Skip to content

CMS

WordPress Website Audit

WordPress audit: cache, builders, and headers nginx actually sets

· Configuration notes, not a newsroom.

How SiteRune fingerprints WordPress, what the WordPress bootcamp playbook contains, and why page builders show up as CMS health — not as a moral failing.

WordPress Website AuditWO

What SiteRune checks on this stack

  • WordPress detection from wp-content, generator, cookies, and optionally /wp-json/ — not a guaranteed plugin census
  • Page-builder footprints (Elementor, Divi, WPBakery, Gutenberg blocks) when they appear in HTML
  • Cache plugins we can see (WP Rocket, LiteSpeed) plus document Cache-Control
  • Yoast / Rank Math / AIOSEO fingerprints when present; we do not replace the SEO plugin
  • xmlrpc.php mentioned in markup; public /wp-json/ as an info finding
  • robots.txt AI-bot policy (Wordfence 'block AI' presets show up here)
  • Security headers at the edge — we will not pretend the theme can set HSTS

Common problems

  • Discourage search engines left on after staging
  • Builder CSS + unused sliders on every template
  • No full-page cache; TTFB is a cold PHP bootstrap
  • Security plugin writes Disallow: / for GPTBot
  • xmlrpc.php still advertised; REST user enumeration open
  • Theme overrides Yoast canonicals or titles

Fingerprint, then dialect

We detect WordPress from wp-content, generator tags, and common plugin fingerprints. WooCommerce is a separate slug when the shop stack is visible. The playbook is written like a senior WP engineer: staging, updates, full-page cache (LiteSpeed or Cloudflare APO), kill unused builders, security headers at nginx, Yoast/Rank Math sitemap + schema, publish llms.txt.

What we ship for WordPress

A mu-plugin snippet for headers when you do not control nginx. We do not ship a replacement llms.txt or robots.txt if the origin file is already stronger. We do not recommend 'install another security plugin' as the first move — headers and cache usually pay faster.

  • Update debt and builder CSS as CMS-health findings, not malware.
  • XML sitemap and schema via the SEO plugin you already run.
  • AI-bot robots policy that does not fight Wordfence's block-AI preset blindly — we report the file.

FAQ

Do you detect every plugin?

No. Detection is fingerprint-based: paths, generator tags, cookies, and HTML signatures. A plugin that leaves no public footprint will not appear. Treat the ecosystem list as clues, not an inventory.

Is this a WordPress security scan or malware check?

No. We review public configuration: headers, cookies, mixed content, version banners, xmlrpc mentions, open REST. We do not log into wp-admin or run exploits.

Will you tell me to install another SEO plugin?

Usually the opposite. Keep Yoast or Rank Math if it already ships titles, schema, and the sitemap. The brief is headers, cache, robots, and interiors.

Run it on a live URL

Same scan engine. Guest scans stay free.

https://