Free instant check, then the written report

WordPress Site Audit: Patch Backlog, Exposure and Load Timings

Run the free WordPress site audit above and the surface findings come back immediately: versions, exposure, response time and indexation. The written audit goes inside the site, ranks every finding by what it is costing you, and is the $149 one-time audit in our add-ons rather than a quote.

Worldwide service, remote. No long-term contracts.

Get a free site audit See what it costs

30-day money-back guarantee · No setup fee · Cancel anytime

Get a free written site audit

Send the address and we return a written report inside one working day: patch backlog, exposure, load timings, restore status.

Written report within one working day · No obligation · We never sell your details

  • The instant check is genuinely free and returns while you wait
  • The written audit is assessed by hand, not scored out of 100 by a script
  • Every finding carries a consequence, an effort estimate and a rank
  • Read-only access throughout - nothing on your site is changed
written site assessment covering patches and exposure
The path this interrupts: a grader scores the page then findings carry no value then the list is sorted by severity then nothing gets actioned.

What this covers

  • Security posture: users, roles, file permissions, exposed endpoints, known vulnerable versions
  • Update debt: how far behind core, plugins and themes are, and what breaks if it is all caught up at once
  • Backup and recovery: whether a restore has ever actually been proven to work
  • Plugin and theme inventory: abandoned, duplicated, and paid for but unused
  • Performance: field data, server response time and the slowest queries
  • Technical SEO foundations: indexation, crawl waste, redirect chains, structured data
  • Customisation risk: work sitting in the theme, hard-coded credentials, edited core
  • Hardening recommendations, ranked, with what each one costs to apply
1,000+ WordPress sites built
500+ hacked sites recovered
150+ malware removals
100+ sites under management
50+ popular plugins mastered
10+ years on one platform

What a score out of 100 cannot tell you

Automated site graders are useful and they answer a question nobody actually has. They tell you how a page compares against a general standard. What an owner needs to know is which of these things will cost me money, and in what order.

A grader cannot rank findings because it cannot see value. It does not know that the page it flagged is your highest-converting one, or that the plugin it called critical is deactivated, or that the two-second response it measured happens only on the pages where people buy. It marks a missing image dimension and a publicly exposed admin endpoint with the same shade of red, and it has no way to tell you that fixing the first takes ten minutes while the second changes who can reach your site.

The instant check on this page is honest about being that kind of tool. It reads the outside of a site quickly and tells you what it found, which is genuinely useful and is where most people should start. What it cannot do is weigh anything, and weighing is the part that turns a list into a decision.

The findings that repeat

Across sites arriving from elsewhere, the same handful accounts for most of the risk, and almost none of it is exotic.

  • Update debt measured in years, not weeks. The site was left alone because updating felt risky, which made updating riskier, which is the loop. Breaking it is what a staged update cycle is for.
  • Backups that have never been restored. Present, scheduled, and unproven – often failing quietly for months into an inbox nobody reads. The test, not the schedule, is the thing that matters, and it is why off-site backups are quoted with a quarterly restore.
  • Plugins doing nothing. A typical inventory carries several installed for a single feature, one duplicate of something the theme already does, and at least one paid licence that lapsed.
  • Customisation in the theme. Functionality written into a theme that will be replaced one day, so replacing it silently removes features nobody documented.
  • Administrator accounts belonging to nobody. A developer from two agencies ago, a plugin’s support login, a shared account with a password sitting in a breach list.

None of these is difficult on its own. What makes them dangerous is that each one hides the next, and a site carrying all five has no safe place to start. Establishing that order is most of what you are paying for.

Reading the report as a decision

The report is written to be acted on by someone who is not going to do the work personally. Every finding states the observation, the evidence behind it, the consequence of leaving it, the effort to resolve it, and what it depends on.

That shape means it works as a brief. Hand it to your existing developer and it is a scope of work with the arguing already done. Hand it to a second supplier and it is a like-for-like quote request, which is the only honest way to compare two of them. Keep it in-house and it is a backlog already in priority order. It is also the document to read before deciding whether this belongs with your host or with a specialist at all – host support against a maintenance specialist sets out where the line usually falls.

Where the answer is that the site needs ongoing attention rather than a project, the work continues as WordPress maintenance and the report becomes the first month’s plan; plans and pricing sets out what each cadence covers. Where one finding dominates, it goes to whichever service owns it – security hardening or Core Web Vitals work. And where the finding is that a compromise is already present, the audit stops and malware removal starts, because assessing a site while somebody else still has access to it produces a report about their work rather than yours.

How the work runs

  1. Run the instant checkEnter the address above. It reads what is visible from outside - server headers, exposed versions, response time, indexation - and returns the findings on the spot. No call, no wait.
  2. Read-only access for the written auditAn admin account scoped to reading, plus a copy of the database. Nothing on the live site is modified at any point.
  3. Collect what a script canVersions, known vulnerabilities, query logs, field data and crawl data are gathered first, because nobody should pay a person to list what a tool can list.
  4. Assess by handThe part that cannot be automated: whether a finding matters on this site, what depends on it, and what breaks if it is fixed carelessly. A vulnerable plugin nothing calls is a different problem from the same plugin in a checkout.
  5. Rank by consequence, not by severity labelFindings are ordered by what they are costing now. A critical rating on a page nobody visits sits below a slow checkout, and a report that says otherwise is sorted on the wrong column.

Plans that include this

  • Starter$39/monthor $390 a year — two months freeBlogs, portfolios and brochure sites
    • UpdatesMonthly
    • BackupsWeekly, 30-day retention
    • Uptime5-minute checks
    • Malware removalNot included
    See what is includedKept current and backed up.
  • Business$149/monthor $1490 a year — two months freeStores, membership sites, anywhere downtime costs money
    • UpdatesWeekly, tested on staging first
    • BackupsDaily, 90-day, multi-location
    • Uptime1-minute + 2-hour restore
    • Malware removalIncluded
    See what is includedEverything, including unlimited hack recovery.

The service that covers this

managed wordpress hosting vs maintenance service

Decide whether managed WordPress hosting already covers you or leaves a gap. Hosts patch the server stack and often core. What they exclude is plugins, themes,…

Related pages

Questions people ask before calling

How is the written audit different from the free check above?

The free check reads what is visible from outside: headers, versions, response time, indexation. The written audit reads the inside - the database, the plugin inventory, the query log and whatever someone left in the theme.

What does the written audit cost?

It is the one-time WordPress audit in our add-ons at $149, covering the report and the hardening recommendations. Anything outside that scope is quoted before we start rather than added afterwards.

Do I have to buy a plan afterwards?

No. The report is the deliverable. A good number of them go straight to an in-house developer or to the agency already looking after the site.

Will you change anything on my site?

Nothing. Access is read-only for the whole engagement. If we find something actively dangerous we tell you the same day rather than fixing it uninvited.

What if the report says the site is fine?

Then it says so, and knowing that is worth owning. It happens more often on small, simple sites than people expect - the sites in trouble are usually the ones that have been added to for years.