Skip to content
codecollab.pl
§ Blog wordpress site audit

WordPress site audit - what to check beyond SEO

A site audit is not only about visibility in Google - the most dangerous things sit under the bonnet, where nobody looks

Krystian Kacik 10 min read
Contents

A site audit is not only about visibility in Google - the most dangerous things sit under the bonnet, where nobody looks. A WordPress site audit is an ordered review of five areas: security, backups, plugins and theme, speed with hosting, and the contact path to the customer. SEO is the sixth area, not the only one - and usually the least urgent, because a site that falls over once a month or silently drops form submissions loses money faster than a site with average copy on a subpage.

Below I set out exactly what I check when I open somebody else’s site. You can walk this list yourself - for most points, access to the WordPress dashboard and the hosting panel is enough.

How a site audit differs from an SEO audit

An SEO audit answers “why am I invisible in search”. A site audit answers “is this site healthy at all, and can we keep building on it”. Two different reports, run with different tools and a different order of priorities.

AreaSEO auditTechnical site audit
Goalvisibility in searchstability, security, sales
Checkscontent, phrases, links, indexingplugins, backups, server, forms
When it is urgentwhen traffic dropswhen the site is over a year old and nobody has touched it
Outputa content and fix plana risk list with priorities

If you only care about the search side, I have a separate piece: SEO audit step by step. Here we handle the rest - and it is the rest that usually blows up.

1. Security - start here

Security is checked first, because an infected site invalidates every other conclusion in the audit. There is no point optimising the speed of a site that has foreign code sitting inside it.

What to go through, in order:

  1. The list of users with the administrator role - in the dashboard, under Users. Any account you do not recognise is suspicious. Accounts belonging to former contractors and employees should be disabled or demoted to Subscriber
  2. The date of the last WordPress update - if the core version is more than a few months old, the site stands on a leaky foundation
  3. Plugins with no update in over a year - the most common back door; the author stopped developing them, the holes stayed
  4. The PHP version on the hosting - older branches no longer get security patches. A current, supported version is the minimum
  5. The SSL certificate and forced HTTPS - the padlock has to be on every page, including old URLs
  6. Dashboard login - are passwords unique, is two-factor authentication on, is the login page exposed with no limit on attempts

If along the way you see content nobody added, redirects to unknown domains or a malware warning from the hosting provider - the audit ends and detecting and removing the malware begins. That is a different procedure and a different order of moves.

2. Backups - test a restore, not a declaration

A backup exists only once it has been restored. The fact that a plugin shows a green “backup complete” message says nothing about whether that file can bring the site back.

In an audit I check four things: does the backup cover files and the database (not just the database), how often it runs, where it lives (a backup on the same server as the site dies with the server) and how many versions back are available. The last point is often a surprise: with a single backup from the last 24 hours, an infection from a week ago gets restored along with everything else. How to arrange this sensibly, I described in the piece on WordPress backups.

A test worth doing once a year: restore the backup onto a staging copy. Either it works, or you find out about the problem in a calm week rather than on the day of the outage.

3. Plugins and theme - inventory without sentiment

Every plugin is code you did not write that has full access to your site. A healthy company site usually copes with a dozen or so plugins; when I see thirty-odd, you can almost always cut that in half.

For each plugin I ask four questions:

  • Is it used? An inactive plugin still sits in the files and can still be vulnerable. Unused ones I delete, not disable
  • Is it maintained? The date of the last update and the declared compatibility with the current WordPress
  • Is it paid for? Premium versions without a valid licence stop receiving patches, even though they still look active
  • Does it duplicate another one? Two SEO plugins, three backup plugins or two caching systems is a classic that can take a site down

The theme is a separate matter. I check whether it is updated, and whether changes were made in a child theme. Edits written directly into the parent theme’s files disappear at the first update - and that is one of the most common reasons a site “broke by itself”.

4. Speed and hosting - numbers instead of impressions

Speed is measured with a tool, not by the feel of your own laptop on a fibre connection. In an audit I measure the mobile and desktop versions several times and take the median - a single measurement can swing wildly. How to run that measurement on your own site I described in the speed mini audit - the method is the same for a company site and for a store.

What to look at beyond the score itself:

  • Server response time - if the server itself takes a long time to think, no amount of image optimisation will make up for it. That points to hosting, or to a homepage that is simply too heavy
  • Image weight - photos uploaded straight from a camera at full resolution are the single most common brake on a company site
  • The number of external scripts - chat widgets, pixels, maps, review carousels. Each one adds its share
  • Cache and compression - are they on at all, and are they not fighting each other

5. The contact path - where the money gets lost

This is the point that drops out of most audits and delivers the fastest return. The contact form has to be filled in and actually sent, from an external address, and you have to check that the message arrived and where it landed.

The checklist:

  1. Send a test from the form and check the inbox, including the spam folder
  2. Check which address the submissions go to - in many companies it is a former employee’s mailbox
  3. Check whether the sender gets a confirmation
  4. Tap the phone number on a mobile - does it start a call
  5. Walk the whole “homepage to offer to contact” path on a phone, one-handed

Form messages can quietly stop arriving after a hosting change or a plugin update. Nobody notices, because no emails looks exactly the same as no interest.

Two things worth touching during an audit, because both are already in force.

Digital accessibility. The European accessibility requirements have applied since June 2025 and cover mainly services sold to consumers electronically. In an audit I check the basics: text contrast, keyboard operation, alt text on images and whether form fields are properly labelled. That is usually a few hours of fixes, not a rebuild.

Invoices and KSeF. Poland’s national e-invoicing system is already live - it covers the largest entities from February 2026 and all remaining taxpayers from April 2026. If your site issues or passes on invoice data, this is the moment to check that the path is closed off on the accounting side.

Plus ordinary hygiene: a current privacy policy, a working cookie consent banner and clear information about who controls the data from the form.

What a good audit report looks like

A good site audit report has three traits: every point has evidence (a screenshot, a measurement, a plugin name with version), every point has a business impact described in plain words, and the whole thing is sorted by urgency, not by chapter. Three levels are plenty:

PriorityWhat it meansExample
Urgentrisk of losing the site or datano working backup, a plugin with a known vulnerability
Importantloses money every dayform not arriving, slow loading on mobile
To be plannedimproves results over a longer horizoncontent cleanup, accessibility, theme refactor

What should not be in such a report: a hundred pages of charts from a free scanner with no commentary, promises of specific Google positions, and an invoice for the fix before anyone has agreed the scope.

When it is worth handing this to someone outside

You can walk through most of this list yourself - the hardest points are the ones requiring access to files and the server, because that is where a mistake gets expensive. I start every engagement with a free diagnosis: I look at the site, measure it, go through the plugins and come back with a short list of what is urgent and what can wait. No obligations and no scare tactics.

If the diagnosis turns up real work, you get a written quote before the start - fixed-price projects on my side usually land in the 5,000-10,000 PLN net range, depending on scope. And if the problem is simply the lack of a rhythm - because nobody watches updates and backups - ongoing technical support on a monthly plan often makes more sense: Basic from 1,000, Pro from 2,000 or Premium from 3,500 PLN net per month, depending on how big the site is and how fast the response has to be.

Frequently asked questions

What is a website audit? A website audit is an ordered review that shows the site’s real condition: security, backups, plugin currency, speed, the correctness of the contact path and visibility in search. The output is a list of concrete problems with priorities, not a general “the site is fine”.

How long does a WordPress site audit take? The initial diagnosis is usually a matter of hours - enough to catch the urgent things. A full audit with measurements, a plugin review and a backup restore test usually takes 1-3 working days, depending on how large the site is and how quickly I get access.

Can I do a site audit myself? Yes, a big part of it. The user list, plugin currency, a form test and a speed measurement you can check yourself from the WordPress dashboard. The harder parts sit on the server - PHP version, logs, an actual backup restore - and that is where a mistake can cost more than the audit.

What should a site audit report contain? Evidence for every point (a measurement, a screenshot, a plugin name and version), a plain-language description of the business impact, and a split into what is urgent, what is important and what can be planned for later. A good report ends with a recommended order of work, so you can act on it without a translator.


Sitting on this yourself and unsure where to start? I speed up and repair existing sites and stores - Core Web Vitals, outages, the features that are missing. Tell me what is happening and you will get a concrete quote with a date.

§ Quote in 24h

Facing a similar problem and not sure where to start?

Describe the scope in two sentences or send a link. I tell you what to fix first, and you get a fixed bid in writing within 24 hours - no "from X" pricing.

Send your scope - quote in 24h