Audit
The complete WordPress site audit.
An audit is not a feeling about whether the site seems fine. It is a list of specific things you look at, in an order, with a definition of what good looks like for each one. This is that list — six areas, and what to do about what you find.
Work through it top to bottom. The order is deliberate: each section is roughly ordered by how much damage the finding does, divided by how long it takes to fix. If you only have twenty minutes, the first item in each section is the one to do.
1. Updates
This is first because it is where real sites actually break and get broken.
- Is WordPress core up to date? Dashboard → Updates. Minor releases are mostly security fixes and should never be behind.
- Are any plugins out of date? Each one is a published list of what is wrong with your site, because the changelog that describes the fix also describes the flaw.
- Are any themes out of date? Including the ones you are not using.
- Is anything installed that has been closed or abandoned? A plugin removed from the WordPress directory, or with no update in three years, will not be fixed when something is found in it.
- Are automatic updates on? For plugins and themes at minimum.
- Is PHP current? Running an unsupported PHP version means security fixes stopped arriving. Your host’s control panel will tell you, and usually let you change it.
Good looks like: nothing pending, nothing abandoned, auto-updates on, PHP in support. The security checklist goes deeper here.
2. Security
- Who has an administrator account? Read the whole Users list. Look for people who left, agencies you no longer use, and anyone you do not recognise.
- Is registration open, and what does a new user become? Settings → General. If “Anyone can register” is ticked and the default role is anything above Subscriber, anyone on the internet can create an account with real power.
- Is the file editor enabled? Tools → Theme File Editor. It turns admin access into arbitrary code execution, and a typo into a white screen.
- Is your WordPress version in the page source? It does not make you vulnerable, it makes you easy to find with a scanner.
- Is XML-RPC open and unused? An interface with no legitimate traffic is pure surface area.
- Is the whole site on HTTPS? Both addresses in Settings → General.
- Do you have off-site backups you have actually restored once? An untested backup is a belief.
Good looks like: the smallest number of admins that works, registration closed or defaulting to Subscriber, file editor off, HTTPS everywhere, backups that have been proven.
3. Database
The least visible section and often the most surprising.
- How large is your autoload? Every option marked to autoload is read on every single request. A few hundred kilobytes is healthy; several megabytes is a tax on every page view. Autoloaded options covers this properly.
- How many expired transients are sitting in the options table? WordPress expires them lazily, so abandoned ones never get cleared.
- How many post revisions do you have? Uncapped by default, kept forever.
- How much orphaned post meta is there? Rows belonging to posts that no longer exist, usually left by a plugin that was removed.
- Is there leftover data from plugins you deleted? Deleting a plugin does not oblige it to clean up after itself, and many do not.
Good looks like: autoload comfortably under a megabyte, expired transients cleared, revisions capped going forward.
Clearing expired transients is safe — they have already expired. Deleting revisions, post meta or orphaned rows is not reversible, and “orphaned” is sometimes just “used by something the cleanup tool did not know about”. Back up before any bulk deletion, and prefer tools that tell you exactly what they will remove before they remove it.
4. Media
- Are any images absurdly large? Anything over about 500KB deserves a question.
- Are images being served at the size they are displayed? A 4000px photo shown at 800px wastes most of what it downloads.
- Are there unattached files? Uploads not used in any post. Usually harmless, occasionally a lot of disk.
- Are thumbnails being generated? If a plugin or theme has registered twenty image sizes, every upload becomes twenty files.
Good looks like: nothing enormous, nothing being downsized in the browser, image sizes you actually use.
5. Accessibility
Most WordPress accessibility problems are content problems, not theme problems, which means you can fix them yourself without touching code.
- Do your images have alt text? The most common accessibility failure on the web, and the easiest to fix. It also happens to help image search.
- Does each page have exactly one H1? And do the headings below it descend in order, without skipping from H2 to H4 because H4 looked the right size?
- Do links say what they go to? “Read more” eleven times on a page is useless to someone navigating by link list.
- Is there a language set on the page? Screen readers use it to choose pronunciation.
- Does text have enough contrast against its background? 4.5:1 for normal text.
- Do form fields have real labels? Placeholder text is not a label — it disappears when you start typing.
Good looks like: every meaningful image described, one H1 per page, headings in order, links that make sense read aloud on their own. Checking accessibility in WordPress has the detail.
6. SEO
- Can search engines see the site at all? Settings → Reading. This single checkbox can hide everything. It is worth its own article, because of how often it is the whole answer.
- Are your permalinks readable? If URLs look like
?p=123, change it now, before more of them get indexed. - Do you have a sitemap? WordPress has had one built in since 5.5 at
/wp-sitemap.xml. - Does every page have a title and a meta description? And are they different from each other?
- Is the site in Google Search Console? If not, you are guessing about everything else in this section.
- Are there pages returning errors? Search Console will tell you.
Good looks like: visible to crawlers, readable URLs, a sitemap submitted, Search Console verified and showing pages indexed.
How often to do this
| Site | Full audit | Quick check |
|---|---|---|
| Personal blog | Twice a year | Monthly |
| Business site | Quarterly | Monthly |
| Shop or membership site | Quarterly | Weekly |
| After a redesign or migration | Immediately, all six sections, no exceptions | |
That last row is the important one. A migration is the single most reliable way to arrive at a site that is blocked from search engines, missing its sitemap, serving mixed content and running a stale plugin — all at once, all invisibly, because everything looks fine from the front page.
Doing it without doing it by hand
Everything above can be checked manually, and it is worth doing manually once so you understand what you are looking at. After that, it is a list of things a computer should check for you, because a list of forty items checked by a human every quarter is a list that gets checked twice and then forgotten.
That is what Guru Site Health is: these six areas, 32 checks, one score, and thirteen of the findings fixable from the dashboard with an Undo on each. It runs entirely on your server and makes no external requests, so running an audit does not mean handing a description of your site to someone else.
Frequently asked questions
What should a WordPress site audit include?
Six areas: updates (core, plugins, themes, PHP), security (user roles, registration, file editor, HTTPS, backups), database (autoload size, expired transients, revisions, orphaned data), media (oversized images, unused files), accessibility (alt text, heading order, contrast, labels) and SEO (crawlability, permalinks, sitemap, titles, Search Console). Anything narrower is a partial audit.
How often should I audit my WordPress site?
A full audit quarterly for a business site and twice a year for a personal blog, with a quick check monthly. Always run a full audit immediately after a migration or redesign — that is when sites most often end up blocked from search engines or missing their sitemap, with no visible symptom.
Can I audit a WordPress site for free?
Yes. Every check listed here can be done by hand through the WordPress admin, your browser’s view-source and Google Search Console, all free. Free plugins such as Query Monitor and Guru Site Health automate most of it. Paid tools mainly save time rather than finding things you could not.
What is the most commonly missed item in a WordPress audit?
Two tie. The “Discourage search engines” checkbox in Settings → Reading, which can hide an entire site from Google with no warning anywhere in the dashboard; and autoload size in the options table, which nothing in WordPress displays and which can quietly reach several megabytes read on every request.
Does auditing a site slow it down or change anything?
Reading does not change anything — a scan only looks. What matters is what you do next. Be careful with any tool that offers bulk database cleanup: clearing expired transients is safe, but deleting revisions, post meta or so-called orphaned rows is not reversible. Back up first and prefer tools that show you exactly what they will remove.
Do I need an agency to audit my WordPress site?
Not for the checks on this page — they are deliberately ones a site owner can do. An agency is worth paying when the findings need work you cannot do yourself, such as rewriting a slow custom theme or untangling a migration gone wrong. Knowing what is wrong first makes that conversation much cheaper.
Find these on your own site in about ten seconds
Guru Site Health runs 32 checks across updates, security, database, media, accessibility and SEO, and gives you one score. Thirteen of the findings can be fixed from the dashboard in one click, and every fix can be undone. It makes no external requests — nothing about your site ever leaves it.