{"id":361000,"date":"2026-09-08T17:11:48","date_gmt":"2026-09-08T17:11:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/320px-site-audit\/"},"modified":"2026-09-08T17:11:23","modified_gmt":"2026-09-08T17:11:23","slug":"320px-site-audit","status":"publish","type":"plugin","link":"https:\/\/twd.wordpress.org\/plugins\/320px-site-audit\/","author":23548038,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.1","stable_tag":"0.1.1","tested":"7.1","requires":"6.4","requires_php":"7.4","requires_plugins":null,"header_name":"320px Site Audit","header_author":"320px team","header_description":"A local, read-only WordPress check that shows what to fix, what is fine, and what could not be tested.","assets_banners_color":"f5f8f9","last_updated":"2026-09-08 17:11:23","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wp-content.ru\/site-audit\/","header_author_uri":"https:\/\/320px.ru\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":56,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.1":{"tag":"0.1.1","author":"appsmax","date":"2026-09-08 17:11:23","revision":3687068}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3687068,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3687068,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3687068,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3687068,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3687068,"resolution":"1","location":"assets","locale":"","width":1440,"height":1100},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3687068,"resolution":"2","location":"assets","locale":"","width":1440,"height":1100},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3687068,"resolution":"3","location":"assets","locale":"","width":1440,"height":1100},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3687068,"resolution":"4","location":"assets","locale":"","width":1440,"height":1100},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3687068,"resolution":"5","location":"assets","locale":"","width":1440,"height":1100},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3687068,"resolution":"6","location":"assets","locale":"","width":1440,"height":1100}},"screenshots":{"1":"Russian start screen with the recommended Main audit, its Express subset, and separate additional checks.","2":"Russian Main report with a concrete observed result, affected page, and next action.","3":"English Express report with localized evidence, limitations, and actions.","4":"Server continuation with the zero-network WP-CLI command and no SSH credential form.","5":"Russian privacy self-check with bundled sources and masked local comments.","6":"Optional review preview with recipient, purpose, data classes, retention, payload, and separate consent."}},"plugin_section":[],"plugin_tags":[1953,23519,396,186,20034],"plugin_category":[34,54,55],"plugin_contributors":[276234],"plugin_business_model":[],"class_list":["post-361000","plugin","type-plugin","status-publish","hentry","plugin_tags-accessibility","plugin_tags-diagnostics","plugin_tags-privacy","plugin_tags-seo","plugin_tags-site-audit","plugin_category-accessibility","plugin_category-security-and-spam-protection","plugin_category-seo-and-marketing","plugin_contributors-appsmax","plugin_committers-appsmax"],"banners":{"banner":"https:\/\/ps.w.org\/320px-site-audit\/assets\/banner-772x250.png?rev=3687068","banner_2x":"https:\/\/ps.w.org\/320px-site-audit\/assets\/banner-1544x500.png?rev=3687068","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/320px-site-audit\/assets\/icon-128x128.png?rev=3687068","icon_2x":"https:\/\/ps.w.org\/320px-site-audit\/assets\/icon-256x256.png?rev=3687068","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/320px-site-audit\/assets\/screenshot-1.png?rev=3687068","caption":"Russian start screen with the recommended Main audit, its Express subset, and separate additional checks."},{"src":"https:\/\/ps.w.org\/320px-site-audit\/assets\/screenshot-2.png?rev=3687068","caption":"Russian Main report with a concrete observed result, affected page, and next action."},{"src":"https:\/\/ps.w.org\/320px-site-audit\/assets\/screenshot-3.png?rev=3687068","caption":"English Express report with localized evidence, limitations, and actions."},{"src":"https:\/\/ps.w.org\/320px-site-audit\/assets\/screenshot-4.png?rev=3687068","caption":"Server continuation with the zero-network WP-CLI command and no SSH credential form."},{"src":"https:\/\/ps.w.org\/320px-site-audit\/assets\/screenshot-5.png?rev=3687068","caption":"Russian privacy self-check with bundled sources and masked local comments."},{"src":"https:\/\/ps.w.org\/320px-site-audit\/assets\/screenshot-6.png?rev=3687068","caption":"Optional review preview with recipient, purpose, data classes, retention, payload, and separate consent."}],"raw_content":"<!--section=description-->\n<p>320px Site Audit helps an administrator understand what needs attention, what\nis fine, and what could not be tested. It analyses WordPress, PHP, the database,\nscheduled tasks, installed components, selected source code, public pages,\ntechnical search signals, rendered-page evidence, privacy-process answers, and\noptional server evidence.<\/p>\n\n<p>The recommended Main audit contains 46 results: the 20-result Express local\nsubset, ten further local WordPress checks, and 16 analyses of one bounded\nsame-site crawl. Separate checks cover active custom code, 1\u201310 components\nchosen by the administrator, a controlled rendered home page, and local server\nevidence through WP-CLI.<\/p>\n\n<p>Reports lead with the observed fact and a concrete next action. Search findings\ngroup the exact problem and show safe same-site page paths when privacy rules\nallow them. Clean results stay available in a collapsed section. Method,\ncoverage, confidence, sources, and limitations remain available without\nobscuring the answer.<\/p>\n\n<p>The plugin analyses and explains. It does not repair, delete, optimize, update,\nor change audited content, users, settings, plugins, themes, server\nconfiguration, or databases. It writes only its own bounded run, task, result,\ndecision, and operation records.<\/p>\n\n<h4>Local and optional checks<\/h4>\n\n<ul>\n<li><strong>Express:<\/strong> 20 local WordPress and hosting-environment results.<\/li>\n<li><strong>Main:<\/strong> Express plus database, filesystem, components, privacy signals, and\none confirmed, limited crawl of this site's public pages.<\/li>\n<li><strong>Custom code:<\/strong> local tokenizer and lexical signals for the active\/parent\nthemes, MU plugins, drop-ins, and recognized active Code Snippets entries.<\/li>\n<li><strong>Selected components:<\/strong> the same bounded code triage for 1\u201310 installed\nplugins or themes explicitly selected and confirmed by the administrator.<\/li>\n<li><strong>Rendered home page:<\/strong> 20 aggregate DOM, layout, form, resource,\naccessibility, and data-handling signals from 1\u201317 confirmed anonymous GET\nrequests to the site's exact origin. It does not execute page JavaScript.<\/li>\n<li><strong>Server continuation:<\/strong> nine masked results from\n  wp 320px-audit server-scan, run by the owner over SSH without giving the\nplugin SSH credentials.<\/li>\n<li><strong>Optional browser CLI:<\/strong> executed-JavaScript, responsive, and automated\naccessibility evidence at five fixed widths, run independently by the owner.<\/li>\n<\/ul>\n\n<p>Static and automated findings are review signals, not proof of a vulnerability,\ncompatibility with every environment, search ranking, WCAG conformance, or\nlegal compliance. Missing or limited evidence is reported as not tested or\npartial, never converted to a pass.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>The complete base report works locally without an account, license, payment,\nemail gate, telemetry, or automatic report transfer. Opening the plugin,\nrunning local checks, viewing or exporting reports, cron, activation, and\nuninstall do not contact 320px or another external service.<\/p>\n\n<p>Stored evidence is bounded and masked. The plugin does not retain page HTML,\nvisible text, cookies, credentials, secret values, database content, or source\ncode. A crawl may retain a hostless, queryless page path only when its segments\ndo not resemble personal data, credentials, or opaque tokens. Reports and\nexports should still be treated as private technical documents.<\/p>\n\n<p>Every optional external operation is off by default. Before it runs, an\nauthorized administrator sees the receiver, purpose, data classes, and relevant\nterms, then confirms that one operation. No scheduled task starts an external\ntransfer.<\/p>\n\n<h3>External services<\/h3>\n\n<p>The services below are optional and are not required for the local report.<\/p>\n\n<h4>WordPress.org checksums<\/h4>\n\n<p>Core integrity sends only the installed WordPress version and locale to\n    https:\/\/api.wordpress.org\/core\/checksums\/1.0\/. Plugin integrity sends only one\nadministrator-selected public plugin slug and version to\n    https:\/\/downloads.wordpress.org\/plugin-checksums\/{slug}\/{version}.json.\nOrdinary network metadata is also visible to the receiver. Neither operation\nsends the site URL, files, paths, component inventory, report, cookies, or\nauthorization. Each operation requires its own confirmation. Privacy policy:\nhttps:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<h4>Wordfence vulnerability feed<\/h4>\n\n<p>The optional owner-run WP-CLI continuation has a zero-request preview. Only\nafter <code>--confirm-network<\/code>, it sends the owner's bearer API key, the minimal Site\nAudit user agent, and ordinary network metadata to the fixed Wordfence Scanner\nFeed endpoint at\n    https:\/\/www.wordfence.com\/api\/intelligence\/v3\/vulnerabilities\/scanner. It\ndoes not send the site URL, component inventory or versions, report, or personal\ndata. The complete feed is matched locally and deleted immediately. The key is\nread from <code>PX320_WORDFENCE_TOKEN<\/code> and is never stored. Terms:\nhttps:\/\/www.wordfence.com\/wordfence-intelligence-terms-and-conditions\/\nPrivacy policy: https:\/\/www.wordfence.com\/privacy-policy\/<\/p>\n\n<h4>Request a review from 320px<\/h4>\n\n<p>An administrator may voluntarily send a review request to\n    https:\/\/wp-content.ru\/wp-json\/wp-content-platform\/v1\/review-requests.\nContact-only is the default. The administrator may instead choose a short\nsummary, selected results, or the redacted full report. The exact payload and\nbyte size are previewed locally before separate consent and final confirmation.\nThe site URL, local identifiers, credentials, and private visual evidence are\nnever included. There is no retry or background submission. The response gives\nan opaque request ID, deletion link, and retention date of about 90 days.\nTerms: https:\/\/wp-content.ru\/terms\/\nPrivacy policy: https:\/\/wp-content.ru\/privacy\/\nConsent: https:\/\/wp-content.ru\/personal-data-consent\/<\/p>\n\n<h4>Optional browser CLI dependencies and page requests<\/h4>\n\n<p>The browser companion is human-readable source included in <code>cli\/browser<\/code>; PHP\nand wp-admin never install or execute it. The owner independently installs its\npinned packages. With default npm settings that contacts\n    https:\/\/registry.npmjs.org\/; npm terms and privacy are at\nhttps:\/\/www.npmjs.com\/policies\/terms and\nhttps:\/\/www.npmjs.com\/policies\/privacy. The Playwright installer provides a\ndry run that lists its browser download URLs; documentation is at\nhttps:\/\/playwright.dev\/docs\/browsers and Microsoft privacy terms are at\nhttps:\/\/privacy.microsoft.com\/privacystatement.<\/p>\n\n<p>Without <code>--confirm-network<\/code>, the companion makes no page request. A confirmed\nrun loads only 1\u20135 explicit queryless pages in a fresh sandboxed Chromium\ncontext. The pages and their ordinary first- or third-party resources receive\nnormal browser\/network metadata and anything page scripts place in allowed GET\nrequest URLs or headers. Mutating HTTP methods, later document navigation,\nframes, popups, saved downloads, WebSockets, WebRTC, WebTransport, and workers\nare blocked within fixed request, byte, and time limits. Its ordinary JSON\ncontains aggregates and keyed references, not URLs, text, HTML, selectors,\nfield values, cookies, screenshots, or response bodies. There is no upload or\nWordPress callback.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>In WordPress, open Plugins &gt; Add New Plugin and install 320px Site Audit.<\/li>\n<li>Activate it, then open Site Audit in the main administrator menu.<\/li>\n<li>Choose a check and read its local\/network boundary.<\/li>\n<li>Start the check and wait for the report. Interrupted work can be resumed.<\/li>\n<li>Open results that need attention; clean and unavailable results are grouped\nseparately.<\/li>\n<\/ol>\n\n<p>Only administrators with <code>manage_options<\/code> can open reports or start actions.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20site%20audit%20fix%20or%20change%20my%20site%3F\"><h3>Does Site Audit fix or change my site?<\/h3><\/dt>\n<dd><p>No. It analyses and explains. It changes only its own removable operational\nrecords.<\/p><\/dd>\n<dt id=\"is%20an%20account%2C%20email%2C%20license%2C%20or%20report%20upload%20required%3F\"><h3>Is an account, email, license, or report upload required?<\/h3><\/dt>\n<dd><p>No. The complete base report and local exports work without any of them. There\nis no telemetry. Optional network actions are separately disclosed and\nconfirmed.<\/p><\/dd>\n<dt id=\"why%20can%20a%20result%20be%20%E2%80%9Cnot%20tested%E2%80%9D%3F\"><h3>Why can a result be \u201cnot tested\u201d?<\/h3><\/dt>\n<dd><p>The required evidence was unavailable, restricted, stale, or outside the\nselected check. The result includes the exact reason and next step instead of\nguessing.<\/p><\/dd>\n<dt id=\"does%20a%20clean%20report%20prove%20security%2C%20seo%20results%2C%20accessibility%2C%20or%20compliance%3F\"><h3>Does a clean report prove security, SEO results, accessibility, or compliance?<\/h3><\/dt>\n<dd><p>No. It is bounded diagnostic evidence, not a guarantee, certification,\npenetration test, ranking forecast, manual accessibility audit, or legal advice.<\/p><\/dd>\n<dt id=\"how%20do%20i%20report%20a%20security%20issue%20or%20ask%20for%20support%3F\"><h3>How do I report a security issue or ask for support?<\/h3><\/dt>\n<dd><p>Read <code>SECURITY.md<\/code> and <code>SUPPORT.txt<\/code> in the installed plugin. Never send a live\nsite archive, database dump, credentials, or an unreviewed report.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.1<\/h4>\n\n<ul>\n<li>Corrected directory metadata, release translation packaging, custom-layout\npath handling, and direct web access protection following the WordPress.org\nreview.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>First stable submission candidate: action-first RU\/EN reports, bounded local\nWordPress and code checks, same-site technical search analysis, controlled\nrendered evidence, optional server\/browser continuations, explicit coverage,\nlocal exports, and no telemetry or hidden report transfer.<\/li>\n<\/ul>","raw_excerpt":"A local, read-only WordPress check that shows what to fix, what is fine, and what could not be tested.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/361000","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=361000"}],"author":[{"embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/appsmax"}],"wp:attachment":[{"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=361000"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=361000"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=361000"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=361000"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=361000"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/twd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=361000"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}