

Security review dashboard with maintenance summaries and the trusted-baseline workflow.
Site Security Auditor gives WordPress administrators a practical security review dashboard. See plugin update information, compare plugin and theme files against a trusted snapshot, and understand which settings deserve attention.
Open Tools Security Audit to start. Each section explains what it checks, what the result means, and what to do next. It is designed for routine maintenance and investigating unexpected file changes, without automatically editing your site.
A baseline records the current state; it does not prove that state is clean. Keep independent backups and ask a trusted professional about unexplained changes.
New baselines cover PHP, PHP7, PHTML, INC, TWIG, JSON, JS and CSS files inside the configured plugin directory and registered theme directories. WordPress core, uploads, must-use plugins, database content and other file types are excluded. Symbolic links are not followed and cause an incomplete result.
Each run is bounded to 20,000 directory entries, 100 MiB of file data, 8 MiB per file and an approximately 8-second processing budget. Unreadable files or exceeded limits produce an incomplete report. Incomplete scans never replace a baseline or present a partial comparison as complete. Large sites may need a host-level integrity tool. Avoid editing files or running updates during a scan.
This plugin is not a malware scanner, firewall or vulnerability database. It does not repair files, guarantee security, or certify a plugin as safe. An update or legitimate edit can change a file; unchanged files can still contain problems.
No account, API key, telemetry or additional remote metadata requests are required. The dashboard uses the update information already maintained by WordPress; WordPress itself may contact its normal update services.
File hashes, relative paths, baseline time and the latest file report are stored in the site’s options, without autoloading them. Reports are restricted to administrators; on multisite they require a network administrator. Downloaded reports contain relative file paths, so share them only with trusted people. Deactivation and deletion preserve these records to avoid silently discarding your trusted reference.