WordPress Audit – Where Your Site Really Stands
From a free quick check to a full audit with PDF report and review call. So you know what's actually pending – before you sign a maintenance contract with us or anyone else.
Three Tiers, Depending on How Much You Want to Know
The quick check looks from the outside, the audit from the inside. For large or special sites, we agree on the scope in advance.
Quick check
free of charge
- Only needs the URL, no access
- 34 checks, publicly visible data only
- Short PDF report with a traffic light per area and the key findings
- Only for website owners or people they have commissioned
Standard audit
290 € net, each additional site 190 €
- 56 checks in 9 areas, with access to your site
- Collected automatically, reviewed and assessed by us
- PDF report with roadmap and effort estimates
- 30-minute review call
Larger audits
Scope and price by agreement
- Multisite
- WooCommerce with a lot of custom code
- Code review of custom themes and plugins
- Accessibility according to WCAG/BFSG
What a WordPress Audit Is Good For
An audit makes sense in four situations. If you recognize yourself in one of them, here's our honest take: a structured assessment gives you more clarity than half a dozen conversations with providers.
Before You Switch Maintenance Partners
Current provider too expensive, too slow, or gone? We analyze the status before you switch blindly. You see in black and white where your site stands.
After Taking Over a Third-Party Site
Site was built by the last developer who is no longer reachable. Nobody knows what's inside. We document what exists – plugins, themes, custom code.
After a Security Incident
Site was hacked, spammed, or blacklisted and has since been cleaned up? We check where things stand now: known vulnerabilities, access, hardening. This is not a forensic root-cause analysis – an acute hack is a case for our emergency service.
Before an Investment Decision
Should the site be relaunched, migrated, or extended? The audit provides the technical basis for your decision – including realistic effort estimates.
What the Quick Check Covers
34 checks, using publicly visible data only. You give us the URL; nothing on your website is changed. The result is a short PDF report with a traffic light per area and the key findings.
Security from the outside
- Known vulnerabilities in visible plugins, themes and the WordPress version
- Publicly retrievable usernames
- XML-RPC
- Security headers
SSL/TLS
- Certificate
- Redirect to HTTPS
- Outdated TLS versions
Performance
- PageSpeed mobile and desktop
- Core Web Vitals from real visitors (if Google has data)
- Server response time
- Page cache
- Image optimization
Data protection (technical)
- Third parties and cookies before consent
- Consent tool
- Imprint and privacy policy linked
- Embedded services mentioned in the privacy policy
- SPF
- DMARC
Technical SEO
- Indexing, sitemap, robots.txt
- Titles, descriptions, headings
- Broken links and redirect chains
- Unencrypted content
Accessibility
- Automated quick scan
For online shops
- Withdrawal button (mandatory in Germany since 19 June 2026, § 356a BGB)
The quick check only sees what is visible from the outside and doesn't replace an audit. We only run it for website owners or people they have commissioned. Tell us via the contact form which site it is.
What We Specifically Check in the Audit
56 checks in 9 areas, collected automatically and reviewed and assessed by us. Here's what's openly included in the 290 € for the first site – each additional one costs 190 €:
Technical Basics & Inventory
- WordPress and PHP version, including end of security updates
- Complete plugin and theme list with update status
- Maintenance status: no update for over two years, removed from the directory
- Unused and duplicate plugins
- Database size
Security
- Check against a vulnerability database (Wordfence Intelligence)
- Administrator accounts and registration
- Debug mode and file editor
- Exposed files (e.g. backups, .env, logs) and directory listings
- Security headers
With server access, additionally
- Modified core and plugin files
- Malware patterns
- PHP files in the uploads folder
- Hidden administrator accounts
Performance
- PageSpeed mobile and desktop
- Core Web Vitals from real visitors (if Google has data)
- Server response time
- Page cache
- Image optimization
With server access, additionally
- Autoload data
- Scheduled tasks
Infrastructure & Email
- SSL/TLS: certificate and outdated TLS versions
- Redirect to HTTPS
- Hostnames: reachability with and without www
- Email: SPF and DMARC
Backup & Operations
- Is there a current backup – files and database?
- Where is it stored – separate from the hosting?
- Retention period?
- Has a restore ever been tested and documented?
- WordPress Site Health
Data Protection (technical)
- Third parties and cookies before consent
- Consent tool
- External fonts, maps and embedded services
- Imprint and privacy policy linked, embedded services mentioned in it
- DPAs for the embedded services – as stated by you, without reviewing the contracts
Technical SEO
- Indexing, sitemap, robots.txt
- Titles, descriptions, headings
- Broken links and redirect chains
- Unencrypted content
- The crawl covers up to 200 pages
Accessibility (quick scan)
- Automated scan of several pages
- Against the automatically testable part of WCAG 2.2 AA
- Explicitly not a complete review
Shop (with WooCommerce)
- Withdrawal button (mandatory in Germany since 19 June 2026, § 356a BGB)
Recommendations with Effort Estimates
- Risks by priority (critical / high / medium / low)
- Roadmap: now / within 30 days / within 90 days
- Estimated effort in hours at the hourly rate of 120 € net
- Maintenance plan recommendation, if applicable
How deep we check depends on the access
A WordPress admin login covers most of the checks. With SSH/SFTP, we also check files and the database. The report states what was checked with which access and what remained open.
The standard audit covers the usual case. Multisite, WooCommerce with a lot of custom code, a code review of custom themes and plugins, or an accessibility review according to WCAG/BFSG are larger audits – we agree on scope and price with you in advance.
Optional add-on: restore test
In the audit, we find out whether your backup exists and whether a restore has ever been tested. Whether it actually restores only shows in the test: we restore the backup into a test environment and check whether it produces a working site. For that we need access to the backup and the hosting. Billed by effort at the hourly rate of 120 € – we estimate the effort up front once we know your backup solution and hosting. In our WordPress maintenance, the regular restore check is included in every package.
What You'll Receive After the Audit
A PDF Report
Structured, readable, with clear priorities. No tech-buzzword bingo, just understandable recommendations. It opens with a one-page summary, followed by the roadmap and the findings with priority and effort. The details are in the appendix: the inventory of your site and an overview of all checks. In German or English, as you prefer.
The report stays with you. Even if you don't continue with us afterward, you can show it to other providers. We don't hide findings behind paywalls.
A 30-minute Review Call
We go through the report together, answer questions, and prioritize the most important points with you. Via video call, by phone, or on-site – whatever suits you.
If you book our maintenance afterward: great. If not: also fine. We leave the conversation without wagging fingers.
WordPress
Audit Report
Example Company Ltd
Sample · not for publication
What an Audit with Us Is Not
Five clarifications, because the term is used unclearly in the market:
Not a penetration test
We check security basics but don't conduct active attack simulations. If you need that – for example for ISO 27001 audits – a specialized pentest firm is the better choice.
Not an SEO audit
We check technical SEO – indexing, sitemap, titles, links – but not your content strategy, backlink profiles, or keyword performance. SEO specialists exist for that.
Not marketing consulting
We don't say anything about how your site sells better or how you generate leads. We look at whether it's technically clean, secure, and performant – not whether it's commercially successful.
Not an accessibility review under the BFSG
The quick scan only finds barriers that can be detected automatically. A reliable review is a separate audit.
Not legal advice
Statements about data protection and the withdrawal button are technical findings, not a legal assessment.
How an Audit With Us Works
Request
You write to us via the contact form or call directly. We confirm the appointment in writing, including order and invoice – 290 € net for the first site, 190 € for each additional one.
Provide Access
You create a dedicated administrator user for us – please don't share existing accounts. We use it to create an application password. Optional: read-only SSH/SFTP and hosting access. The basis is a data processing agreement. After the audit, we delete or revoke the access and confirm this in writing.
Conduct the Audit
We check the 9 areas, review the results and summarize the findings with assessment, roadmap and effort in the report. Duration: 5 business days.
PDF Report
You receive the report by email, with a preview of the key findings in the email body. On the agreed deadline.
Review Call
30 minutes via video call, phone, or on-site. We go through the recommendations, answer questions, sort priorities.
Credit Toward Maintenance Contract
If you sign a maintenance contract with us within 4 weeks after the audit, we credit the audit price against your first monthly fee – up to that fee's amount. With Basic and Pro the first month is covered; with Premium you pay only the difference.
If you go to another provider after the audit: that's fine too. The report stays with you, the 290 € was your price for clarity.
Frequent Questions About the WordPress Audit
What's the difference between the quick check and the audit?
The quick check only needs your URL and sees what is visible from the outside: 34 checks, a short PDF report with a traffic light per area, free of charge. The audit works with access to your site: 56 checks in 9 areas, collected automatically and reviewed and assessed by us, with a roadmap, effort estimates and a review call. The quick check shows whether a closer look is worthwhile – it doesn't replace an audit.
What access do you need?
For the quick check, none – just the URL. For the audit, a dedicated administrator user in WordPress – please don't share existing accounts. We use it to create an application password. That covers most of the checks. Optionally, you give us read-only SSH/SFTP access and access to your host; then we also check files and the database. The report states what was checked with which access and what remained open.
How do you handle our data?
We only read and change nothing. No plugin is installed on your website. Credentials stay local with us and are deleted after the audit; we delete or revoke the access itself and confirm this to you in writing. The analysis is AI-assisted; user data is only analysed in pseudonymised form. The basis is a data processing agreement.
What if the audit shows that our site is a total loss?
Then we say so honestly. Sometimes a site is so badly built that a rebuild is cheaper than rehabilitation. We don't recommend anything that doesn't make economic sense – even if it means fewer maintenance contracts for us. In that case, the report contains a realistic cost-benefit calculation.
Can we also book the audit without a follow-up contract?
Yes, it's actually the common case. Some clients just want to know where they stand without immediately changing anything. Others get the audit as a second opinion on their existing provider. Both are fine.
How long does it take from order to report?
Standard delivery is 5 business days after receiving access. For very large sites or urgent cases, we agree on the date in advance. We'd rather deliver on time than too quickly.
What if we want to implement the recommendations ourselves after the audit?
Wonderful. The report contains a concrete recommendation with effort estimate per finding. You can then decide what to handle internally and what to outsource. We're available for questions – billable at the hourly rate, but without a minimum volume.
Do you test in the audit whether our backup can be restored?
Not in the base price. We check whether a current backup exists, where it is stored, how long it is retained and whether a restore has ever been tested. If not, it goes into the report as a risk. You can book the restore test itself as an add-on: we restore the backup into a test environment and check whether it produces a working site – billed by effort at the hourly rate of 120 €, with an estimate up front. In our maintenance plans, the regular restore check is included in every package.
Request an Audit?
Briefly tell us which site should be checked and whether you'd like to start with the free quick check or go straight to the audit. We confirm the appointment within one business day. The audit price of 290 € net is transparent and one-time.
Prefer to call directly?
+49 9163 6791505Mon–Fri, 8 AM – 6 PM CET · Gerhardshofen / Middle Franconia