Audit

The complete WordPress site audit.

An audit is not a feeling about whether the site seems fine. It is a list of specific things you look at, in an order, with a definition of what good looks like for each one. This is that list — six areas, and what to do about what you find.

Work through it top to bottom. The order is deliberate: each section is roughly ordered by how much damage the finding does, divided by how long it takes to fix. If you only have twenty minutes, the first item in each section is the one to do.

1. Updates

This is first because it is where real sites actually break and get broken.

Good looks like: nothing pending, nothing abandoned, auto-updates on, PHP in support. The security checklist goes deeper here.

2. Security

Good looks like: the smallest number of admins that works, registration closed or defaulting to Subscriber, file editor off, HTTPS everywhere, backups that have been proven.

3. Database

The least visible section and often the most surprising.

Good looks like: autoload comfortably under a megabyte, expired transients cleared, revisions capped going forward.

Be careful what you delete here

Clearing expired transients is safe — they have already expired. Deleting revisions, post meta or orphaned rows is not reversible, and “orphaned” is sometimes just “used by something the cleanup tool did not know about”. Back up before any bulk deletion, and prefer tools that tell you exactly what they will remove before they remove it.

4. Media

Good looks like: nothing enormous, nothing being downsized in the browser, image sizes you actually use.

5. Accessibility

Most WordPress accessibility problems are content problems, not theme problems, which means you can fix them yourself without touching code.

Good looks like: every meaningful image described, one H1 per page, headings in order, links that make sense read aloud on their own. Checking accessibility in WordPress has the detail.

6. SEO

Good looks like: visible to crawlers, readable URLs, a sitemap submitted, Search Console verified and showing pages indexed.

How often to do this

SiteFull auditQuick check
Personal blogTwice a yearMonthly
Business siteQuarterlyMonthly
Shop or membership siteQuarterlyWeekly
After a redesign or migrationImmediately, all six sections, no exceptions

That last row is the important one. A migration is the single most reliable way to arrive at a site that is blocked from search engines, missing its sitemap, serving mixed content and running a stale plugin — all at once, all invisibly, because everything looks fine from the front page.

Doing it without doing it by hand

Everything above can be checked manually, and it is worth doing manually once so you understand what you are looking at. After that, it is a list of things a computer should check for you, because a list of forty items checked by a human every quarter is a list that gets checked twice and then forgotten.

That is what Guru Site Health is: these six areas, 32 checks, one score, and thirteen of the findings fixable from the dashboard with an Undo on each. It runs entirely on your server and makes no external requests, so running an audit does not mean handing a description of your site to someone else.

Frequently asked questions

What should a WordPress site audit include?

Six areas: updates (core, plugins, themes, PHP), security (user roles, registration, file editor, HTTPS, backups), database (autoload size, expired transients, revisions, orphaned data), media (oversized images, unused files), accessibility (alt text, heading order, contrast, labels) and SEO (crawlability, permalinks, sitemap, titles, Search Console). Anything narrower is a partial audit.

How often should I audit my WordPress site?

A full audit quarterly for a business site and twice a year for a personal blog, with a quick check monthly. Always run a full audit immediately after a migration or redesign — that is when sites most often end up blocked from search engines or missing their sitemap, with no visible symptom.

Can I audit a WordPress site for free?

Yes. Every check listed here can be done by hand through the WordPress admin, your browser’s view-source and Google Search Console, all free. Free plugins such as Query Monitor and Guru Site Health automate most of it. Paid tools mainly save time rather than finding things you could not.

What is the most commonly missed item in a WordPress audit?

Two tie. The “Discourage search engines” checkbox in Settings → Reading, which can hide an entire site from Google with no warning anywhere in the dashboard; and autoload size in the options table, which nothing in WordPress displays and which can quietly reach several megabytes read on every request.

Does auditing a site slow it down or change anything?

Reading does not change anything — a scan only looks. What matters is what you do next. Be careful with any tool that offers bulk database cleanup: clearing expired transients is safe, but deleting revisions, post meta or so-called orphaned rows is not reversible. Back up first and prefer tools that show you exactly what they will remove.

Do I need an agency to audit my WordPress site?

Not for the checks on this page — they are deliberately ones a site owner can do. An agency is worth paying when the findings need work you cannot do yourself, such as rewriting a slow custom theme or untangling a migration gone wrong. Knowing what is wrong first makes that conversation much cheaper.

Find these on your own site in about ten seconds

Guru Site Health runs 32 checks across updates, security, database, media, accessibility and SEO, and gives you one score. Thirteen of the findings can be fixed from the dashboard in one click, and every fix can be undone. It makes no external requests — nothing about your site ever leaves it.

Install it free from WordPress.org

Keep reading