Security audit

Check your WordPress security in plain English.

Ask your AI to audit your site and get findings ranked by severity, each with an explanation and a fix. Then ask it to apply the safe fixes, like plugin updates, with a backup first and your approval.

What the audit checks

AreaChecks
UpdatesWordPress core, plugins and themes with updates available; inactive plugins and unused themes left installed
File integrityCore files compared with WordPress.org's official checksums to spot modified or missing files; PHP files hidden in the uploads folder
ConfigurationErrors shown to visitors (WP_DEBUG), a public debug.log, the built-in code editor, XML-RPC, the default wp_ table prefix
AccountsA user named “admin”, more than three administrators, open registration and the default role new users get
EnvironmentHTTPS, and PHP versions that no longer get security fixes

Findings are ranked critical, high, medium or low, with an overall score. The checksum comparison can be skipped for a faster run.

Fix it from the same chat

Run a security audit and explain the critical and high findings.
Update all plugins that have updates available.
Delete the inactive plugins I'm not using.
The update broke the contact form. Roll back the plugin update.

Plugin and theme changes always go to your Approvals page first. Before an update or deletion, WPMate saves a copy of the plugin or theme folder, so a rollback restores the previous version.

Some fixes are deliberately left to you or your host: editing wp-config.php, upgrading PHP or removing suspicious files. The audit tells you exactly what to change.

Not a malware scanner. The audit finds common weaknesses and signs of tampering such as modified core files or PHP in uploads, but it is not a full malware scan or a firewall. If it reports suspicious files, have the site checked by a security professional or your host.

For a checklist you can follow step by step, read the WordPress security checklist.

Frequently asked questions

Which plan includes the security audit?

The security audit is part of Pro ($14.99/month) and Agency. See pricing.

Can WPMate update WordPress core?

Not yet. The audit tells you when a core update is available; update from Dashboard → Updates after taking a backup. Plugins and themes can be updated from your AI with a backup first.

Does the audit slow my site down?

It runs only when you ask for it. The core-file checksum comparison is the slowest part and can be skipped.

Is WPMate itself secure?

Sites connect with a one-time code, never a password. Every request to your site is signed, can be used once and expires after five minutes. Read the security overview.

Find the weak spots before someone else does

Connect your site and ask: “Run a security audit.”

Create free account