WordPress Service · One-time fixed price

WordPress Audit – Where Your Site Really Stands

Structured site assessment with PDF report and review call. For 290 € net. So you know what's actually pending – before you sign a maintenance contract with us or anyone else.

5–7 page PDF report Risk assessment: critical / high / medium / low 30-minute review call Fully credited toward maintenance contract within 4 weeks
What we check

What a WordPress Audit Is Good For

An audit makes sense in four situations. If you recognize yourself in one of them, here's our honest take: a structured assessment gives you more clarity than half a dozen conversations with providers.

Before You Switch Maintenance Partners

Current provider too expensive, too slow, or gone? We analyze the status before you switch blindly. You see in black and white where your site stands.

After Taking Over a Third-Party Site

Site was built by the last developer who is no longer reachable. Nobody knows what's inside. We document what exists – plugins, themes, custom code.

After a Security Incident

Site was hacked, spammed, or blacklisted. We look at where the weak point was and what the current situation is – before further measures are taken.

Before an Investment Decision

Should the site be relaunched, migrated, or extended? The audit provides the technical basis for your decision – including realistic effort estimates.

What We Specifically Check in the Audit

6 review areas, approximately 4–5 hours of work, a structured PDF report. Here's what's openly included in the price of 290 €:

01

Technical Basics

  • WordPress version, PHP version, server configuration
  • Complete plugin list with versions and update status
  • Active themes including child themes
  • Database size and table overview
  • SSL setup and certificate remaining validity
02

Security Inventory

  • Known vulnerabilities via Patchstack scan
  • Login hardening (2FA, IP limits, brute-force protection)
  • User list with roles and last login dates
  • Malware quick check
  • HTTP security headers
03

Performance Inventory

  • Lighthouse scores for mobile and desktop
  • Core Web Vitals (LCP, CLS, INP)
  • Performance-blocking plugins identified
  • Caching status
  • Image optimization status
04

Backup Status

  • Is there a current backup?
  • Where is it stored?
  • Retention period?
  • Does a restore test work?
05

GDPR Basics

  • Cookie banner present and correct
  • Privacy policy with all tools documented
  • DPAs with external services
  • External fonts, maps, embedded services
06

Recommendations with Effort Estimates

  • Risks by priority (critical / high / medium / low)
  • Concrete recommendations per finding
  • Estimated effort for remediation (in hours at the 100 € hourly rate)
  • Maintenance plan recommendation, if applicable

The audit covers the standard case. For very large or complex sites (multisite with 20+ subsites, WooCommerce with extensive custom code, headless setups), we expand the scope by prior agreement – with transparent additional cost.

What You'll Receive After the Audit

A PDF Report

Structured, readable, with clear priorities. No tech-buzzword bingo, just understandable recommendations. Typical length 5 to 7 pages – compact, not bloated.

The report stays with you. Even if you don't continue with us afterward, you can show it to other providers. We don't hide findings behind paywalls.

A 30-minute Review Call

We go through the report together, answer questions, and prioritize the most important points with you. Via video call, by phone, or on-site – whatever suits you.

If you book our maintenance afterward: great. If not: also fine. We leave the conversation without wagging fingers.

Codeäffchen

WordPress
Audit Report

Example Company Ltd

Sample · not for publication

What an Audit with Us Is Not

Three clarifications, because the term is used unclearly in the market:

Not a penetration test

We check security basics but don't conduct active attack simulations. If you need that – for example for ISO 27001 audits – a specialized pentest firm is the better choice.

Not an SEO audit

We check technical SEO basics (sitemap, robots.txt, Schema.org markup, pagespeed) but not your content strategy, backlink profiles, or keyword performance. SEO specialists exist for that.

Not marketing consulting

We don't say anything about how your site sells better or how you generate leads. We look at whether it's technically clean, secure, and performant – not whether it's commercially successful.

How an Audit With Us Works

1

Request

You write to us via the contact form or call directly. We confirm the appointment in writing, including order and invoice for 290 € net.

2

Provide Access

You set up a time-limited WordPress admin login for us and grant us read access to hosting. We send the access requirements as a checklist.

3

Conduct the Audit

We systematically check the 6 areas. Tobias handles the technical analysis, Daniel handles the strategic assessment and recommendations. Duration: 5 business days.

4

PDF Report

You receive the report by email, with a preview of the key findings in the email body. On the agreed deadline.

5

Review Call

30 minutes via video call, phone, or on-site. We go through the recommendations, answer questions, sort priorities.

Credit Toward Maintenance Contract

If you sign a maintenance contract with us within 4 weeks after the audit, the audit price is fully credited toward the first month. So effectively, you pay nothing for the audit if you come to us anyway.

If you go to another provider after the audit: that's fine too. The report stays with you, the 290 € was your price for clarity.

Frequent Questions About the WordPress Audit

What if the audit shows that our site is a total loss?

Then we say so honestly. Sometimes a site is so badly built that a rebuild is cheaper than rehabilitation. We don't recommend anything that doesn't make economic sense – even if it means fewer maintenance contracts for us. In that case, the report contains a realistic cost-benefit calculation.

Can we also book the audit without a follow-up contract?

Yes, it's actually the common case. Some clients just want to know where they stand without immediately changing anything. Others get the audit as a second opinion on their existing provider. Both are fine.

How long does it take from order to report?

Standard delivery is 5 business days after receiving access. For very large sites or urgent cases, we agree on the date in advance. We'd rather deliver on time than too quickly.

What if we want to implement the recommendations ourselves after the audit?

Wonderful. The report contains a concrete recommendation with effort estimate per finding. You can then decide what to handle internally and what to outsource. We're available for questions – billable at the hourly rate, but without a minimum volume.

Request an Audit?

Briefly tell us which site should be checked and what you particularly care about. We confirm the appointment within one business day. Initial conversation is free, the audit price of 290 € net is transparent and one-time.

Prefer to call directly?

+49 9163 6791505

Mon–Fri, 9 AM – 5 PM CET · Gerhardshofen / Middle Franconia