Protuno Workspace

All 85 Checks, Referenced

All 85 checks that run on a connected site, grouped the way the report groups them, and which 54 run from an address alone.

Protuno Editorial Team·4 min read

This is every check that runs on a connected site, grouped the way the report groups them. Eighty-five in total: the 54 that run from the address alone, plus the 31 that can only be read from inside the install.

54 or 85: which number applies to your site

Audit Checks What it needs
From the domain alone 54 A web address. No account, no plugin.
Connected site 85 The Protuno plugin installed and the site connected.

The extra 31 are the things no outsider can see: which plugins are genuinely active, the real PHP version, what the database is carrying, whether a restore point exists at all.

Why the report shows five categories and the website shows eight

The report groups findings into five categories. Some of the marketing pages group the same checks into eight areas instead. The checks are identical; only the grouping differs. The five below are what you will see in the product.

Security (42 checks)

The ways a site gets taken, and the records that decide whether its mail is trusted.

2 core files do not match WordPress 7.1.1
HTTP isn’t redirected to HTTPS
Missing HSTS header
Missing X-Content-Type-Options: nosniff
No clickjacking protection
No DMARC record is published
No SPF record is published
Dashboard file editing is enabled
No content security policy
The WordPress login form is open to the internet
User accounts are listable via the REST API
Usernames are exposed via author enumeration
Database uses the default ‘wp_’ table prefix
No CAA record restricts who can issue certificates
WordPress 7.1.1 is named in the homepage source
WordPress version is publicly disclosed
Admin accounts
Certificate hostname coverage
Cookie security flags
Debug mode
Directory listing
DMARC policy
DMARC reporting
File permissions
For a DKIM key
For exposed debug.log
For exposed sensitive files
For login links on the homepage
For mixed content
HTTPS / SSL
Plugin files
Plugins against the directory
Referrer policy
Server version disclosure
SPF lookup count
SSL certificate expiry
The certificate chain
The public REST index
The store’s admin API
TLS protocol versions
Wp-config.php access
XML-RPC

General (16 checks)

The install itself, its mail delivery, its DNS, and the housekeeping nobody checks.

Mail is being sent by the web server, not a mail service
Default WordPress sample content is still published
No site icon (favicon) is set
Timezone is set to a fixed UTC offset
Admin email
DNS TTLs
Mail servers
Nameservers
PHP version
Search visibility
Site URL consistency
The checkout page
Where mail is delivered
WooCommerce status
WordPress version
WP-Cron

Growth (12 checks)

Whether search engines and AI assistants can find the site, and what they are told.

No canonical tag on the homepage
No llms.txt for AI assistants
No Open Graph tags on the homepage
No SEO plugin active
No explicit AI-crawler policy
Image alt text
Mobile viewport meta
Robots.txt crawl rules
Site tagline
Www and apex addresses
Www and apex resolve
XML sitemap

Performance (10 checks)

What the visitor waits for, and what the database is quietly carrying.

Active plugins
Cart and checkout caching
Database autoload
Database bloat
For a page cache
For duplicate analytics tags
Measuring server response time
Persistent object cache
Response compression
Static-asset caching

Care (5 checks)

Whether there is a restore point, and whether the scheduled work is still running.

Backups
For unmaintained plugins
Inactive plugins
Scheduled jobs
Spam & trash comments

What a check does when it cannot tell

A check that cannot reach its answer says so, rather than passing. An unreadable cron array is reported as stopped, never as fine. A domain expiry that neither RDAP nor WHOIS will confirm comes back unknown, never “fine”. Worth knowing before reading a clean result as an all-clear.

Where to go next

Comments