WordPress Service · Free quick check, fixed-price audit

WordPress Audit – Where Your Site Really Stands

From a free quick check to a full audit with PDF report and review call. So you know what's actually pending – before you sign a maintenance contract with us or anyone else.

PDF report in German or English Risk assessment: critical / high / medium / low Roadmap: now / 30 days / 90 days 30-minute review call Credited toward your first monthly fee with a maintenance contract within 4 weeks

Three Tiers, Depending on How Much You Want to Know

The quick check looks from the outside, the audit from the inside. For large or special sites, we agree on the scope in advance.

Quick check

free of charge

  • Only needs the URL, no access
  • 34 checks, publicly visible data only
  • Short PDF report with a traffic light per area and the key findings
  • Only for website owners or people they have commissioned
What the quick check covers →

Standard audit

290 € net, each additional site 190 €

  • 56 checks in 9 areas, with access to your site
  • Collected automatically, reviewed and assessed by us
  • PDF report with roadmap and effort estimates
  • 30-minute review call
What the audit covers →

Larger audits

Scope and price by agreement

  • Multisite
  • WooCommerce with a lot of custom code
  • Code review of custom themes and plugins
  • Accessibility according to WCAG/BFSG

What a WordPress Audit Is Good For

An audit makes sense in four situations. If you recognize yourself in one of them, here's our honest take: a structured assessment gives you more clarity than half a dozen conversations with providers.

Before You Switch Maintenance Partners

Current provider too expensive, too slow, or gone? We analyze the status before you switch blindly. You see in black and white where your site stands.

After Taking Over a Third-Party Site

Site was built by the last developer who is no longer reachable. Nobody knows what's inside. We document what exists – plugins, themes, custom code.

After a Security Incident

Site was hacked, spammed, or blacklisted and has since been cleaned up? We check where things stand now: known vulnerabilities, access, hardening. This is not a forensic root-cause analysis – an acute hack is a case for our emergency service.

Before an Investment Decision

Should the site be relaunched, migrated, or extended? The audit provides the technical basis for your decision – including realistic effort estimates.

What the Quick Check Covers

34 checks, using publicly visible data only. You give us the URL; nothing on your website is changed. The result is a short PDF report with a traffic light per area and the key findings.

Security from the outside

  • Known vulnerabilities in visible plugins, themes and the WordPress version
  • Publicly retrievable usernames
  • XML-RPC
  • Security headers

SSL/TLS

  • Certificate
  • Redirect to HTTPS
  • Outdated TLS versions

Performance

  • PageSpeed mobile and desktop
  • Core Web Vitals from real visitors (if Google has data)
  • Server response time
  • Page cache
  • Image optimization

Data protection (technical)

  • Third parties and cookies before consent
  • Consent tool
  • Imprint and privacy policy linked
  • Embedded services mentioned in the privacy policy

Email

  • SPF
  • DMARC

Technical SEO

  • Indexing, sitemap, robots.txt
  • Titles, descriptions, headings
  • Broken links and redirect chains
  • Unencrypted content

Accessibility

  • Automated quick scan

For online shops

  • Withdrawal button (mandatory in Germany since 19 June 2026, § 356a BGB)

The quick check only sees what is visible from the outside and doesn't replace an audit. We only run it for website owners or people they have commissioned. Tell us via the contact form which site it is.

What We Specifically Check in the Audit

56 checks in 9 areas, collected automatically and reviewed and assessed by us. Here's what's openly included in the 290 € for the first site – each additional one costs 190 €:

01

Technical Basics & Inventory

  • WordPress and PHP version, including end of security updates
  • Complete plugin and theme list with update status
  • Maintenance status: no update for over two years, removed from the directory
  • Unused and duplicate plugins
  • Database size
02

Security

  • Check against a vulnerability database (Wordfence Intelligence)
  • Administrator accounts and registration
  • Debug mode and file editor
  • Exposed files (e.g. backups, .env, logs) and directory listings
  • Security headers

With server access, additionally

  • Modified core and plugin files
  • Malware patterns
  • PHP files in the uploads folder
  • Hidden administrator accounts
03

Performance

  • PageSpeed mobile and desktop
  • Core Web Vitals from real visitors (if Google has data)
  • Server response time
  • Page cache
  • Image optimization

With server access, additionally

  • Autoload data
  • Scheduled tasks
04

Infrastructure & Email

  • SSL/TLS: certificate and outdated TLS versions
  • Redirect to HTTPS
  • Hostnames: reachability with and without www
  • Email: SPF and DMARC
05

Backup & Operations

  • Is there a current backup – files and database?
  • Where is it stored – separate from the hosting?
  • Retention period?
  • Has a restore ever been tested and documented?
  • WordPress Site Health
06

Data Protection (technical)

  • Third parties and cookies before consent
  • Consent tool
  • External fonts, maps and embedded services
  • Imprint and privacy policy linked, embedded services mentioned in it
  • DPAs for the embedded services – as stated by you, without reviewing the contracts
07

Technical SEO

  • Indexing, sitemap, robots.txt
  • Titles, descriptions, headings
  • Broken links and redirect chains
  • Unencrypted content
  • The crawl covers up to 200 pages
08

Accessibility (quick scan)

  • Automated scan of several pages
  • Against the automatically testable part of WCAG 2.2 AA
  • Explicitly not a complete review
09

Shop (with WooCommerce)

  • Withdrawal button (mandatory in Germany since 19 June 2026, § 356a BGB)
10

Recommendations with Effort Estimates

  • Risks by priority (critical / high / medium / low)
  • Roadmap: now / within 30 days / within 90 days
  • Estimated effort in hours at the hourly rate of 120 € net
  • Maintenance plan recommendation, if applicable

How deep we check depends on the access

A WordPress admin login covers most of the checks. With SSH/SFTP, we also check files and the database. The report states what was checked with which access and what remained open.

The standard audit covers the usual case. Multisite, WooCommerce with a lot of custom code, a code review of custom themes and plugins, or an accessibility review according to WCAG/BFSG are larger audits – we agree on scope and price with you in advance.

Optional add-on: restore test

In the audit, we find out whether your backup exists and whether a restore has ever been tested. Whether it actually restores only shows in the test: we restore the backup into a test environment and check whether it produces a working site. For that we need access to the backup and the hosting. Billed by effort at the hourly rate of 120 € – we estimate the effort up front once we know your backup solution and hosting. In our WordPress maintenance, the regular restore check is included in every package.

What You'll Receive After the Audit

A PDF Report

Structured, readable, with clear priorities. No tech-buzzword bingo, just understandable recommendations. It opens with a one-page summary, followed by the roadmap and the findings with priority and effort. The details are in the appendix: the inventory of your site and an overview of all checks. In German or English, as you prefer.

The report stays with you. Even if you don't continue with us afterward, you can show it to other providers. We don't hide findings behind paywalls.

A 30-minute Review Call

We go through the report together, answer questions, and prioritize the most important points with you. Via video call, by phone, or on-site – whatever suits you.

If you book our maintenance afterward: great. If not: also fine. We leave the conversation without wagging fingers.

Codeäffchen

WordPress
Audit Report

Example Company Ltd

Sample · not for publication

What an Audit with Us Is Not

Five clarifications, because the term is used unclearly in the market:

Not a penetration test

We check security basics but don't conduct active attack simulations. If you need that – for example for ISO 27001 audits – a specialized pentest firm is the better choice.

Not an SEO audit

We check technical SEO – indexing, sitemap, titles, links – but not your content strategy, backlink profiles, or keyword performance. SEO specialists exist for that.

Not marketing consulting

We don't say anything about how your site sells better or how you generate leads. We look at whether it's technically clean, secure, and performant – not whether it's commercially successful.

Not an accessibility review under the BFSG

The quick scan only finds barriers that can be detected automatically. A reliable review is a separate audit.

Not legal advice

Statements about data protection and the withdrawal button are technical findings, not a legal assessment.

How an Audit With Us Works

1

Request

You write to us via the contact form or call directly. We confirm the appointment in writing, including order and invoice – 290 € net for the first site, 190 € for each additional one.

2

Provide Access

You create a dedicated administrator user for us – please don't share existing accounts. We use it to create an application password. Optional: read-only SSH/SFTP and hosting access. The basis is a data processing agreement. After the audit, we delete or revoke the access and confirm this in writing.

3

Conduct the Audit

We check the 9 areas, review the results and summarize the findings with assessment, roadmap and effort in the report. Duration: 5 business days.

4

PDF Report

You receive the report by email, with a preview of the key findings in the email body. On the agreed deadline.

5

Review Call

30 minutes via video call, phone, or on-site. We go through the recommendations, answer questions, sort priorities.

Credit Toward Maintenance Contract

If you sign a maintenance contract with us within 4 weeks after the audit, we credit the audit price against your first monthly fee – up to that fee's amount. With Basic and Pro the first month is covered; with Premium you pay only the difference.

If you go to another provider after the audit: that's fine too. The report stays with you, the 290 € was your price for clarity.

Frequent Questions About the WordPress Audit

What's the difference between the quick check and the audit?

The quick check only needs your URL and sees what is visible from the outside: 34 checks, a short PDF report with a traffic light per area, free of charge. The audit works with access to your site: 56 checks in 9 areas, collected automatically and reviewed and assessed by us, with a roadmap, effort estimates and a review call. The quick check shows whether a closer look is worthwhile – it doesn't replace an audit.

What access do you need?

For the quick check, none – just the URL. For the audit, a dedicated administrator user in WordPress – please don't share existing accounts. We use it to create an application password. That covers most of the checks. Optionally, you give us read-only SSH/SFTP access and access to your host; then we also check files and the database. The report states what was checked with which access and what remained open.

How do you handle our data?

We only read and change nothing. No plugin is installed on your website. Credentials stay local with us and are deleted after the audit; we delete or revoke the access itself and confirm this to you in writing. The analysis is AI-assisted; user data is only analysed in pseudonymised form. The basis is a data processing agreement.

What if the audit shows that our site is a total loss?

Then we say so honestly. Sometimes a site is so badly built that a rebuild is cheaper than rehabilitation. We don't recommend anything that doesn't make economic sense – even if it means fewer maintenance contracts for us. In that case, the report contains a realistic cost-benefit calculation.

Can we also book the audit without a follow-up contract?

Yes, it's actually the common case. Some clients just want to know where they stand without immediately changing anything. Others get the audit as a second opinion on their existing provider. Both are fine.

How long does it take from order to report?

Standard delivery is 5 business days after receiving access. For very large sites or urgent cases, we agree on the date in advance. We'd rather deliver on time than too quickly.

What if we want to implement the recommendations ourselves after the audit?

Wonderful. The report contains a concrete recommendation with effort estimate per finding. You can then decide what to handle internally and what to outsource. We're available for questions – billable at the hourly rate, but without a minimum volume.

Do you test in the audit whether our backup can be restored?

Not in the base price. We check whether a current backup exists, where it is stored, how long it is retained and whether a restore has ever been tested. If not, it goes into the report as a risk. You can book the restore test itself as an add-on: we restore the backup into a test environment and check whether it produces a working site – billed by effort at the hourly rate of 120 €, with an estimate up front. In our maintenance plans, the regular restore check is included in every package.

Request an Audit?

Briefly tell us which site should be checked and whether you'd like to start with the free quick check or go straight to the audit. We confirm the appointment within one business day. The audit price of 290 € net is transparent and one-time.

Prefer to call directly?

+49 9163 6791505

Mon–Fri, 8 AM – 6 PM CET · Gerhardshofen / Middle Franconia