All 85 Checks, Referenced
All 85 checks that run on a connected site, grouped the way the report groups them, and which 54 run from an address alone.
This is every check that runs on a connected site, grouped the way the report groups them. Eighty-five in total: the 54 that run from the address alone, plus the 31 that can only be read from inside the install.
54 or 85: which number applies to your site
| Audit | Checks | What it needs |
|---|---|---|
| From the domain alone | 54 | A web address. No account, no plugin. |
| Connected site | 85 | The Protuno plugin installed and the site connected. |
The extra 31 are the things no outsider can see: which plugins are genuinely active, the real PHP version, what the database is carrying, whether a restore point exists at all.
Why the report shows five categories and the website shows eight
The report groups findings into five categories. Some of the marketing pages group the same checks into eight areas instead. The checks are identical; only the grouping differs. The five below are what you will see in the product.
Security (42 checks)
The ways a site gets taken, and the records that decide whether its mail is trusted.
| 2 core files do not match WordPress 7.1.1 |
| HTTP isn’t redirected to HTTPS |
| Missing HSTS header |
| Missing X-Content-Type-Options: nosniff |
| No clickjacking protection |
| No DMARC record is published |
| No SPF record is published |
| Dashboard file editing is enabled |
| No content security policy |
| The WordPress login form is open to the internet |
| User accounts are listable via the REST API |
| Usernames are exposed via author enumeration |
| Database uses the default ‘wp_’ table prefix |
| No CAA record restricts who can issue certificates |
| WordPress 7.1.1 is named in the homepage source |
| WordPress version is publicly disclosed |
| Admin accounts |
| Certificate hostname coverage |
| Cookie security flags |
| Debug mode |
| Directory listing |
| DMARC policy |
| DMARC reporting |
| File permissions |
| For a DKIM key |
| For exposed debug.log |
| For exposed sensitive files |
| For login links on the homepage |
| For mixed content |
| HTTPS / SSL |
| Plugin files |
| Plugins against the directory |
| Referrer policy |
| Server version disclosure |
| SPF lookup count |
| SSL certificate expiry |
| The certificate chain |
| The public REST index |
| The store’s admin API |
| TLS protocol versions |
| Wp-config.php access |
| XML-RPC |
General (16 checks)
The install itself, its mail delivery, its DNS, and the housekeeping nobody checks.
| Mail is being sent by the web server, not a mail service |
| Default WordPress sample content is still published |
| No site icon (favicon) is set |
| Timezone is set to a fixed UTC offset |
| Admin email |
| DNS TTLs |
| Mail servers |
| Nameservers |
| PHP version |
| Search visibility |
| Site URL consistency |
| The checkout page |
| Where mail is delivered |
| WooCommerce status |
| WordPress version |
| WP-Cron |
Growth (12 checks)
Whether search engines and AI assistants can find the site, and what they are told.
| No canonical tag on the homepage |
| No llms.txt for AI assistants |
| No Open Graph tags on the homepage |
| No SEO plugin active |
| No explicit AI-crawler policy |
| Image alt text |
| Mobile viewport meta |
| Robots.txt crawl rules |
| Site tagline |
| Www and apex addresses |
| Www and apex resolve |
| XML sitemap |
Performance (10 checks)
What the visitor waits for, and what the database is quietly carrying.
| Active plugins |
| Cart and checkout caching |
| Database autoload |
| Database bloat |
| For a page cache |
| For duplicate analytics tags |
| Measuring server response time |
| Persistent object cache |
| Response compression |
| Static-asset caching |
Care (5 checks)
Whether there is a restore point, and whether the scheduled work is still running.
| Backups |
| For unmaintained plugins |
| Inactive plugins |
| Scheduled jobs |
| Spam & trash comments |
What a check does when it cannot tell
A check that cannot reach its answer says so, rather than passing. An unreadable cron array is reported as stopped, never as fine. A domain expiry that neither RDAP nor WHOIS will confirm comes back unknown, never “fine”. Worth knowing before reading a clean result as an all-clear.
Where to go next
- Read your site report, for what to do with the findings these produce.
Comments