
內容簡介
Technical Site Auditor 是一款強大的 WordPress 外掛,能夠對網站進行全面的技術審核。它識別多個類別中的問題,並提供可行的建議,以改善網站的 SEO、性能、安全性和整體健康狀況。
【主要功能】
• 超過 215 項自動檢查,涵蓋 25 個類別
• WooCommerce 專屬審核,包含 45 項檢查
• 一鍵自動修復問題,並提供備份和撤銷功能
• 定期掃描和電子郵件通知
• 安全性審核,包括 SSL/HTTPS 驗證
外掛標籤
開發者團隊
原文外掛簡介
Technical Site Auditor is a powerful WordPress plugin that performs comprehensive technical audits of your website. It identifies issues across multiple categories and provides actionable recommendations to improve your site’s SEO, performance, security, and overall health.
The free version runs over 215 automated checks across 25 categories. The premium version adds WooCommerce auditing (45 store-specific checks), one-click auto-fixes with backups and undo, scheduled scans, and extra modules.
Key Features
Content Analysis
* Thin content detection (Unicode-aware word counting)
* Duplicate title and description checks
* Heading structure validation
* Link density and anchor text analysis
SEO Checks
* Meta title and description optimization
* Open Graph and Twitter Card validation
* Schema.org markup verification
* Robots.txt and XML sitemap analysis
* Canonical URL validation
Performance Optimization
* Image optimization recommendations (WebP/AVIF aware)
* Asset loading analysis (CSS/JS)
* Font loading checks (display parameter, preconnect)
* Database cleanup suggestions
* Server configuration checks (PHP version, compression, HTTP/2)
Security Audits
* SSL/HTTPS verification
* HTTP security header checks (verified via real requests)
* XML-RPC exposure detection
* REST API user enumeration probing
* debug.log exposure detection
* Open registration with elevated default roles
* PHP execution in the uploads directory
* wp-config.php file permissions
Plugin Hygiene
* Detects installed plugins that have been closed or removed from WordPress.org
* Flags plugins abandoned for years or untested with recent WordPress versions
* Reports pending updates and PHP/WordPress requirement conflicts
AI Visibility
* Shows which AI crawlers your robots.txt allows, blocks, or does not mention
* Optional llms.txt generator (see the FAQ for an honest note on this convention)
Email Deliverability
* SPF and DMARC DNS record checks for your domain
Link Analysis
* Broken internal link detection
* External link verification (with retry logic to avoid false positives)
* Redirect chain and loop analysis
* Accessibility checks (labels, alt text, skip links, iframes)
Database Health
* Autoload option monitoring (WordPress 6.6+ aware)
* Post revision cleanup suggestions
* Expired transient detection
* Spam and trash comment detection
Free vs Premium
Free Version
* Unlimited URL scanning
* Over 215 automated checks, including plugin hygiene and AI visibility
* Detailed fix guidance for every issue
* Export issues to CSV
Premium Version
* One-click auto-fix for many issues
* Safe .htaccess auto-fix (security headers, GZIP, caching) with automatic backup, health check and rollback
* One-click undo for file and settings fixes
* Database cleanups with row-level backups: deleted spam, revisions and other rows can be restored for 30 days
* Quick backup and full backup with safe, atomic restore
* Scheduled automated scans
* Email notifications
* WooCommerce auditing (45 store-specific checks, including REST API security)
* Premium modules:
* Redirect Manager
* Meta Title/Description Manager
* Breadcrumbs Generator
Integrations
Technical Site Auditor detects and integrates with popular plugins:
Yoast SEO
Rank Math
All in One SEO
SEOPress
WooCommerce
Elementor
Divi Builder
WPBakery Page Builder
External Services
This plugin connects to the following external services:
WordPress.org API
This plugin uses the official WordPress.org API to check for WordPress core updates and verify core file integrity.
What it does:
* Checks if your WordPress installation is up to date
* Verifies that core WordPress files have not been modified (security check)
Data sent:
* Your WordPress version number
* Your site locale (language setting)
When data is sent:
* Only during a site audit scan, when the “WordPress Updates” or “Core File Integrity” checks are enabled
Service provider: WordPress.org (Automattic)
* Terms of Service
* Privacy Policy
WordPress.org Plugin Directory API
When the Plugin Hygiene check is enabled, the plugin queries the official WordPress.org plugin information API (api.wordpress.org/plugins/info/1.2/) for each installed plugin.
What it does:
* Checks whether installed plugins are still listed in the WordPress.org directory or have been closed
* Checks when each plugin was last updated and which WordPress version it was tested with
* Checks each plugin’s declared minimum PHP and WordPress requirements
Data sent:
* The directory slug (folder name) of each installed plugin. No personal data, site URL, or license information is transmitted.
When data is sent:
* Only during a site audit scan when the Plugin Hygiene check is enabled. Responses are cached locally for up to 24 hours, and at most 30 lookups are performed per scan. Plugins that declare their own update source (Update URI header) are never sent to WordPress.org.
Service provider: WordPress.org (Automattic)
* Terms of Service
* Privacy Policy
Public DNS lookups
When the email deliverability check is enabled, the plugin performs DNS TXT lookups for your own site’s domain (and its _dmarc subdomain) to see whether SPF and DMARC records exist. These are standard public DNS queries made by your server; no data about your site is transmitted beyond the domain name being looked up. The check is skipped entirely for local and development domains.
Outbound link checks
During a scan, the plugin makes HTTP requests to your own site’s pages and, when the external link checker is enabled, to external URLs found in your content in order to verify they still work. No personal user data is ever transmitted.
