WordPress site check, no login required

WordPress site check, no login required

5.00/5 - (17 votes)
7 min read
Guide
500+ WP projects

The tool below fetches the public version of one address and tells you what follows from it. It does not sign in, it does not scan your network, and it does not guess. It reads what your visitor’s browser reads: the status code after redirects, the headers, the HTML, and the assets that HTML tells the browser to fetch before it can paint anything. Those assets it actually downloads and weighs, rather than estimating them.

Site check

See what your site shows in public

Give us the address of a site you run. We fetch it the way a browser would and show what follows from it, together with exactly what we read.

What we check

Response headers, time to first byte, title and description, the canonical address, content headings, structured data, images, robots.txt and the sitemap, and on WordPress also what the page source reveals about installed plugins. We also fetch the assets that block the first render and add up what they actually weigh.

What we did not check

  • the admin area and anything behind a login
  • the database, its size and its state
  • backups, whether they exist and whether they restore
  • plugin versions against a vulnerability database
  • how the site behaves for a logged-in user
  • any page other than the single address you gave us

We fetch public pages at the address you give us, we never log in, and we store nothing beyond an anonymous counter of runs.

What the check actually measures

The first layer is our own HTTP requests from a Cloudflare edge: time to first byte, the status code once redirects have resolved, security headers, cache headers and compression. The second layer is the HTML itself, which yields the title, the meta description, the canonical, the number of top level headings, JSON-LD blocks, the language attribute and how images are declared.

The third layer is the weight of your page start, and it is usually the one that changes a conversation. The check collects every stylesheet and every non-deferred script in the head, which is precisely what a browser has to finish downloading before it can draw anything. Then it fetches them and reports the real kilobyte count, split between CSS and JavaScript, with the time of the slowest one and the list of third-party origins they come from.

For WordPress there are a few things that are public by design and still surprise owners. Plugin and theme asset paths reveal what is installed and at which version, because the version number usually sits in the stylesheet URL. The REST endpoint listing users answers without authentication unless somebody closed it. The file xmlrpc.php often still answers even though most installations no longer need it for anything.

Why there is no score here

This is a decision, not a missing feature. A score of sixty-two invites exactly one follow-up question, what do I do about it, and the honest answer to that question is another audit. Weight does not have that problem. Nineteen blocking requests is a number an owner can watch go down. A megabyte of JavaScript arriving before first paint is a number that points at a specific plugin. Eleven requests from two external domains points at a font service and a tag manager, and both of those are decisions somebody made and can unmake.

The layer has a ceiling and it deserves naming. It measures weight and response time, not what your users experience. This is not a Core Web Vitals measurement and it does not replace one. Field data is collected from your real visitors over a twenty-eight day window and it is already yours, free, in Google Search Console under the Core Web Vitals report. If you want to know how a phone on a weak connection in Manchester experiences your checkout, that report is the only thing that will answer. Our numbers tell you which part of the page is responsible for what it shows.

What the check cannot see

The out of reach list is short and worth knowing before you treat the result as a full picture. The check never enters the admin area, so it knows nothing about accounts, roles, or who last signed in from an unfamiliar address. It cannot see the database, so it will not tell you whether your tables are swollen with abandoned transients. It does not check backups, because backups are by definition not public. It does not compare detected plugin versions against a vulnerability database, so a version it reads is a fact, not a risk assessment. And it checks exactly the one address you gave it, not the whole site.

The logged-in view is its own gap. WordPress serves signed-in visitors an entirely different set of queries and usually disables page caching for them. A store that answers a guest in a few hundred milliseconds can take several times longer for a signed-in customer with a full basket. An outside check will not show that, and no tool without account access will.

How to read each class of finding

High severity findings cost money or security immediately. No HTTPS on the final URL, a robots noindex on a page meant to be indexed, an open user enumeration endpoint, four or more of the five security headers missing, a slow first byte. A heavy start lands here too: fifteen or more blocking requests, or over half a megabyte before first paint. Each of these has one concrete fix, usually in server configuration or in a plugin you already have.

Medium severity findings describe a state you can run for a year without an outage while quietly losing ground. No caching on the HTML, blocking assets served without compression, fonts loaded from Google’s servers instead of your own domain, a missing meta description, no structured data block, images without dimensions, no sitemap. An owner with steady traffic can schedule these for the next review. An owner running a store through a peak season should pull compression, caching and images off that list first, because those reach the basket fastest.

Low severity findings are mostly traces the stack leaves behind: the WordPress version in the meta generator, the server name and version in a header, several top level headings on one page, short cache lifetimes on static assets, images without lazy loading. None of it will take the site down. Tidy them alongside other work, not instead of it.

Confirmations sit apart from all of that. When the tool reports that the security headers are complete, that the HTML came back from cache, that structured data is present and that the page start is light, it is not filler. It answers the question owners actually ask most often, which is whether the last team did the job.

When the honest answer is that nothing needs doing

This happens more often than the diagnostic tool market suggests. A company site on decent hosting, on a current WordPress, with a full set of headers, sane caching and a light start, needs nothing from us. If the report shows only low severity findings and confirmations, that is this case. Close the tab and come back in six months.

There is also a middle state where the right move is to wait. If you changed theme or host last week, our numbers already describe the new site while your Search Console report will keep describing the old one for another month. Do not commission work on the strength of two sources describing two different sites. Let the window move first.

And a third case: a real finding that is not yours to fix. A missing security header, missing compression or uncached HTML are frequently host configuration rather than site configuration. One message to your hosting support closes those for less than any project would cost.

What we do with the address you give us

We fetch public pages at the address you submit, we do not sign in anywhere, and we store nothing beyond an anonymous run counter. The report goes on no mailing list, because we never ask for an email address. If you click through to contact, the form arrives prefilled with the address and the three most serious findings, and you see the whole text before anything is sent.

Where to go if the report found something real

Repeating medium severity findings usually mean no one is minding the site rather than one broken thing, and the answer to that is WordPress website maintenance. A heavy start and a slow first byte lead to speeding up WordPress. An open user endpoint, a responsive xmlrpc.php and absent headers are material for a WordPress security audit, because those three are not worth fixing one at a time.

Related cluster

Explore other WordPress services and knowledge base

Strengthen your business with professional technical support in key areas of the WordPress ecosystem.

Recommendations from LinkedIn

Recommendations and reviews of working with WPPoland

Selected recommendations from WordPress, WordCamp and e-commerce leaders - with a focus on delivery on time, technical depth, and a business-driven approach to WordPress development.

Karolina Czapla

Karolina Czapla

Marketing Strategist, Performance & Digital Strategy

“Working with Mariusz on WordCamp has shown me how rare it is to combine deep technical skill with genuine leadership. He plans, coordinates and delivers with precision, while giving the team space to grow and contribute....”

Co‑organiser, WordCamp Gdynia 2024 & 2025

Anna Kamińska

Anna Kamińska

Talent Acquisition Specialist / HR People Partner

“Mariusz's portfolio speaks for itself. It reflects his precision, versatility and sense of responsibility. You can trust him to guide a project from idea to delivery, keep stakeholders informed and make sure things are d...”

Worked on the same team

Sarah‑Luisa Kwolek

Sarah‑Luisa Kwolek

IT Project Management & Product Owner, Web/App

“For over two years I could always rely on Mariusz to handle WordPress tasks calmly and professionally, from styling and templating to third‑party integrations. He brings steadiness to the team and keeps the frontend side...”

Mariusz was her client for WordPress work

Argert Boja

Argert Boja

Senior Full‑Stack Developer

“Mariusz is the teammate everyone hopes for: strong full‑stack WordPress skills, clear explanations and a positive attitude even under pressure. He moves easily between custom plugins, performance work and Gutenberg layou...”

Worked alongside Mariusz on WordPress projects

Varun Patil

Varun Patil

Growth & CRM Lead

“Beyond development, Mariusz understands SEO, analytics and growth. He talks directly with stakeholders, asks the right questions and ships solutions that move business metrics, from AMP to tracking to performance.”

Managed Mariusz on growth initiatives

Rafał Osiński

Rafał Osiński

Founder @ EasyTrips.pl, Senior WordPress Dev

“I've known Mariusz through the WordPress community for many years. He's reliable, deeply involved and consistently shows up, at meetups, WordCamps and in projects. If you care about long‑term collaboration and someone wh...”

WordPress community co‑organiser

Daniel Blossfeld

Daniel Blossfeld

Process Optimization & Digitalization Consultant

“I had the pleasure of working with Mariusz for almost three years. During that time, his WordPress development skills proved invaluable across a range of projects, from website builds to online member areas and even Shop...”

Mariusz was his client for WordPress work

Natalie Wiszczor

Natalie Wiszczor

CRM & E-Mail Marketing Manager

“I had the great pleasure of working with Mariusz for over 4 years in the technical field. During this time, he proved to be a competent and reliable colleague. What stood out in particular was his friendly nature and his...”

Worked with Mariusz on different teams

Mark Chalklen

Mark Chalklen

Head of Design & Build at Itineris Limited

“Mariusz is a great member of the team, always happy to get stuck into any task and happy to learn new things. A great communicator and all round nice guy to work with. Hard to beat on our weekly Strava leader board thoug...”

Managed Mariusz directly

Jessica Di Pasquale

Jessica Di Pasquale

Leading SEO initiatives with data-driven growth strategies.

“Mariusz is a very skilled, patient and expert guy. Always ready to help and to fix errors, I really appreciated working with him. He is such a great colleague!”

Managed Mariusz directly

Biki John

Biki John

Content Marketing Aficionado & SEO Enthusiast

“It was great to work with Mariusz. I really appreciated his extensive knowledge of WordPress and how that came in handy whenever I needed support navigating the CMS. I commend Mariusz totally for his patience, good natur...”

Worked with Mariusz on different teams

Rafal Borowiec

Rafal Borowiec

Software Developer, Consultant, Manager and Lecturer

“I had an opportunity to work with Mariusz for 7 months. He excels in technical optimization for search engines (SEO). Mariusz has also strong expertise in AMP development, GTM, and GA. Mariusz feels very comfortable with...”

Managed Mariusz directly

Belinda Koch

Belinda Koch

Web-Tracking Analyst at TUI

“Mariusz is a great person to work with. He is extremely motivated to learn new things and share his knowledge, and is very knowledgeable on a wide range of topics. We worked together on digital analytics and tracking top...”

Worked with Mariusz on digital analytics and tracking topics

Ali Nezamolmaleki

Ali Nezamolmaleki

Growth, SEO, Analytical thinking, AMP

“Mariusz is an extremely talented person in his field of work. He is always capable of giving a new perspective to solve problems and to think out of the box in situations where everything seems to be locked. Working with...”

Worked with Mariusz on the same team

Karol Jakubcewicz

Karol Jakubcewicz

Front-end / JavaScript Developer

“Mariusz is an incredibly experienced WordPress developer and SEO/SEM specialist I've had the pleasure to work with for almost two years. As a pilot of the team responsible for AirHelp's website development, he's been one...”

Worked with Mariusz on the same team

Paweł Lewczuk

Paweł Lewczuk

Front-end developer, WordPress developer

“I collaborated with Mariusz on several projects and our cooperation was always exemplary. I believe there are many more joint projects ahead of us. Highly recommended!”

Mariusz was Paweł's client

Przemek Wroblewski

Przemek Wroblewski

Software Developer with 20+ years of experience

“I found Mariusz as someone with great expertise and profound knowledge of frontend solutions. Powerful, knowledgeable and accountable WordPress developer. Has an easiness to build interpersonal relations with others. He ...”

Worked with Mariusz on different teams

Service FAQ

Frequently asked questions

Questions about scope, delivery, pricing, and execution quality.

SEO-readyGEO-readyAEO-ready5 Q&A
Do I have to give an email address to see the result?#
No. The report renders as soon as the request finishes. The contact form is a separate step and only opens when you click it. At that point it arrives prefilled with your address and the three most serious findings, so your first message already contains the diagnosis.
Why is there no score out of a hundred?#
Because a score is a model, and a model has to be translated back into work before anyone can act on it. An owner who reads forty-seven out of a hundred knows exactly what they knew before. An owner who reads nineteen render blocking requests, 1.4 MB before first paint, eleven of them from two third-party domains, already has a task list and knows where to start.
Is this a Core Web Vitals measurement?#
No. Core Web Vitals are field data, collected from your real visitors over twenty-eight days. This check measures weight and response time from one edge location at one moment. If you want field data, it is already yours and free in Google Search Console under the Core Web Vitals report. Our numbers tell you which part of the page is causing what that report shows.
Does the tool log in to my WordPress?#
No, and it has no way to. It fetches the public version of the address you gave it, the same way a visitor's browser would. It has no password, never touches the database and never writes anything.
The check found nothing. Does that mean my site is secure?#
It means nothing from this list is visible from outside. Out of reach are the admin area, backups, user roles, plugin versions compared against a vulnerability database, and every page other than the one you submitted. An empty report is a good signal, not a certificate.

Need an FAQ tailored to your industry and market? We can build one aligned with your business goals.

Let’s discuss

Related Articles