration. You get a clear score, a list 
of issues ordered by importance, and a report you can save as PDF.

The plugin only looks and never changes your site. The report is never stored – 
it exists only in the browser tab that generated it.

#### What you get

 * **A score that sets priorities** – an overall score from 0 to 100% across Security,
   Updates, Performance and Configuration, with every issue that lowered it, the
   most serious first
 * **Plugins and themes checked live against WordPress.org** – removed from the 
   directory (often for a security issue, with the date and reason), no release 
   in over a year or two, not tested with recent WordPress versions, updates waiting,
   and where each one gets its updates from
 * **Missing security releases** – whether WordPress is missing a security release
   of its own version line, and when PHP and the database server stop, or stopped,
   receiving support
 * **What your site exposes** – security headers, log files and configuration files
   that can be downloaded from a browser, usernames given away by the REST API, 
   XML-RPC, and folder listings
 * **Mixed content, with the addresses** – what the home page loads over plain http://,
   whether the browser blocks it, and http:// resources stored in your posts
 * **Database health** – tables on MyISAM or below utf8mb4, heavy autoloaded options,
   expired transients, trash, spam and posts keeping more revisions than the limit
 * **A report ready to share** – print it or save it as PDF

#### Who it is for

Site owners who want to know where their site stands, and agencies and freelancers
who look after client sites. Use it before taking over a site, as a regular check-
up, or to show a client what needs fixing and why.

#### Everything the audit checks

**Security**

 * WordPress core: missing security releases of the installed version line, checked
   live against WordPress.org
 * Plugins and themes: removed from WordPress.org, unmaintained, and where their
   updates come from
 * HTTP security headers (HSTS, X-Content-Type-Options, X-Frame-Options, CSP)
 * Public access to sensitive files: wp-config.php, .htaccess, .user.ini and log
   files in the WordPress folder, wp-admin and wp-content
 * REST API user enumeration, XML-RPC, and folder listings in uploads
 * Developer leftovers that should not be on a live site: phpinfo.php, .env, SQL
   dumps, .git folders
 * PHP errors shown to visitors, secret keys in wp-config.php, and a user named “
   admin”
 * End-of-life dates for PHP and the database server
 * Forms that send visitor data over plain http://

**Updates**

 * WordPress core, plugins and themes with pending updates
 * Time since each plugin’s and theme’s last release, and plugins not tested with
   the last three WordPress versions
 * Where each plugin and theme gets its updates from: WordPress.org, its author’s
   server, or unknown
 * Whether the server can reach WordPress.org for updates at all

**Performance**

 * Autoloaded options, with the largest ones listed
 * Expired transients, trash, spam, auto-drafts and orphaned metadata
 * Posts keeping more revisions than the revision limit
 * Database size, overhead and tables on MyISAM
 * OPcache, object cache and PHP limits

**Configuration**

 * Key WordPress constants with the value actually in effect
 * WordPress tables below utf8mb4, where emoji and some characters are cut off when
   saved
 * Mixed content on the home page and in published posts
 * The PHP error log: whether it has content and whether errors were written in 
   the last seven days – the entries themselves are never read
 * Search engine visibility and robots.txt, read the way crawlers read it
 * Scheduled cron jobs, inactive plugins and unused themes

The report also lists system details, must-use plugins, file permissions, post types,
taxonomies, permalinks and content statistics.

#### Safe and read-only

 * Only administrators (the `manage_options` capability) can run an audit
 * Every request is protected with a nonce, and every database query is a read-only
   SELECT
 * The report is never stored on the server
 * No personal data in the report: no logins, email addresses or registration dates
 * No server paths, database name, database host or table prefix in the report
 * No database tables, cron jobs or REST API endpoints of its own
 * The only thing it writes is a one-hour cache of public WordPress.org answers,
   removed when the plugin is deleted

#### Third-party libraries

None. The plugin ships only its own code.

#### External services

The plugin connects to external services only while an audit is running, never in
the background. No site content, credentials or personal data is sent.

**Your own site.** The audit requests pages and files from your own domain to read
security headers, check which files are publicly reachable, test the REST API and
XML-RPC, read robots.txt and check the home page for mixed content. These requests
stay on your server and are limited to 20 seconds in total.

**WordPress.org (api.wordpress.org).** Used to check plugins, themes and WordPress
core for updates, release dates and removal from the directory.

 * The plugin and theme information APIs receive the folder name (slug) of each 
   installed plugin and theme – including ones not from WordPress.org, since a removed
   plugin can only be recognised by asking. Plugins and themes whose Update URI 
   points to another server are skipped. These requests carry no site address.
 * The core version-check API is read without any parameters.
 * A connectivity check calls the update endpoints with the same user agent WordPress
   core uses, which includes your WordPress version and site address.
 * Answers are cached for one hour.

WordPress.org privacy policy: https://wordpress.org/about/privacy/

Support end dates for PHP and MySQL/MariaDB ship with the plugin and are not looked
up online.

#### About wpBara

wpBara Audit is made by wpBara – taking care of your site. We look after WordPress
sites every day: updates, security, backups and performance. If you would rather
have someone handle what the report finds, we can help: https://wpbara.com/

## Installation

#### From your WordPress dashboard

 1. Go to **Plugins -> Add New Plugin**
 2. Search for **wpBara Audit**
 3. Click **Install Now**, then **Activate**

#### Manual installation

 1. Download the plugin zip file from this page
 2. Go to **Plugins -> Add New Plugin -> Upload Plugin**, choose the zip file and click**
    Install Now** – or unzip it and upload the `wpbara-audit` folder to `/wp-content/
    plugins/` over FTP
 3. Activate the plugin through the **Plugins** menu in WordPress

#### Running an audit

 1. Go to **Tools -> wpBara Audit**
 2. Click **Generate report** – the report is displayed in the admin panel and can 
    be saved as PDF
 3. After use you can deactivate and delete the plugin – deleting it clears its cache
    as well

## FAQ

### How is this different from Site Health?

Site Health, built into WordPress, covers the basics: core and PHP versions, pending
updates, HTTPS, loopback requests, caching and scheduled events. wpBara Audit does
not repeat those checks. It looks at what they leave out – plugins removed from 
WordPress.org, missing security releases, files the site exposes, mixed content,
database health – and turns everything into one score with priorities and a report
you can share.

### Does the plugin fix anything?

No. It checks and reports, and never changes your site. Every issue in the report
says what is wrong, so you or your developer can decide how to fix it.

### Will it slow down my site?

No. The audit runs only when you click Generate report, and nothing runs in the 
background. Requests to your own site during an audit are limited to 20 seconds 
in total.

### Is any data stored after the report is generated?

The report is not. It lives only in the browser tab that generated it and is gone
when you close or refresh the page – nothing about it is written to the database
or to disk.

The plugin does keep one cache, of public product data and holding no information
about your site: what wordpress.org answers about your plugins, themes and WordPress
releases, stored for one hour so that running the audit twice in a row does not 
query the directory twice. Lookups that fail are never stored. The end-of-life dates
for PHP and your database server are not looked up at all – they ship with the plugin.

### Who can generate a report?

Only users with the `manage_options` capability, which by default means administrators
only.

### How do I get the best-looking PDF?

In the print dialog, choose A4 paper, turn off headers and footers, and leave the
scale at 100%. The page margins are set by the plugin; the headers and footers are
your browser’s own, and only you can switch them off – a web page is not allowed
to do it for you. In Chrome they are under “More settings”, in Firefox under “Margins
and Header and Footer”.

### What happens when I deactivate or delete the plugin?

Deactivating leaves the lookup cache in place, and it expires on its own within 
an hour. Deleting the plugin removes it immediately. Nothing else is left behind,
because nothing else was stored.

### How do I report a bug?

Please open a topic in this plugin’s support forum on WordPress.org. Tell us your
WordPress and PHP versions and what you expected to see. Do not post a full report
of a client’s site – a screenshot of the part that looks wrong is enough.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“wpBara Audit” is open source software. The following people have contributed to
this plugin.

Contributors

 *   [ wpbara ](https://profiles.wordpress.org/wpbara/)
 *   [ Emilia ](https://profiles.wordpress.org/emiliasmarthost/)

[Translate “wpBara Audit” into your language.](https://translate.wordpress.org/projects/wp-plugins/wpbara-audit)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/wpbara-audit/), check
out the [SVN repository](https://plugins.svn.wordpress.org/wpbara-audit/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/wpbara-audit/) by
[RSS](https://plugins.trac.wordpress.org/log/wpbara-audit/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.6

 * Faster and more reliable on slow sites: all requests to the site itself share
   a 20-second limit, and checks that do not fit are shown as not checked instead
   of the audit failing
 * Mixed content is checked on the home page and in post content, reported as two
   separate parts
 * New “Update source” column in the plugin and theme tables: WordPress.org, the
   author’s server, or unknown
 * Log files are found by name (error_log, debug.log, php.error.log and the like)
   and checked for public access
 * The PHP error log lowers the score only when errors were written in the last 
   seven days
 * Revisions are judged by the posts that keep more of them than the revision limit
 * Fixed: wp-config.php was reported as leaked on servers that run it as PHP, which
   exposes nothing
 * Fixed: REST API, XML-RPC and uploads checks that could not run are shown as not
   checked
 * Removed: the “Conflicting plugins” check, which relied on a fixed list and was
   too imprecise to act on
 * Information findings are listed after warnings and no longer counted as alerts
 * The printed report has a new cover with the wpBara Audit logo

#### 1.0.5

 * Plugins and themes are checked live against WordPress.org, including ones removed
   from the directory, with the date and reason
 * New “Last release” column, and flags for plugins not tested with recent WordPress
   versions
 * WordPress core updates tell a missing security release apart from a newer major
   version
 * Mixed content is read from what the browser actually loads, with the effect of
   each resource
 * robots.txt is read the way crawlers read it
 * Database checks cover WordPress’s own tables and no longer count what a healthy
   site always has
 * Many fixes to avoid false alarms and false “all clear” results

#### 1.0.4

 * End-of-life dates for PHP and database servers ship with the plugin; no third-
   party service is contacted
 * Fixed: the REST API check on sites with plain permalinks or a custom REST prefix

#### 1.0.3

 * Themes are checked against WordPress.org like plugins
 * The PHP error log section no longer reads log entries into the report
 * Accessibility and reduced-motion improvements

#### 1.0.2

 * Printing and saving as PDF are done by the browser, which fixes a hang in Firefox

#### 1.0.1

 * Initial release.

## Meta

 *  Version **1.0.6**
 *  Last updated **11 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/wpbara-audit/)
 * Tags
 * [audit](https://pcm.wordpress.org/plugins/tags/audit/)[diagnostics](https://pcm.wordpress.org/plugins/tags/diagnostics/)
   [performance](https://pcm.wordpress.org/plugins/tags/performance/)[security](https://pcm.wordpress.org/plugins/tags/security/)
   [tools](https://pcm.wordpress.org/plugins/tags/tools/)
 *  [Advanced View](https://pcm.wordpress.org/plugins/wpbara-audit/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/wpbara-audit/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/wpbara-audit/reviews/)

## Contributors

 *   [ wpbara ](https://profiles.wordpress.org/wpbara/)
 *   [ Emilia ](https://profiles.wordpress.org/emiliasmarthost/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/wpbara-audit/)