Apraksts
Site Security Auditor gives WordPress administrators a practical security review dashboard. See plugin update information, compare plugin and theme files against a trusted snapshot, and understand which settings deserve attention.
Open Tools Security Audit to start. Each section explains what it checks, what the result means, and what to do next. It is designed for routine maintenance and investigating unexpected file changes, without automatically editing your site.
What you can do
- Review plugin updates: see available updates, inactive plugins and missing or stale update information. Open the familiar WordPress update screen to take action.
- Compare files: save a trusted SHA-256 baseline, then identify added, modified and removed code files in plugin and theme directories.
- Return to your latest report: the most recent file check stays visible with its timestamp and file count. Simply opening the dashboard does not start another scan.
- Download a file report: export the latest result as JSON to review with your developer or host.
- Follow a plain-language checklist: review HTTPS configuration, dashboard code editing and WordPress debug display, with links to Site Health and official guidance.
- Use a responsive dashboard: clear sections, keyboard-accessible controls and a scrollable plugin table on small screens.
A useful maintenance routine
- Review available updates and take a backup.
- Confirm your files are trustworthy before saving the first baseline.
- Run a comparison after maintenance or when investigating changes.
- Match changed files to intentional updates or edits.
- Replace the baseline only after reviewing and trusting the current files.
A baseline records the current state; it does not prove that state is clean. Keep independent backups and ask a trusted professional about unexplained changes.
Scope and limitations
New baselines cover PHP, PHP7, PHTML, INC, TWIG, JSON, JS and CSS files inside the configured plugin directory and registered theme directories. WordPress core, uploads, must-use plugins, database content and other file types are excluded. Symbolic links are not followed and cause an incomplete result.
Each run is bounded to 20,000 directory entries, 100 MiB of file data, 8 MiB per file and an approximately 8-second processing budget. Unreadable files or exceeded limits produce an incomplete report. Incomplete scans never replace a baseline or present a partial comparison as complete. Large sites may need a host-level integrity tool. Avoid editing files or running updates during a scan.
This plugin is not a malware scanner, firewall or vulnerability database. It does not repair files, guarantee security, or certify a plugin as safe. An update or legitimate edit can change a file; unchanged files can still contain problems.
Privacy and performance
No account, API key, telemetry or additional remote metadata requests are required. The dashboard uses the update information already maintained by WordPress; WordPress itself may contact its normal update services.
File hashes, relative paths, baseline time and the latest file report are stored in the site’s options, without autoloading them. Reports are restricted to administrators; on multisite they require a network administrator. Downloaded reports contain relative file paths, so share them only with trusted people. Deactivation and deletion preserve these records to avoid silently discarding your trusted reference.
Ekrānuzņēmumi



Uzstādīšana
- Install Site Security Auditor from Plugins Add New, or upload the plugin ZIP.
- Activate the plugin.
- Open Tools Security Audit using an administrator account.
- Read the baseline warning, confirm that you trust the current files, and choose Save trusted baseline.
- Return and select Compare files now to review changes.
On multisite, a network administrator can open the dashboard from a site’s Tools menu. Baselines and reports are stored per site, while plugin and theme files may be shared across the network.
BUJ
-
Does it scan for malware or known vulnerabilities?
-
No. It compares code-file hashes with your own baseline and shows maintenance/configuration checks. Use other appropriate controls and professional advice alongside this tool.
-
When should I replace the baseline?
-
Only after verifying the current files, for example after reviewing an intentional plugin update. Replacing it accepts the current state as the reference and removes the previous comparison point.
-
Why does a plugin say Unknown?
-
WordPress has not supplied current update information for it, or that information is more than two days old. Open WordPress Updates to refresh it. Some premium or custom plugins use separate update systems. Unknown does not mean unsafe or safe.
-
What happens to my existing baseline when I update?
-
Your baseline is retained. Baselines made before 1.4.0 continue comparing their original file types, without JS and CSS. A newly saved trusted baseline includes JS and CSS. Review changes before replacing it.
-
Why is a scan incomplete?
-
The scan reached a resource limit, encountered a symbolic link, could not read a directory/file, or found a file changing during the run. The report explains the issue. Finish updates and ask your host to check permissions; large sites may need another integrity tool.
-
Does it change my security settings automatically?
-
No. It provides guidance and links. Configuration changes can affect hosting or integrations, so review them with your administrator.
-
Can I use this every day?
-
You can manually review the dashboard and compare files whenever useful. There are no scheduled scans or email alerts in this version. The dashboard stores only the latest file report; download reports you need to keep.
Atsauksmes
Par šo spraudni nav atsauksmju.
Autori un izstrādātāji
“Site Security Auditor – Plugin & File Checks” ir atvērtā pirmkoda programmatūra. Šo spraudni ir veidojuši šādi cilvēki.
LīdzdalībniekiTulkot “Site Security Auditor – Plugin & File Checks” savā valodā.
Vai jūs interesē attīstība?
Pārlūkojiet kodu, apmeklējiet SVN krātuvi vai abonējiet attīstības žurnālu, ko izveidojis RSS.
Izmaiņu žurnāls
1.4.0
- New responsive dashboard, guided baseline workflow and actionable security checklist.
- Save the latest file report and download it as JSON.
- Run scans only through authenticated, nonce-protected POST actions.
- Preserve baselines when scans are incomplete; add resource limits and explicit coverage warnings.
- Include JS and CSS in new baselines while preserving legacy comparison scope.
- Use cached WordPress update data instead of per-plugin remote lookups on dashboard views.
- Recognize network-active plugins and restrict multisite access to network administrators.
- Refresh directory branding, documentation, screenshots and release metadata.
1.0
- Initial dashboard for plugin information, file baselines and hardening checks.
