Description
WPHI Diagnostic Suite Lite is a full diagnostic toolkit for WordPress. It captures and explains PHP errors, shows which update or plugin change caused them, and checks the parts of a site that usually go wrong quietly: the database, autoloaded options, scheduled tasks, front-end assets, outdated or abandoned plugins, SSL, email delivery and hosting performance.
It looks, it doesn’t touch. Nothing is written to your database, no settings are changed and no plugins are deactivated, so it’s safe to run on a live production site. Everything starts working as soon as you activate it; there’s nothing to configure.
Who it’s for
- Site owners who want to know why their site is slow, broken or not sending email
- Developers debugging PHP errors, deprecations and plugin conflicts
- Agencies auditing a site before launch, before a round of updates, or as ongoing maintenance
- Support teams who need a clear report to hand to a host or developer
Start here: the dashboard
π©Ί Health Score Dashboard
A 0β100 health score with the reasons behind it: PHP version, autoload size, pending plugin updates and how far behind WordPress core is. Each issue links straight to the page that deals with it, and a chart breaks the issues down by severity. Recent errors and recent changes are summarised alongside, with a system snapshot of your WordPress, PHP, theme and plugin details and a quick link to every module.
π§ Recommended Diagnostic Paths
Not sure where to begin? The dashboard reads your site’s live signals (recent errors, overdue cron jobs, autoload size, pending updates) and suggests which pages to check, in order, for common problems: something broke after an update, a slow admin, checkout or payment issues, random outages, plugin conflicts, database errors, and a slow site with no errors at all. Each suggestion shows the signals that triggered it and any matching errors.
Errors and changes
π΄ Error Log
Captures PHP errors, warnings, notices and deprecations as they happen, even when WP_DEBUG and WP_DEBUG_LOG are turned off. That includes fatal errors and the notices WordPress raises for deprecated functions, arguments and hooks, and for functions called incorrectly. Identical errors are grouped, rated by severity and shown with first and last seen times, occurrence count, file and line.
- Find the error that matters: search, filter by severity or by source, and sort by date, severity, frequency or message. A frequency chart and a “most error-prone files” list show where the problems are concentrated.
- Fix guide for every error: what the error means, the likely cause (read from the actual message), the impact, numbered steps to fix it, useful WP-CLI commands and tips to stop it coming back.
- The code that caused it: a snippet of the source with the error line highlighted, and a warning if the file has changed since the error was logged. When WordPress reports its own internals instead of the real culprit (common with deprecation notices), it finds the calling file where it can, or explains how to trace it. File paths can be copied with one click.
- Linked to What Changed?: see the changes that came before each error, and jump between the error and the timeline.
- Three views: the Temp Log (errors happening now, from the plugin’s own capture combined with your debug.log and server error log), your WordPress debug.log, and your server’s PHP error log. Each view shows the log’s location, size, last modified time and number of entries read, and an “About these logs” guide explains the difference. Custom log locations can be set under Log Sources, and common hosting stacks such as Laragon, XAMPP, WampServer, Apache, nginx, PHP-FPM and Homebrew are detected automatically.
- Clear fixed errors: Clear reloads a few front-end and admin pages to see which errors still occur and keeps only those, so a fixed error disappears and stays gone. Re-Scan checks again without clearing anything. The Temp Log trims itself so it never grows without limit.
- Exposed log check: warns you if your debug.log can be downloaded from the web.
- Self-check: if the plugin can’t set up or write its own log (file permissions, another plugin taking over error handling), it tells you why instead of failing silently.
π
What Changed?
Every change that commonly breaks a site, plotted on the same interactive timeline as your PHP errors: plugin updates, activations and deactivations, WordPress core updates, PHP version changes, theme switches and theme updates, sudden growth in the options table, and spikes in autoloaded data. It also spots plugin, theme and core files that were modified outside WordPress, for example by FTP or your host.
Errors are matched to the change most likely to have caused them, first by file path (the error comes from inside the plugin that changed) and then by timing, with a 0β99 score and a plain-English reason for each match.
- Zoom, pan, pick a time range (7 days up to a year) or open the timeline full screen; hover or click any change or error for details
- A chronological event log and an error onset table showing the nearest change before each error, whether it followed a recent update, and the likely cause, each with a detailed view for every row
- A one-click plain-text summary of the most likely cause, ready to paste into a ticket, a Slack message or an email to a client
- A snapshot panel showing the WordPress and PHP versions, active theme, active plugins and total autoloaded data at the last snapshot, with a Snapshot Now button
- Choose which log the errors come from, and clear or re-scan them, without leaving the page
π Blast Radius
What each plugin has added to your site: custom database tables (with row counts) and scheduled cron jobs, each traced back to the plugin that created it, plus the total size of autoloaded options. Useful before deactivating or removing a plugin.
Performance
ποΈ Database Health
Tables over 50 MB with a size comparison chart, autoloaded options ranked by size, and integrity checks for orphaned postmeta, usermeta and term relationships, the autoload index and Action Scheduler history. An options table audit finds oversized options (over 100 KB), options that no longer belong to any installed plugin, and active and expired transients. Content checks find posts with more than 20 revisions, the total revision count, and posts that have sat in the trash for over 30 days.
π¦ Autoload Governor
Autoloaded options are loaded on every single page request. This shows the total against recommended limits, which plugin or feature each option belongs to, and the biggest individual offenders, colour-coded by size. Deep diagnostics find options left behind by deleted plugins, autoloaded transients, duplicates, leftovers from migration and backup plugins, and stored sessions.
βοΈ Cron Inspector
WP-Cron and Action Scheduler jobs in one list with next run times, intervals and overdue jobs highlighted, split into WordPress core and custom jobs. A 24-hour chart shows when jobs pile up, overlap and bottleneck detection flags jobs that crowd each other, Action Scheduler’s completed and failed counts are shown, and a traffic check tells you whether your cron jobs depend on visitors to run.
π Asset Inspector
Loads your home page the way a visitor would and lists every script and stylesheet on it, with file sizes, JavaScript and CSS totals, and a breakdown chart. It suggests ways to cut the payload (deferring JavaScript, minifying and combining files, loading assets only where they’re needed, using a CDN) along with well-known plugins that can help. Results are cached, with a button to scan again.
π Hosting Benchmark
Is your host slow? Four timed tests (database round trips, PHP processing speed, file system read and write, and time to first byte for your home page) each get a letter grade, plus an overall grade. It also reports whether a persistent object cache is in use and keeps your last 12 results in a history chart, so you can see whether things have got slower, for example after moving hosts. It only runs when you click the button.
Updates and stability
π Update Impact
Before you update a plugin, see what it shares with the rest of your site: hooks other plugins also use (with the full list), database tables, cron jobs, REST routes, asset size and any errors after its past updates. Each pending update gets a 0β100 blast radius score, highest risk first, with an Update Now button when you’re ready. Results are cached per plugin version, and you can re-scan at any time.
π΅οΈ Plugin Abandonment Radar
Every installed plugin checked against WordPress.org for how long it’s been since its last update, how far its “tested up to” version lags behind, and whether it has been closed or removed from the directory, which often happens because of an unpatched security issue. Each plugin gets a risk level (critical, high, medium, low or unknown) with the reasons, sorted by risk. Plugins that aren’t on WordPress.org are flagged as unverifiable rather than risky.
π£ Time Bombs
Checks when your SSL certificate expires and how many days are left, so it doesn’t lapse without warning.
Infrastructure
π₯οΈ Server & PHP
The PHP settings that matter most for WordPress in one place: PHP version, memory and execution limits, upload limits, WordPress memory limits, whether errors are displayed on screen, and whether OPcache is on.
βοΈ Mail Health
Answers “why isn’t my site sending email?”. It shows how WordPress is sending mail (PHP mail, a recognised SMTP plugin, or a replaced mail function) and the from address, checks your domain’s SPF, DMARC, MX and common DKIM records, and sends you a test email that reports the real error if delivery fails.
Reports and WP-CLI
π Export Report
A self-contained HTML report with the health score and issues, database health, cron, front-end assets and an error log summary. Send it to your host or a developer without giving them admin access. Reports contain no personal information: no user data, IP addresses or session details.
β¨οΈ WP-CLI commands
wp wphi score, errors, timebombs, radar, benchmark and mail bring the same checks to the command line, with table, JSON or CSV output where it makes sense. wp wphi radar --refresh skips the cache. wp wphi score --fail-below=<n> exits with an error when the score drops below a threshold, so you can use it in a CI or deployment pipeline.
Built for everyday use
- Tables can be sorted, searched and paged, and your page size is remembered
- Charts throughout: gauges, bar charts, density charts and breakdowns alongside the raw data
- Collapsible sections keep long pages manageable
- Works on phones and tablets as well as the desktop
- Pages link to each other, so an issue on the dashboard or an error in the log takes you straight to the right place
Safe on production
- Never writes to your database. The plugin’s own data (captured errors, change snapshots and cached results) is stored as protected files inside its folder and removed when you delete the plugin.
- No scripts or styles are loaded for visitors, and there is no background processing.
- The only things with side effects are ones you trigger yourself: the test email, the benchmark’s temporary test file (deleted straight away), and the page loads Clear and Re-Scan use to check which errors are still happening.
- Only administrators can see the plugin’s pages.
Want more?
WP Health Inspector Pro builds on everything in Lite with automated analysis and tools for teams and agencies: Root Cause Analysis, Conflict Detector, Request Profiler, Code Linter, External Dependency Monitoring, Performance Baselines, Core Web Vitals estimates, Security Audit, and Content Health. It also adds deeper versions of several Lite pages, including the REST route explorer and hook inspector in Blast Radius, PHP, stale plugin and license key checks in Time Bombs, a full php.ini, wp-config.php and extension audit, and copy-paste cleanup commands for autoload problems. Plus Fleet Sync to monitor every client site from one dashboard, sorted worst-first; Integrations that file any error straight to Jira, Trello, Asana, ClickUp, Linear, GitHub or Slack; weekly Health Digest emails; and white-label report branding.
Learn more at wphealthinspector.com
External Services
This plugin connects to the official WordPress.org Plugin API to power the Plugin Abandonment Radar module.
What it does: for each installed plugin, the plugin requests that plugin’s public directory listing (last-updated date, tested-up-to version, and open/closed status) from the WordPress.org Plugin API, so it can flag plugins that appear abandoned or removed.
When it happens: only when an administrator views the Plugin Abandonment Radar page. Results are cached for 12 hours between requests.
Data sent: only the plugin slugs of plugins already installed on your site. No site content, user data, or personally identifiable information is sent.
Service provider: WordPress.org
API endpoint: https://api.wordpress.org/plugins/info/1.2/
Terms of Service: https://wordpress.org/about/terms-of-service/
Privacy Policy: https://wordpress.org/about/privacy/
Other network requests. The Mail Health page looks up your own domain’s public DNS records (SPF, DKIM, DMARC and MX) using your server’s normal DNS resolver; results are cached for an hour. The Asset Inspector, Hosting Benchmark, and the Error Log’s Clear and Re-Scan buttons make requests to your own site only. None of these send data to any third party.
Installation
- Install the plugin through the WordPress Plugins screen, or upload the plugin files to
/wp-content/plugins/wphi-diagnostic-suite-lite. - Activate the plugin through the Plugins screen in WordPress.
- Navigate to Health Inspector in the admin menu to get started.
No configuration required. The health score dashboard loads immediately on activation.
FAQ
-
Why did my WordPress site break after an update?
-
Most likely a recent change is responsible: a plugin update, an activation, a core update or a theme switch. What Changed? plots all of those on the same timeline as your PHP errors and scores how likely each change is to have caused them, so you can see which change lines up with the moment things broke instead of guessing.
-
Do I need to turn on WP_DEBUG or WP_DEBUG_LOG?
-
No. The plugin captures PHP errors itself, so the Error Log works with debugging switched off. If you do have a debug.log or a server error log, it reads those too.
-
How do I read the WordPress debug.log?
-
Open the Error Log page. It groups identical errors, rates each group by severity, shows the first and last time it happened, how often, and the file and line, and gives you a fix guide with the offending code highlighted. It also warns you if your debug.log can be downloaded from the web.
-
Why isn’t my site sending email?
-
The Mail Health page shows how your site sends mail, checks the DNS records that decide whether your email is trusted (SPF, DKIM, DMARC and MX), and lets you send yourself a test email that shows the actual error if it fails.
-
Is my site slow because of my host?
-
Run the Hosting Benchmark. It times your database, PHP, file system and home page response and grades each one. If those look fine, check Database Health, Autoload Governor and Asset Inspector for the usual causes of a slow site.
-
What’s the difference between the free version and Pro?
-
Lite gives you 14 fully working diagnostic modules plus the health score dashboard, for one site. Nothing is locked or time-limited. Pro adds more modules for teams and agencies, including automated Root Cause Analysis, a Conflict Detector, Fleet Sync for monitoring many sites from one dashboard, and integrations that file errors straight to your task tracker.
-
Does this plugin make any changes to my database?
-
No. It only reads from the database. The small amount of data it keeps for itself, such as captured errors and change snapshots, is stored as protected files in its own plugin folder and removed when you delete the plugin.
-
Can I use this on a live production site?
-
Yes. It’s designed for production. Nothing is loaded for visitors, and nothing on your site is changed.
-
Will this slow down my site?
-
No. The plugin only runs its checks when an administrator opens one of its pages, and there is no background processing. On every request it registers a lightweight error handler so PHP errors can be recorded, which adds no database queries. The What Changed? timeline takes a small snapshot when plugins, themes or WordPress are updated, activated or switched, and when you open its page.
-
What is the correlation score in What Changed?
-
Each pairing of an error and a change gets a score from 0 to 99. Matches on file path, where the error comes from inside the plugin or theme that changed, score 70β90 whatever the timing. Matches on timing alone score from 5 up to 99 depending on how close together the change and the errors were, and how precisely the change time is known.
-
Can I use it from the command line?
-
Yes. Run
wp wphito see the commands.wp wphi score --fail-below=80, for example, fails when the health score is under 80, which is handy in a deployment pipeline. -
Who can see the plugin pages?
-
Only administrators (users with the
manage_optionscapability). Update Impact also requires permission to update plugins. -
Does it work alongside WP Health Inspector Pro?
-
Yes. If Pro is also installed, Lite goes dormant: it stays listed as active (for WordPress.org update checks) but registers no hooks and uses no resources. Pro handles everything.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“WPHI Diagnostic Suite Lite” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “WPHI Diagnostic Suite Lite” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
3.4.0
- Changed: Blast Radius and Server & PHP now ship a complete basic view; Pro-only depth is described in a static notice rather than shown as locked.
- Changed: Time Bomb Detector ships the SSL expiry check; additional checks are described as Pro features.
- Changed: Deep Autoload Diagnostics shows all findings in full; guided copy-paste cleanup commands are a Pro feature.
- Added: Dashboard now includes a dismissible “Available in Pro” section and a contextual upgrade note based on your own health score.
- Removed: Legacy locked “Pro feature” pages and the per-site teaser statistics they displayed.
- Housekeeping: Removed bundled runtime cache and log artifacts from the plugin package.
3.3.1
- Fixed: Admin notices from other plugins and WordPress core now display correctly on Health Inspector pages (no longer suppressed)
- Fixed: Dismissing a fatal error in the dashboard now redirects correctly back to the dashboard
- Fixed: “Upgrade to Pro” menu entry removed β upgrade information is available in the dashboard
- Fixed: Backup files removed from plugin package
- Fixed: Uninstall routine now correctly cleans up all plugin data and references Lite (not Pro)
- Improved: Textdomain loader registered so the plugin is ready for translation
- Improved: All permission-check messages are now translatable
- Improved: Admin submenu scrollbar CSS now delivered via wp_add_inline_style instead of a raw echo
- Improved: Method names now follow WordPress snake_case conventions throughout
3.3.0
- New: Plugin Abandonment Radar β every installed plugin checked against WordPress.org for last-updated staleness, tested-up-to drift, and closed/removed status; risk-sorted table with 12-hour cache
- New: Mail Health Inspector β transport detection, live SPF/DKIM/DMARC/MX DNS checks, one-click send test with real failure messages
- New: Hosting Benchmark β on-demand DB/PHP/filesystem/loopback probes with letter grades, object-cache detection, and history chart
- Fixed: “What Changed?” and “Update Impact” pages are now correctly registered in the admin menu
- Fixed: Admin styles and scripts now load correctly on every plugin page
- Improved: Admin menu reordered into a clearer, more logical grouping
- Improved: Error log parser rewritten β three-stage matching handles all PHP error formats correctly including uncaught fatals
- Removed: Unused Pro-only module files that were bundled by mistake and never ran
3.1.0
- New: What Changed? β interactive SVG timeline correlating change events to PHP error spikes; two-phase correlation (file-path matching first, temporal proximity fallback); 0β99 correlation scores with plain-English reasoning
- New: Update Impact β before every update, see shared hooks, DB tables, cron jobs, REST routes, and asset footprint for the plugin being updated
- New: Table pagination across all data tables β 10/25/50/100/All page size selector, result counter, and page navigation
- Improved: Dashboard health issue list includes direct links to the relevant module for each issue
- Improved: WP_DEBUG_LOG health check now verifies actual web accessibility of the log file
- Improved: Error log search uses class-based filtering so it composes correctly with pagination
3.0.0
- New: Error Log Aggregation module
- New: Export Report feature
- Improved: PHP requirement raised to 8.0
- Improved: All date output now uses gmdate() for timezone safety
- Improved: AJAX endpoints now verify nonces
- Fixed: Unprefixed global functions renamed with a wphi_ prefix
- Fixed: Database queries use $wpdb->prepare() and esc_like() throughout
2.0.0
- New: Health Score dashboard with animated SVG gauge
- New: Server and PHP Environment module
- New: Complete CSS design system with CSS custom properties
- New: Full mobile responsiveness across all pages
- Improved: Consistent Model/View architecture across all modules
- Fixed: Autoload size query now covers auto in addition to yes, on, auto-on
1.1.0
- Initial structured release with DB Health, Blast Radius, Asset Inspector, Cron Inspector, Autoload Governor, and Time Bomb Detector modules.