Title: BuildWithHumza Go Live Check
Author: Mohammad Humza
Published: <strong>September 29, 2026</strong>
Last modified: September 29, 2026

---

Search plugins

![](https://ps.w.org/buildwithhumza-go-live-check/assets/banner-772x250.png?rev=
3719833)

![](https://ps.w.org/buildwithhumza-go-live-check/assets/icon-256x256.png?rev=3719833)

# BuildWithHumza Go Live Check

 By [Mohammad Humza](https://profiles.wordpress.org/mohammadhumza/)

[Download](https://downloads.wordpress.org/plugin/buildwithhumza-go-live-check.1.1.0.zip)

 * [Details](https://wordpress.org/plugins/buildwithhumza-go-live-check/#description)
 * [Reviews](https://wordpress.org/plugins/buildwithhumza-go-live-check/#reviews)
 *  [Installation](https://wordpress.org/plugins/buildwithhumza-go-live-check/#installation)
 * [Development](https://wordpress.org/plugins/buildwithhumza-go-live-check/#developers)

 [Support](https://wordpress.org/support/plugin/buildwithhumza-go-live-check/)

## Description

A common launch slip is easy to miss. A site is built on staging with **“Discourage
search engines from indexing this site”** ticked, it goes live, and nobody unticks
it. The site looks normal to visitors, but it asks search engines not to index it,
and the only sign is a short line in the dashboard’s At a Glance box.

BuildWithHumza Go Live Check adds one page under **Tools** that looks for that and
nineteen other launch leftovers, scores the site out of 100, and tells you exactly
where to fix each one.

It changes nothing. It only reports.

#### What it checks

**Search engines**

 * **Search engine visibility** – whether the site is still asking search engines
   not to index it
 * **robots.txt file** – whether a real file in the site root blocks every crawler,
   which overrides the Reading setting and is invisible in the dashboard
 * **Permalinks** – still set to plain, so URLs look like `?p=123`

**Security**

 * **Secure connection** – whether the site address is still plain http
 * **Debug mode** – whether `WP_DEBUG` is on, and whether errors are being printed
   to visitors along with your file paths
 * **Guessable usernames** – accounts called admin, administrator, root, test and
   the rest of the list bots try first
 * **Open registration** – anyone can register, and what role they are handed when
   they do
 * **Built in file editor** – whether `DISALLOW_FILE_EDIT` is set

**Configuration**

 * **Site address** – whether WordPress still thinks it lives on a staging, local
   or IP address
 * **Site title** – empty or still a placeholder
 * **Site tagline** – still “Just another WordPress site”, which many themes print
   in the header
 * **Site icon** – missing, so browser tabs show a blank placeholder
 * **Administration email** – still a placeholder address, so password resets and
   update notices go nowhere
 * **Timezone** – never set, so scheduled posts fire at the wrong local time

**Leftover content**

 * **Default post** – the “Hello world!” post still published
 * **Default page** – the “Sample Page” still published
 * **Default category** – posts still filed under “Uncategorized”
 * **Privacy policy** – not set, or set to a page that was never published
 * **Comment moderation** – comments open with nothing held for approval, so the
   first spam run publishes itself

**Maintenance**

 * **Pending updates** – core, plugin or theme updates already waiting at handover

#### A score, and a report you can send

Every run produces a score out of 100. Critical checks weigh three times a recommendation,
so the number moves for the things that actually matter.

**Copy report** puts a plain text summary on your clipboard, ready to paste into
an email. **Download report** saves a standalone HTML page named after the site 
and dated: it opens in any browser with no stylesheet to fetch, and printing it 
saves a tidy PDF. Both are written for somebody who does not have a login.

#### Set a check aside

Some findings are deliberate. A brochure site with no comments does not need a privacy
policy warning forever. **Set aside** removes a row from the score and parks it 
at the bottom of the report, marked as a decision rather than an oversight, and 
one click brings it back.

#### In the places you already look

The findings also appear in **Tools > Site Health**, and as a dashboard widget with
the score and the three worst rows. If a check fails at the critical level, administrators
see one notice with a link to the report, which can be dismissed for good.

#### For developers

    ```
    wp go-live-check run
    wp go-live-check run --format=json
    wp go-live-check run --failures-only
    ```

The command exits with an error when a critical check fails, so it can gate a deploy
script. Add `--format=markdown` or `--format=html` for the same report the browser
produces.

Two filters are available. `bwh_glc_checks` registers or removes a check, and `bwh_glc_capability`
changes who may see the report.

#### Why not just use a checklist

A written checklist relies on you remembering to open it, and on being honest about
ticking items you did not actually verify. This reads the site’s real configuration
every time you open the page, so it reports what is actually set, not what someone
remembers setting.

It is also useful on sites you did not build. Open it on an inherited site and you
will know in a few seconds whether the previous developer left anything behind.

#### Accurate about debug mode

    ```
    WP_DEBUG on with `WP_DEBUG_DISPLAY` off is a normal production setup for sites that log errors to a file. That combination is reported as a recommendation, not a failure. Only errors visible to visitors are treated as critical, because that is what leaks file paths and stack traces.
    ```

#### Careful about false alarms

The default post check matches the exact title, so a real article that happens to
contain the words “Hello world!” is not reported. Drafts are ignored, because nobody
can see them. The staging address check matches whole labels in the hostname, so`
dev-site.example.com` is flagged and `devonplumbing.co.uk` is not. A robots.txt 
that blocks one directory or one scraper is left alone; only a blanket block aimed
at every crawler counts.

#### Privacy

This plugin makes no external requests, loads no remote scripts and includes no 
tracking. The update check reads the data WordPress already keeps rather than asking
wordpress.org anything. It stores one option holding the checks you set aside, and
one user setting when you dismiss the notice. Both are removed when you delete the
plugin.

## Screenshots

[⌊The report under Tools: the launch score and the checks grouped by area.⌉⌊The 
report under Tools: the launch score and the checks grouped by area.⌉[

The report under Tools: the launch score and the checks grouped by area.

[⌊Each finding with the fix for it, and a link to set it aside.⌉⌊Each finding with
the fix for it, and a link to set it aside.⌉[

Each finding with the fix for it, and a link to set it aside.

[⌊Run again works through every check with a progress bar, without reloading the
page.⌉⌊Run again works through every check with a progress bar, without reloading
the page.⌉[

Run again works through every check with a progress bar, without reloading the page.

[⌊The downloaded report, ready to send to a client or save as a PDF.⌉⌊The downloaded
report, ready to send to a client or save as a PDF.⌉[

The downloaded report, ready to send to a client or save as a PDF.

## Installation

 1. Install through **Plugins > Add New**, or upload the folder to `/wp-content/plugins/`.
 2. Activate it.
 3. Go to **Tools > Go Live Check**.

Viewing the report requires the `manage_options` capability, because it describes
changes to site settings and `wp-config.php`.

## FAQ

### My WordPress site is not showing up in Google. Is this why?

It can be. If “Discourage search engines from indexing this site” is still ticked
under Settings > Reading, WordPress adds a noindex tag to every page and search 
engines drop the site. This plugin reports that as a critical problem on the first
line. It also checks for a robots.txt file in the site root that blocks crawling,
which is another cause and is not shown in the dashboard.

### Where is the search engine visibility setting in WordPress?

Settings > Reading, near the bottom, labelled “Search engine visibility”. Ticking
the box tells search engines not to index the site. It is intended for sites still
being built.

### Does this plugin change anything on my site?

No. Every check is read-only. It reports what it finds and tells you which screen
to change, and you make the change yourself.

### What does the username check mean?

It looks for an account whose login name is one of the obvious ones, such as admin
or administrator. It is not about the role. Bots try those names first, so an account
with one of them leaves only the password to guess.

### My administration email is a Gmail address. Is that a problem?

No. The check only flags reserved placeholder domains such as example.com, which
are left behind by local installs and never receive mail. Any real mailbox passes.

### Should WP_DEBUG be off on a live site?

Errors should never be displayed to visitors, because the output includes server
paths and stack traces. Logging errors to a file with `WP_DEBUG_DISPLAY` set to 
false is fine and often useful. This plugin distinguishes between the two.

### Does it slow down my site?

No. Nothing runs on the front end at all. The checks only run in the admin, when
you open the report, the dashboard or Site Health.

### Can I add my own checks?

Yes. Use the `bwh_glc_checks` filter to register a callable that returns one result
row, or to remove one of the built in checks.

### Does it work on multisite?

It reports on the site you run it from.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“BuildWithHumza Go Live Check” is open source software. The following people have
contributed to this plugin.

Contributors

 *   [ Mohammad Humza ](https://profiles.wordpress.org/mohammadhumza/)

[Translate “BuildWithHumza Go Live Check” into your language.](https://translate.wordpress.org/projects/wp-plugins/buildwithhumza-go-live-check)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/buildwithhumza-go-live-check/),
check out the [SVN repository](https://plugins.svn.wordpress.org/buildwithhumza-go-live-check/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/buildwithhumza-go-live-check/)
by [RSS](https://plugins.trac.wordpress.org/log/buildwithhumza-go-live-check/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.1.0

 * Eleven new checks: robots.txt, staging site address, https, open registration,
   the file editor, timezone, site title, default category, privacy policy, comment
   moderation and pending updates.
 * The username check now covers administrator, root, webmaster, test and other 
   obvious login names, not just “admin”.
 * Launch score out of 100, weighted so critical checks count for more.
 * Checks grouped by area: search engines, security, configuration, leftover content
   and maintenance.
 * Copy the report as text, or download it as a standalone HTML page that prints
   to PDF, to send to a client.
 * Set a check aside on a site where a finding is deliberate, and restore it later.
 * Results added to Site Health, a dashboard widget and a dismissible notice when
   a critical check fails.
 * WP-CLI: `wp go-live-check run`, `ignore` and `restore`.
 * New `bwh_glc_checks` filter for registering your own check.

#### 1.0.0

 * First release.
 * Nine launch checks covering indexing, debug output, default content, permalinks,
   admin username, tagline, site icon and administration email.
 * Results sorted worst first, each with the screen to fix it on.

## Meta

 *  Version **1.1.0**
 *  Last updated **23 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [launch checklist](https://wordpress.org/plugins/tags/launch-checklist/)[noindex](https://wordpress.org/plugins/tags/noindex/)
   [search engine visibility](https://wordpress.org/plugins/tags/search-engine-visibility/)
   [site health](https://wordpress.org/plugins/tags/site-health/)[staging](https://wordpress.org/plugins/tags/staging/)
 *  [Advanced View](https://wordpress.org/plugins/buildwithhumza-go-live-check/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/buildwithhumza-go-live-check/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/buildwithhumza-go-live-check/reviews/)

## Contributors

 *   [ Mohammad Humza ](https://profiles.wordpress.org/mohammadhumza/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/buildwithhumza-go-live-check/)