WebDiagnosis Site Audit

Descripción

Find what’s actually wrong with your WordPress site, and know exactly what to fix.

WebDiagnosis Site Audit is the WordPress audit that tells you what to fix, not just another score or generic list of recommendations.

Run 170+ automated checks across 14 critical areas including SEO, security, performance, accessibility, WordPress configuration, eco-design, and more.

Every finding tells you what was detected, why it matters, how urgent it is, and how to fix it.

Stop auditing. Start fixing.

Most audit tools give you a score and leave you to figure out what it means.

WebDiagnosis turns 170+ checks into a clear, prioritized action plan.

  • 170+ checks across 14 themes
  • Clear severity: Blocker, Major, Minor
  • No false alarms: unverified checks are reported as “Not verifiable”
  • Actionable findings: every issue includes its impact and recommended fix
  • Practical guidance: know what needs to change, who can do it, and how difficult it is

Built to be trusted

A score can tell you that something is wrong. A diagnosis tells you what to do next.

WebDiagnosis never guesses when the required data cannot be verified, and never turns a minor recommendation into an emergency.

The result: less time interpreting reports, more time fixing what actually matters.

One plugin. A complete website diagnosis.

Audit the dimensions that matter to modern WordPress websites:

  • SEO & technical SEO
  • Security
  • Performance & Core Web Vitals
  • Accessibility
  • WordPress configuration
  • Eco-design & sustainability
  • And more

Know what matters. Fix what matters.

Other audit tools tell you how your website scores.
WebDiagnosis tells you what’s wrong and what to fix first.

External Services

This plugin connects to an external service to perform website diagnostics.

The plugin sends technical data about the site, never its posts, pages, comments or user
accounts. This data is sent only once you have accepted data sharing, and you can withdraw that
consent at any time from the plugin settings. Every request the plugin makes is listed below,
including the few it makes on its own.

Service name: WebDiagnosis
Service URL: https://webdiagnosis.io

What the service is used for:
The service analyzes the WordPress website configuration and provides a diagnostic report with recommendations about performance, security and best practices.

What data is sent when a diagnostic runs:

  • Site URL, WordPress version, language and main WordPress settings (debug mode, permalinks, file editing, automatic updates, XML-RPC)
  • Server details: PHP and MySQL versions, PHP limits, disk space, database size, caching, cron and file permissions
  • Installed plugins and themes, with their versions and update status
  • Security settings: whether the security keys are set, whether an account named “admin” exists and its role (never its password or email address)
  • The latest entries of the PHP error log: error type, message, line, and file path relative to the site root
  • Names, sizes and paths of sensitive files found under the site root (backups, database dumps, private keys). Their content is never read nor sent
  • Findings of a scan of the active theme’s code: file path, line and a short code excerpt for each finding
  • Content statistics: number of images with or without alternative text, menu locations, presence of the default sample content
  • How the diagnostic was started: from the plugin interface, the WP-CLI command, the REST endpoints or the Abilities API. The service uses it only for its usage statistics

When data is sent:

  • When a diagnostic is explicitly requested: from the plugin interface, from the WP-CLI command, or through the plugin’s authenticated REST endpoints or the WordPress Abilities API.
  • When a fatal PHP error occurs on the site, and only if data sharing is accepted: the error type and message, its file path relative to the site root, its line, the page URL, the time, and the PHP and WordPress versions, so that the site owner can be alerted. Errors that could not be sent at once are retried every hour.
  • Once a day, and only if you have linked the plugin to a WebDiagnosis account with a subscription key: the site URL and that key, to keep the account status shown in the plugin up to date.
  • When you request help from an expert or send feedback from the plugin: your name, your email address and your message, so that the WebDiagnosis team can answer you.
  • When you accept data sharing, deactivate, reactivate or delete the plugin, and only if data sharing is accepted: the site URL, the plugin version and the event, so that the service knows whether the plugin is still in use.

Links to the service:
* Privacy policy: https://webdiagnosis.io/privacy-policy/
* Terms of service: https://webdiagnosis.io/terms-of-service/

Capturas

Instalación

  1. Download and install WebDiagnosis Site Audit from the WordPress plugins directory.
  2. Activate the plugin through the Plugins screen in WordPress.
  3. Go to Site Audit in the WordPress admin menu to run your first diagnostic.

Preguntas frecuentes

Does this plugin slow down my site?

No. Diagnostics only run when you trigger them. The plugin adds no frontend scripts and does not affect your visitors’ page load times.

What data is collected?

The diagnostic uses technical data such as your WordPress and PHP versions, active plugins, theme information, and server configuration. No personal data or site content is transmitted.

Do I need a WebDiagnosis account?

No. The plugin works standalone, with free diagnostics at regular intervals. A WebDiagnosis account unlocks multi-page analysis, unlimited diagnostics, history, and monitoring.

Why does a check sometimes say “Not verifiable”?

Because WebDiagnosis doesn’t guess. If a check cannot access the data it needs, it reports “Not verifiable” instead of raising a potentially false issue.

Is this plugin affiliated with WordPress?

No. WebDiagnosis Site Audit is an independent plugin developed by WebDiagnosis. It is not affiliated with, endorsed by, or sponsored by WordPress, the WordPress Foundation, or Automattic.

Reseñas

1 de octubre de 2026
I tested WebDiagnosis on a few WordPress sites currently under construction. It quickly flagged useful points on security (such as the built-in file editor still enabled or XML-RPC left active), which helped me secure these sites before going live, as well as on accessibility, performance and SEO. I encourage you to give it a try: having a dashboard built into WordPress to quickly check your site is a real time saver. Limitation: the current free version is limited to one audit per day. The support is responsive and genuinely listens to user feedback. Looking forward to seeing how this plugin evolves!French version : Un plugin d'audit qualité prometteur avec un support réactif J'ai testé WebDiagnosis sur quelques sites WordPress en cours de construction. Il a rapidement remonté des points utiles en matière de sécurité (comme l'éditeur de fichiers intégré encore activé ou XML-RPC resté actif), ce qui m'a permis de sécuriser ces sites avant leur mise en ligne, mais aussi en matière d'accessibilité, de performances et de SEO. Je vous invite à le tester : avoir un dashboard intégré à WordPress pour vérifier rapidement son site fait gagner du temps. Limitation : la version gratuite actuelle est limitée à un audit par jour. Le support est réactif et à l'écoute des retours des utilisateurs. Hâte de voir la suite du développement de ce plugin !
Leer toda la 1 reseña

Colaboradores y desarrolladores

Este software es de código abierto. Las siguientes personas han contribuido a este plugin.

Colaboradores

Traduce “WebDiagnosis Site Audit” a tu idioma.

¿Interesado en el desarrollo?

Revisa el código, echa un vistazo al repositorio SVN o suscríbete al registro de desarrollo por RSS.

Registro de cambios

1.3.1

  • Free diagnostics can now be run far more often: the WebDiagnosis service sets the waiting time between two of them (one hour to start with) and a maximum per 24 hours (five to start with), instead of one per day
  • When the free quota is reached, the plugin shows the exact time of the next possible diagnostic, and says when the 24-hour maximum is the reason, instead of announcing it for tomorrow
  • The update banner no longer offers an older version than the one installed, and its layout matches the other banners of the page
  • Deleting the plugin now removes all of its settings, including the automated-access log and settings, which were left behind
  • When data sharing is accepted, the plugin tells the WebDiagnosis service when it is deactivated, reactivated or deleted, and when data sharing is accepted. The External Services section lists it
  • The External Services section now also lists the two requests the plugin makes on its own: fatal error reports and the daily account status check
  • Each diagnostic request now tells the WebDiagnosis service how it was started (plugin interface, WP-CLI, REST endpoints or Abilities API), for the usage statistics of the service. The External Services section lists it

1.3.0

  • New security checks: an exposed Git or Subversion repository, a readable .env or credentials file, a forgotten phpinfo page, and backups, database dumps or private keys left downloadable under the site root
  • New check on the PHP error log: warnings and fatal errors repeating on every page load are now reported, with the file and the line
  • New check on the theme: content IDs written directly in templates that point to a page or post since deleted
  • Several tests improved and wording fixed in the summary and in the report
  • WP-CLI: output and help are now in English by default, with a new --lang=fr option
  • The follow-up token received from the WebDiagnosis service is now checked before use
  • The External Services section of this readme now lists all the data sent and when

1.2.0

  • Added an optional automated-access surface (REST route, WP-CLI command, WordPress Abilities API) so an AI agent or an integration pipeline can request an audit
  • The .htaccess check now sends only a yes/no verdict, never the file’s content
  • Settings are now split into tabs, and data sharing can be accepted from there without having to run a diagnostic first
  • Fixed two diagnostic status messages that were not translatable

1.1.0

  • Fixed and improved several checks
  • Restored 56 checks that were silently skipped
  • Fixed how translatable strings are handled, so the plugin can be translated into any language
  • Strengthened the checks run before a release is published

1.0.0

  • Initial public release
  • 14 diagnostic themes, 170+ checks
  • Structured data validated against search engine requirements
  • Plain-language explanation and fix for every finding
  • Bilingual interface (English/French)
  • Expert assistance request and feedback form
  • Optional connected mode with the WebDiagnosis platform