Skip to content

WordPress website & SEO

WordPress Website & SEO Audit

SiteRune fingerprints WordPress from public HTML and headers, then writes the week in that dialect: staging, updates, full-page cache, headers at nginx (or a mu-plugin), the SEO plugin you already run, and an honest robots.txt.

https://

No card. Three guest scans, then an account.

WordPress-specific surface

  • WordPress detection: /wp-content/, /wp-includes/, generator, cookies, optional /wp-json/
  • Builder footprints when they leak into HTML (Elementor, Divi, WPBakery, Gutenberg)
  • Cache fingerprints (WP Rocket, LiteSpeed) plus the actual Cache-Control on the document
  • SEO plugin fingerprints (Yoast, Rank Math, AIOSEO) — we observe, we do not replace
  • robots.txt, including security-plugin 'block AI' presets
  • Sitemap via the SEO plugin or core — we fetch what robots.txt names
  • Canonical and title output (theme vs SEO plugin fights)
  • xmlrpc.php advertised in markup; public REST as an info finding
  • Security headers the theme cannot set
  • Version banners in generator tags — configuration leak, not a CVE exploit

Common WordPress SEO problems we see

Settings → Reading → Discourage search engines

Homepage noindex. Critical. Teams ship it from staging about once a year.

Theme wins over Yoast

Empty canonical or a title rewrite in header.php. Fix wp_head, do not hack a second title tag.

Wordfence block-AI robots

AEO chapter reports the file. That is a product decision, not a default anyone meant.

What we ship for WordPress

  1. A mu-plugin snippet for headers when you do not control nginx.
  2. Playbook order: staging + backups, updates, full-page cache, kill unused builders, headers, keep Yoast/Rank Math for sitemap + schema, publish llms.txt.
  3. We do not replace a stronger origin llms.txt or robots.txt with our template.

Accuracy limits

  • Plugin and theme detection is fingerprint-based. Packed or renamed plugins may be invisible.
  • We skip wp-admin, wp-login, cart, and checkout on purpose.
  • This is not a malware scanner and not a pentest of PHP.

Questions

Is this a WordPress SEO checker?

Yes — on-site and technical. It will not do keyword research or tell you to buy backlinks.

How is this different from /for/wordpress?

This page is the transactional audit. /for/wordpress is the longer CMS note (cache, builders, headers nginx actually sets). Same engine.

Scan a live URL

Same engine as the rest of SiteRune. Guest scans stay free.

https://