{"id":373566,"date":"2026-09-22T17:05:19","date_gmt":"2026-09-22T17:05:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/sitelemetry-audit\/"},"modified":"2026-09-27T08:34:56","modified_gmt":"2026-09-27T08:34:56","slug":"sitelemetry-audit","status":"publish","type":"plugin","link":"https:\/\/ast.wordpress.org\/plugins\/sitelemetry-audit\/","author":23522495,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.3","stable_tag":"0.1.3","tested":"7.1.2","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Sitelemetry Audit \u2013 Security, SEO & AI Readiness Scanner","header_author":"Sitelemetry","header_description":"Run Sitelemetry website audits (security first; SEO, performance, accessibility, AI visibility and integrations on paid plans) from the WordPress dashboard and review the findings with fixes.","assets_banners_color":"3c414d","last_updated":"2026-09-27 08:34:56","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/egenil\/sitelemetry-wordpress-plugin","header_author_uri":"https:\/\/sitelemetry.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":86,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.2":{"tag":"0.1.2","author":"ozandikici","date":"2026-09-22 17:04:54","revision":3707809},"0.1.3":{"tag":"0.1.3","author":"ozandikici","date":"2026-09-27 08:34:56","revision":3715162}},"upgrade_notice":{"0.1.3":"<p>Passing checks, explained coverage gaps, a copy-ready AI fix prompt, one-click site verification with automatic renewal and the plugin in nine languages.<\/p>","0.1.2":"<p>Header metadata only. No functional change.<\/p>","0.1.1":"<p>Tested with WordPress 7.1; exact terms and privacy links. No functional change.<\/p>","0.1.0":"<p>First release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3707809,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3707809,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3707809,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3707809,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3707809,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.2","0.1.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3715162,"resolution":"1","location":"assets","locale":"","width":1280,"height":861},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3715162,"resolution":"2","location":"assets","locale":"","width":1280,"height":1104},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3707809,"resolution":"3","location":"assets","locale":"","width":1280,"height":764},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3715162,"resolution":"4","location":"assets","locale":"","width":1280,"height":644},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3715162,"resolution":"5","location":"assets","locale":"","width":1280,"height":371},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3707809,"resolution":"6","location":"assets","locale":"","width":1280,"height":867},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3715162,"resolution":"7","location":"assets","locale":"","width":1280,"height":1606},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3715162,"resolution":"8","location":"assets","locale":"","width":1280,"height":860}},"screenshots":{"1":"Settings: the stored API key shown masked with where to find it in the app, the target, the audit kind and the weekly audit with its next scheduled run.","2":"Results of a completed security audit: status banner, score and grade, findings by severity, the Copy AI fix prompt button, the findings table and the collapsed Passing checks section.","3":"The findings table with the severity filter and a row expanded to show evidence, impact and the fix.","4":"A partially covered audit: what was not measured, with readable module names, the likely cause of each gap, and the checks without a result or that do not apply (unmeasured checks are not passes).","5":"The plan and usage box: the connected plan and what each paid plan includes, with links to pricing and the app.","6":"The dashboard widget with the last score, grade, status and findings by severity, one click from the full results.","7":"The passing checks, grouped by security module, each with its evidence.","8":"Verify this site after one click: the exact host, \"Verification complete\" with its expiry date, the published file tested, automatic renewal, and the other ways to verify (a token from the app, a DNS record or Google Search Console)."}},"plugin_section":[262246],"plugin_tags":[2353,600,138582,186,20034],"plugin_category":[34,54,55],"plugin_contributors":[282105],"plugin_business_model":[],"class_list":["post-373566","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-ai","plugin_tags-security","plugin_tags-security-scanner","plugin_tags-seo","plugin_tags-site-audit","plugin_category-accessibility","plugin_category-security-and-spam-protection","plugin_category-seo-and-marketing","plugin_contributors-ozandikici","plugin_committers-ozandikici"],"banners":{"banner":"https:\/\/ps.w.org\/sitelemetry-audit\/assets\/banner-772x250.png?rev=3707809","banner_2x":"https:\/\/ps.w.org\/sitelemetry-audit\/assets\/banner-1544x500.png?rev=3707809","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/sitelemetry-audit\/assets\/icon.svg?rev=3707809","icon":"https:\/\/ps.w.org\/sitelemetry-audit\/assets\/icon.svg?rev=3707809","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/sitelemetry-audit\/assets\/screenshot-1.png?rev=3715162","caption":"Settings: the stored API key shown masked with where to find it in the app, the target, the audit kind and the weekly audit with its next scheduled run."},{"src":"https:\/\/ps.w.org\/sitelemetry-audit\/assets\/screenshot-2.png?rev=3715162","caption":"Results of a completed security audit: status banner, score and grade, findings by severity, the Copy AI fix prompt button, the findings table and the collapsed Passing checks section."},{"src":"https:\/\/ps.w.org\/sitelemetry-audit\/assets\/screenshot-3.png?rev=3707809","caption":"The findings table with the severity filter and a row expanded to show evidence, impact and the fix."},{"src":"https:\/\/ps.w.org\/sitelemetry-audit\/assets\/screenshot-4.png?rev=3715162","caption":"A partially covered audit: what was not measured, with readable module names, the likely cause of each gap, and the checks without a result or that do not apply (unmeasured checks are not passes)."},{"src":"https:\/\/ps.w.org\/sitelemetry-audit\/assets\/screenshot-5.png?rev=3715162","caption":"The plan and usage box: the connected plan and what each paid plan includes, with links to pricing and the app."},{"src":"https:\/\/ps.w.org\/sitelemetry-audit\/assets\/screenshot-6.png?rev=3707809","caption":"The dashboard widget with the last score, grade, status and findings by severity, one click from the full results."},{"src":"https:\/\/ps.w.org\/sitelemetry-audit\/assets\/screenshot-7.png?rev=3715162","caption":"The passing checks, grouped by security module, each with its evidence."},{"src":"https:\/\/ps.w.org\/sitelemetry-audit\/assets\/screenshot-8.png?rev=3715162","caption":"Verify this site after one click: the exact host, \"Verification complete\" with its expiry date, the published file tested, automatic renewal, and the other ways to verify (a token from the app, a DNS record or Google Search Console)."}],"raw_content":"<!--section=description-->\n<p>Sitelemetry Audit connects your site to the hosted <a href=\"https:\/\/sitelemetry.com\">Sitelemetry<\/a> audit service. From <strong>Settings &gt; Sitelemetry<\/strong> you run a security scan or a full site audit and read the result inside WordPress: a score and grade, every finding with its severity, location and fix, the checks that passed, a clear list of what was not measured and why, and a ready-made prompt for your AI assistant to fix the findings.<\/p>\n\n<p><strong>Audit kinds<\/strong><\/p>\n\n<ul>\n<li>Security (included in every plan, including Free): DNS and email DNS, WHOIS\/RDAP, TLS, HTTP security headers, HTTPS posture, technology fingerprint and, once the site is verified, exposed files, HTTP methods and API exposure. Paid plans add the WordPress checks, port scans and more modules; these need a verified site.<\/li>\n<li>Technical SEO, AI visibility (AI readiness), Integrations, Accessibility, Performance and Full (all pillars with one blended score) on paid plans.<\/li>\n<\/ul>\n\n<p><strong>What the plugin does<\/strong><\/p>\n\n<ul>\n<li><strong>Results in WordPress<\/strong>: a status banner, the score and grade, the findings with a severity filter and each finding's evidence, impact and fix.<\/li>\n<li><strong>Passing checks<\/strong>: the checks that passed, grouped by security module, each with its evidence.<\/li>\n<li><strong>What was not measured<\/strong>: the checks that did not run, with readable module names and the likely cause when the site's own answers explain it (a redirect, a rate limit, a server error, no answer in time, ports a firewall silently drops, the per-audit script limit), the pages a crawl found but could not assess (for example because robots.txt disallows them), the metrics that were not measured (such as the Core Web Vitals when PageSpeed Insights returns no data), and the individual checks that ended without a pass or fail result (an error, no result, a manual review, not applicable). Unmeasured checks are never counted as passes.<\/li>\n<li><strong>Copy AI fix prompt<\/strong>: one click copies a prompt built from the result (the findings with evidence and fixes, and what was not measured) for ChatGPT, Claude or your coding assistant. The prompt is built in wp-admin and only copied to your clipboard; nothing is sent. The assistant is asked to answer in your WordPress admin language.<\/li>\n<li><strong>Verify this site<\/strong>: some checks run only on sites whose ownership is verified. With one click the plugin gets a verification code from Sitelemetry, publishes the verification file for this site and has Sitelemetry check it, so you need no FTP access; it renews the verification automatically when it expires and tells you exactly what to fix when a check fails (for example a server that blocks \/.well-known\/ or a redirect between www and non-www). Where one-click verification is not available yet, paste the token from the Sitelemetry app instead; a \"Test the file\" button checks that the file is reachable. On a multisite network only a network administrator can publish the file.<\/li>\n<li><strong>Dashboard widget<\/strong> with the last score, the findings by severity, a reminder when the site needs to be verified or its verification renewed, and a link to the results. After a weekly audit that needs verification, a notice on the Dashboard and Plugins screens says so until you dismiss it.<\/li>\n<li><strong>Settings page<\/strong> with a <strong>Sign in or create an account<\/strong> button (the Sitelemetry sign-in page, where new users create an account on a free or paid plan) and a link to the page that shows your API key, your Sitelemetry MCP API key (stored in the WordPress options table, shown masked, removable), the target (defaults to your site address), the audit kind and an optional weekly audit through WP-Cron.<\/li>\n<li><strong>Plan and usage box<\/strong> with the connected plan and what each paid plan includes, read from the public plan catalogue.<\/li>\n<\/ul>\n\n<p><strong>Languages<\/strong><\/p>\n\n<p>The plugin's screens are available in English, Turkish, Spanish, German (informal and formal), French, Portuguese (Brazil), Italian, Japanese and Simplified Chinese. The audit itself is requested in your WordPress admin language when Sitelemetry supports it (English, Turkish, Spanish, German, French, Portuguese, Italian, Japanese, Simplified Chinese), so findings, evidence and fixes arrive in that language too; otherwise in English. Translations from translate.wordpress.org take precedence over the bundled ones, which the plugin uses when no language pack is installed.<\/p>\n\n<p><strong>Plans and allowance<\/strong><\/p>\n\n<p>Sitelemetry has free and paid plans. A Free Sitelemetry account includes the security audit with the public security modules and a monthly number of security scans; the public plan catalogue at sitelemetry.com\/api\/plans is the source of truth and the plugin reads it for the plan and usage box. Each completed audit uses one unit of the monthly allowance of the connected account; polling a running audit uses nothing more. When the connected account does not include an audit kind or has used its monthly allowance, the audit is not started, no allowance is used and the results page says so.<\/p>\n\n<p><strong>Ownership<\/strong><\/p>\n\n<p>Audit only websites you own or are explicitly authorized to test. Every audit is performed by Sitelemetry against the live target and is recorded on the connected account. Protected checks (for example HTTP methods and exposed files, and on paid plans the WordPress checks) require ownership verification of the host in Sitelemetry; results list the checks that were left unmeasured for this reason.<\/p>\n\n<p>To verify from WordPress, save your API key and click <strong>Verify this site<\/strong> in <strong>Settings &gt; Sitelemetry<\/strong>. The plugin asks Sitelemetry for a verification code for this site's exact host (www and non-www are different hosts), answers <code>\/.well-known\/sitelemetry-verification.txt<\/code> on this host with that code and nothing else, tests the file and asks Sitelemetry to check it; the page then says \"Verification complete \u2713 valid until\" and the date, or which problem to fix. A verification lasts 30 days; the plugin renews it automatically in the background (WP-Cron) when it expires or when an audit reports that it must be renewed, never earlier, and shows a notice only if the renewal fails. <strong>Remove token<\/strong> stops publishing the file and the automatic renewal until you click <strong>Verify this site<\/strong> again or save a token. Where one-click verification is not available yet, the manual steps remain: in the Sitelemetry app open <strong>Verified Domains<\/strong>, enter the host and click <strong>Start verification<\/strong>, copy the verification code (the token) shown under <strong>HTTP verification file<\/strong>, paste it into <strong>Verify this site<\/strong>, click <strong>Test the file<\/strong>, then click <strong>Verify HTTP<\/strong> in the app (renew with <strong>Reverify<\/strong> in the app). Without a token the path answers 404. A DNS TXT record or Google Search Console work as alternatives. On a multisite network the web server behind a site's host serves the whole network, so only a network administrator can publish the file there.<\/p>\n\n<p><strong>Thin client<\/strong><\/p>\n\n<p>The plugin bundles no libraries and runs no scanner on your server. It sends requests to sitelemetry.com with the WordPress HTTP API and renders the response. There is no tracking and no analytics.<\/p>\n\n<p><strong>External service<\/strong><\/p>\n\n<p>This plugin relies on the hosted Sitelemetry service (https:\/\/sitelemetry.com) operated by Sitelemetry. It sends requests to the service only when you run an audit or after you have stored an API key, as described in the Privacy section below. The terms of service are published at https:\/\/sitelemetry.com\/terms and the privacy policy at https:\/\/sitelemetry.com\/privacy.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>When you run an audit, the plugin sends to sitelemetry.com the target URL, the audit options you configured (the audit kind) and the report language (derived from your WordPress admin language), authenticated with your API key. Every request also identifies the client in its User-Agent header (<code>sitelemetry-audit-wordpress\/<\/code> and the plugin version); no WordPress version, site name, user, plugin list or other data from your site or your server is sent. Sitelemetry then audits the live target from its own infrastructure and records the audit on the connected account, as described in the Sitelemetry terms (https:\/\/sitelemetry.com\/terms) and privacy policy (https:\/\/sitelemetry.com\/privacy).<\/p>\n\n<p>Once an API key is stored, the plugin also reads the public plan catalogue at sitelemetry.com\/api\/plans (no authentication, no data about your site beyond the same plugin User-Agent) to show the plan and usage box.<\/p>\n\n<p>For ownership verification the plugin uses the verification endpoints of sitelemetry.com (<code>\/api\/v1\/verification\/status<\/code>, <code>\/challenge<\/code> and <code>\/verify<\/code>), authenticated with your API key, and sends only this site's address (scheme and host). It asks for the status when an administrator opens the settings page (the answer is kept for up to a week, or for an hour while the service offers no verification endpoints), and requests and checks a verification code when you click Verify this site and when the automatic renewal runs in WP-Cron (when the verification expires or an audit reports that it must be renewed). To check the code, Sitelemetry requests <code>\/.well-known\/sitelemetry-verification.txt<\/code> from this site.<\/p>\n\n<p>Before a key is stored, the plugin makes no request to any external server.<\/p>\n\n<p>The plugin stores in your WordPress database: the settings (API key, target, audit kind, weekly schedule), the last result of each audit kind (score, findings, passing checks and coverage notes about the target), the verification token you paste or the plugin obtains (with the time and outcome of the last file test), the verification status Sitelemetry reported for this site's host and the outcome of the last verification or renewal, for each administrator which weekly-audit and renewal notices they dismissed and, while an audit runs, the job state. It stores no data about visitors or users and uses no cookies or tracking. Uninstalling the plugin removes all of it.<\/p>\n\n<p>The verification token is public by design: once you save it, the plugin serves it at <code>\/.well-known\/sitelemetry-verification.txt<\/code> so Sitelemetry can confirm you control the site. \"Test the file\" requests that address from your own server; it makes no request to any other host. The AI fix prompt is only copied to your clipboard.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>sitelemetry-audit<\/code> folder to <code>\/wp-content\/plugins\/<\/code> or install it from the Plugins screen.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Sign in at <a href=\"https:\/\/sitelemetry.com\/app\">sitelemetry.com\/app<\/a> (the settings page's <strong>Sign in or create an account<\/strong> button opens it). New to Sitelemetry? Switch to <strong>Create account<\/strong> on the same page and choose a plan: Sitelemetry has free and paid plans, and the Free plan includes the security audit. Then open <strong>My account<\/strong>, expand <strong>Manual connection and API key<\/strong> and copy the API key (the settings page's <strong>Get your API key<\/strong> link opens that page).<\/li>\n<li>Go to <strong>Settings &gt; Sitelemetry<\/strong>, paste the key, check the target and save.<\/li>\n<li>Click <strong>Run audit<\/strong>. The results tab updates while the audit runs.<\/li>\n<li>Optional: click <strong>Verify this site<\/strong> on the same page to include the protected checks.<\/li>\n<\/ol>\n\n<p>The site must be able to make outgoing HTTPS requests to sitelemetry.com.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20plugin%20scan%20my%20site%20itself%3F\"><h3>Does the plugin scan my site itself?<\/h3><\/dt>\n<dd><p>No. Sitelemetry audits the live target from its own infrastructure. The plugin only starts the audit, polls its progress and shows the result.<\/p><\/dd>\n<dt id=\"what%20does%20an%20audit%20cost%3F\"><h3>What does an audit cost?<\/h3><\/dt>\n<dd><p>A completed audit uses one unit of the monthly allowance of the connected Sitelemetry account. Polling a running audit uses nothing more. Audits that are not started (plan not included, allowance exhausted, verification required) use nothing.<\/p><\/dd>\n<dt id=\"what%20data%20does%20the%20plugin%20send%2C%20and%20where%3F\"><h3>What data does the plugin send, and where?<\/h3><\/dt>\n<dd><p>Only to sitelemetry.com, and only after you store an API key: the target URL, the audit kind and the report language (from your WordPress admin language), authenticated with your API key, plus the plugin's User-Agent. For ownership verification the plugin sends this site's address (scheme and host). No site content, users, visitors, plugin list or WordPress version are sent. \"Test the file\" requests this site's own verification file from your server and contacts no other host. The Privacy section below lists every request.<\/p><\/dd>\n<dt id=\"why%20does%20the%20result%20say%20%22partial%22%20or%20list%20checks%20that%20were%20not%20measured%3F\"><h3>Why does the result say \"partial\" or list checks that were not measured?<\/h3><\/dt>\n<dd><p>Some checks need ownership verification of the target or a plan that includes them, or a measurement was unavailable for the target. The results page lists each of them under \"What was not measured\", with the likely cause when the site's own answers explain it. Use <strong>Verify this site<\/strong> in the plugin settings, a DNS record or Google Search Console to include the protected checks.<\/p><\/dd>\n<dt id=\"how%20does%20%22verify%20this%20site%22%20work%3F\"><h3>How does \"Verify this site\" work?<\/h3><\/dt>\n<dd><p>Sitelemetry proves that you control a host by fetching <code>https:\/\/&lt;host&gt;\/.well-known\/sitelemetry-verification.txt<\/code> and comparing it with a token it generated for your account. With one click the plugin requests that token with your API key, serves the file for this site's own host (only for exactly this host and path) and asks Sitelemetry to check it, so no FTP upload is needed; it renews the verification in WP-Cron when it expires and never replaces a verification that is still valid. When a check fails, the page names the cause and the fix: a web server that keeps \/.well-known\/ for itself, a firewall or password, a redirect between www and non-www, a cached or other file at that path, no answer in time, DNS or TLS problems, too many attempts or a key Sitelemetry did not accept. Where one-click verification is not available yet, paste the token from the app; \"Test the file\" fetches the file the way Sitelemetry will and reports redirects to another host, 404 answers from the web server, firewall or maintenance pages and wrong content. Local and private sites cannot be verified this way, and subdirectory installs usually cannot; use the DNS record instead. Sitelemetry fetches the default port of the host (443 or 80), so a site that runs on another port must also answer there. On a multisite network only a network administrator (the <code>manage_network_options<\/code> capability, filterable with <code>sitelemetry_audit_verification_capability<\/code>) can publish the file, because the server behind the host is shared by the whole network.<\/p><\/dd>\n<dt id=\"does%20the%20ai%20fix%20prompt%20send%20my%20data%20anywhere%3F\"><h3>Does the AI fix prompt send my data anywhere?<\/h3><\/dt>\n<dd><p>No. The prompt is built by WordPress from the stored result and the button only copies it to your clipboard. It contains the audited address and the findings, never your API key. You decide where to paste it.<\/p><\/dd>\n<dt id=\"where%20is%20the%20full%20report%3F\"><h3>Where is the full report?<\/h3><\/dt>\n<dd><p>The results page in WordPress is the result: Sitelemetry does not keep a separate report of audits run through the plugin. Run the audit again to refresh it.<\/p><\/dd>\n<dt id=\"which%20languages%20does%20the%20plugin%20support%3F\"><h3>Which languages does the plugin support?<\/h3><\/dt>\n<dd><p>The screens are translated into Turkish, Spanish, German (informal and formal), French, Portuguese (Brazil), Italian, Japanese and Simplified Chinese, and audit results arrive in your admin language when Sitelemetry supports it. The bundled translations work from WordPress 6.0; a language pack from translate.wordpress.org replaces them completely, so strings a pack does not translate yet appear in English. You can improve or add translations at translate.wordpress.org.<\/p><\/dd>\n<dt id=\"how%20does%20polling%20work%3F\"><h3>How does polling work?<\/h3><\/dt>\n<dd><p>Long audits return a job id. While the results page is open, the browser asks WordPress every few seconds (as Sitelemetry suggests) for one progress step; each step is one request from your server to Sitelemetry with the job arguments unchanged. If you leave the page, a WP-Cron event finishes the job in the background. A total time budget of 20 minutes applies; when a job exceeds it, run the audit again later to get a result.<\/p><\/dd>\n<dt id=\"where%20is%20the%20api%20key%20stored%3F\"><h3>Where is the API key stored?<\/h3><\/dt>\n<dd><p>In the WordPress options table, like other plugin settings. The settings page shows it masked, it is never written to logs and it is sent only to sitelemetry.com as a Bearer token.<\/p><\/dd>\n<dt id=\"can%20i%20audit%20a%20site%20other%20than%20this%20one%3F\"><h3>Can I audit a site other than this one?<\/h3><\/dt>\n<dd><p>The target defaults to this site's address and can be changed to any URL you own or are authorized to test. Do not audit sites you are not authorized to test. The verification helper publishes the file only for this site's own host; verify other hosts in the Sitelemetry app.<\/p><\/dd>\n<dt id=\"does%20the%20weekly%20audit%20work%20on%20a%20low-traffic%20site%3F\"><h3>Does the weekly audit work on a low-traffic site?<\/h3><\/dt>\n<dd><p>WP-Cron runs when the site receives visits. If your host runs a system cron for WordPress (recommended), the weekly audit runs on time regardless of traffic.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.3<\/h4>\n\n<ul>\n<li>Passing checks: the results page lists the checks that passed, grouped by security module, each with its evidence (full audits included).<\/li>\n<li>What was not measured: readable module names and the likely cause (redirects, rate limits, server errors, no answer in time, silently dropped ports, the per-audit script limit), with the service's own reason underneath, the pages a crawl could not assess and the metrics that were not measured, and the individual checks without a pass or fail result, grouped by status. Both sections are collapsible.<\/li>\n<li>Copy AI fix prompt: builds a prompt from the result in wp-admin and copies it to the clipboard; nothing is sent.<\/li>\n<li>Verify this site with one click: the plugin gets the verification code from Sitelemetry with your API key, publishes the verification file for this site's host, tests it and has Sitelemetry check it, then shows \"Verification complete \u2713 valid until\" the date, or the exact cause and fix of a failure. It renews the verification automatically in WP-Cron when it expires or an audit reports that it must be renewed, and shows a notice only if the renewal fails. Where the service does not offer one-click verification yet, the manual helper (paste the token from the app, Test the file) stays as before. On multisite, only network administrators can publish the file.<\/li>\n<li>Settings: a \"Sign in or create an account\" button (the Sitelemetry sign-in page; new users create an account there on a free or paid plan) and a \"Get your API key\" link for a first setup.<\/li>\n<li>The running-audit status line is the plugin's own; it no longer shows the service's instructions for AI clients.<\/li>\n<li>Translations: Turkish, Spanish, German (informal and formal), French, Portuguese (Brazil), Italian, Japanese and Simplified Chinese ship with the plugin (WordPress 6.0 and later); translate.wordpress.org language packs take precedence.<\/li>\n<li>Audits are requested in your WordPress admin language when Sitelemetry supports it.<\/li>\n<li>Removed the \"Open the full report\" link and the remaining-scans lines: the service returns neither to the plugin, and no text promises a report in the app anymore.<\/li>\n<li>New directory name: Sitelemetry Audit \u2013 Security, SEO &amp; AI Readiness Scanner. The slug and settings are unchanged.<\/li>\n<\/ul>\n\n<h4>0.1.2<\/h4>\n\n<ul>\n<li>Plugin URI now points at the plugin repository; the author URI stays sitelemetry.com (WordPress.org requires the two to differ).<\/li>\n<\/ul>\n\n<h4>0.1.1<\/h4>\n\n<ul>\n<li>Tested with WordPress 7.1. Plugin Check (all categories) passes without errors or warnings.<\/li>\n<li>Description and Privacy sections link to the exact terms and privacy policy pages.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>First release: settings page, manual audits with progress polling, results page with severity filter and coverage notes, dashboard widget, optional weekly audit, plan and usage box.<\/li>\n<\/ul>","raw_excerpt":"Audit your site for security (free plan), SEO and AI readiness: a score, every finding with its fix, passing checks and an AI fix prompt.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/373566","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=373566"}],"author":[{"embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/ozandikici"}],"wp:attachment":[{"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=373566"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=373566"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=373566"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=373566"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=373566"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ast.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=373566"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}