Description
Klydexa Site Integrity Audit audits the WordPress site it is installed on and explains what it finds, with evidence.
Everything works locally. Twenty-four deterministic scanners read your plugin code, database and configuration and produce findings that always cite a file, a line, a query or a measurement. AI is optional: when you enable it, it explains and prioritises findings the scanners already produced. It never replaces them, and the plugin is fully usable with AI switched off.
What it checks
- Plugin inventory – every plugin, must-use plugin and drop-in, with size, update state, declared requirements and cached WordPress.org metadata.
- Security static analysis – unprepared SQL, unsanitised request data, unescaped output, dynamic includes,
eval(), shell execution, deserialisation, upload handling and admin action authorisation. - AJAX and REST authorisation – handlers and routes missing nonce or capability checks, and publicly callable write endpoints.
- Vulnerability intelligence – optional, consent-gated look-ups through a pluggable provider (WordPress.org listing status, Patchstack, WPScan, or your own endpoint).
- PHP compatibility – removed and deprecated functions and language patterns for PHP 8.0 through 8.5, with explicit Confirmed / Likely / Potential labelling.
- WordPress compatibility – declared support windows, block editor and REST surfaces, script modules, and WooCommerce HPOS declarations.
- Deprecated WordPress APIs – catalogue-driven detection of deprecated functions, hooks, classes and constants.
- Database – table sizes, plugin-created tables, tables left behind by removed plugins, revisions, spam and overhead.
- Autoloaded options – total autoload payload, largest entries and plugin attribution.
- Scheduled events – duplicates, very frequent schedules, overdue events, oversized payloads and events from inactive plugins.
- Transients and orphaned data – expired transients, oversized cached payloads, and metadata whose parent record is gone.
- Unused plugins – graded from level 1 (inactive) to level 5 (inactive, unreferenced, with a database footprint and no recent maintenance).
- Performance – a single loopback measurement of the front page, plus an opt-in profiling session that records timing, memory and per-component query attribution for real requests.
- Assets – registered and enqueued scripts and styles, missing files, unregistered dependencies, duplicate bundled libraries and handle collisions.
- JavaScript errors – an opt-in browser diagnostics session that records uncaught errors, promise rejections and failed resource loads.
- Conflicts – overlapping hooks, shortcodes, post types, REST namespaces, AJAX actions and duplicate symbols between plugins, scored with an explicit confidence percentage.
- Duplicate functionality – plugins covering the same functional area, classified by slug, runtime signal or keyword.
- Code quality – function length, nesting depth, duplicated symbols and files that could not be analysed.
Honest reporting
Every finding carries a severity and a confidence level, so a heuristic is never presented as a proven defect. When something cannot be determined, the plugin says “Unable to verify” or “Not measured” rather than implying everything is fine. A quick scan that skipped the security scanners shows those categories as unmeasured instead of scoring them 100.
Safe fixes
Clean-up actions preview exactly what they will change, require explicit confirmation, and store a rollback snapshot where a rollback is possible. Klydexa Site Integrity Audit never edits third-party plugin source, never deletes a plugin, and never runs a destructive action as a side effect.
External services
Klydexa Site Integrity Audit makes no external requests by default and contains no telemetry. Nothing is ever sent to the plugin authors.
Three optional features can make network requests. Each one is off by default and requires both the master privacy switch and its own consent checkbox.
-
Vulnerability intelligence – sends the plugin slug and installed version to the provider you configure, in order to look up published security advisories. Supported providers:
- WordPress.org (api.wordpress.org, listing status only) – Privacy Policy.
- Patchstack (api.patchstack.com) – Terms, Privacy Policy.
- WPScan (wpscan.com) – Terms, Privacy Policy.
- A custom endpoint you supply – that operator’s own terms and privacy policy apply.
Disable under Settings, Security.
-
AI explanations – sends structured scan findings (severity, category, title, plugin slug and, at the widest sharing scope, file paths and code snippets) to an AI provider, in order to prioritise and explain findings in plain language. Requests are routed through the WordPress AI Client (WordPress 7.0+): the provider is the one connected under Settings > Connectors, handled entirely by WordPress core. This plugin never sees or stores AI credentials, never contacts an AI service itself, and does not choose the destination; the site owner does, from whichever connector they add. Which provider’s terms and privacy policy apply depends on the connector you choose. Disable under Settings, AI.
Endpoints for the optional vulnerability provider are checked before any request is made. One that is, or resolves to, a private or reserved address is refused, so an endpoint field cannot be used to reach services inside your network.
- Loopback measurement – one HTTP request from your site to its own home page during a performance scan, so front-end assets and timing can be measured. No third party is involved. Disable under Settings, Performance.
Klydexa Site Integrity Audit never transmits passwords, authentication tokens, other services’ API keys, post content, customer or order records, user data, or database dumps.
Screenshots





Installation
- Upload the
klydexa-site-integrity-auditfolder to/wp-content/plugins/, or install the ZIP through Plugins, Add New, Upload Plugin. - Activate the plugin.
- Open Klydexa Site Integrity Audit, Run scan, and choose a scan type. A standard scan is the usual starting point.
The plugin creates its own database tables and removes them on uninstall only if you opt in under Settings, Advanced.
FAQ
-
Does it need an API key?
-
No. Every scanner runs locally. An API key is only relevant if you choose to enable a vulnerability intelligence provider that requires one. AI explanations use the WordPress AI Client (WordPress 7.0+) and whichever provider you have connected under Settings > Connectors, so no AI key is ever entered into this plugin.
-
Will it change my site?
-
Not by itself. Scanning is read-only. Clean-up actions exist, but each one previews its effect, requires confirmation, and is reversible where technically possible.
-
Does it modify plugin files?
-
Never. Klydexa Site Integrity Audit inspects, reports and recommends. The strongest action it can take on a plugin is toggling activation, which WordPress itself supports and which is recorded so it can be undone.
-
A finding says my plugin might be insecure. Is it?
-
It means a risky pattern was found in the code, with a file and line reference. Static analysis cannot prove that a pattern is reachable or exploitable, which is why every finding shows a confidence level. Read the evidence before acting, and report genuine problems to the plugin developer.
-
Is it safe on a big site?
-
Yes. Scans run in resumable steps with a time budget, results are cached against file fingerprints, queries are indexed and bounded, and analysis of a very large plugin stops at a limit and reports that it was incomplete rather than timing out.
-
Does it work on multisite?
-
Yes. Data, settings and scans are per site. Tables are created for each site on first use. Network-activated plugins are identified as such, and their activation state can only be changed by a network administrator.
-
Can I export a PDF?
-
Reports render as a clean print-friendly page; use your browser’s print dialogue to save as PDF. The plugin does not bundle a PDF library.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Klydexa Site Integrity Audit” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Klydexa Site Integrity Audit” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.3.0
- AI explanations now use only the WordPress core AI Client (WordPress 7.0+). The plugin no longer calls any AI provider’s API directly and no longer stores AI API keys; the directly-configured Anthropic and OpenAI-compatible providers were removed. Any AI key saved by an earlier version is discarded the next time AI settings are saved.
- The profiler no longer defines
SAVEQUERIES. Per-query attribution is used only when the site owner has already enabled it; otherwise only the total query count is recorded. - Directory locations (WordPress core, wp-content) are now discovered through WordPress APIs rather than hardcoded constants and folder names.
- All database queries built by the plugin now use fixed, fully prepared SQL, including
%iidentifier placeholders for table names.
1.2.0
- Fixed a fatal error on PHP 7.4 – 7.x: several scanners and helpers called
str_starts_with()/str_contains()/str_ends_with(), which are PHP 8.0+ only. The plugin now includes polyfills for these functions so it runs cleanly on the minimum PHP version it declares. - Removed the duplicate
Tested up toplugin header from the main plugin file; it is now declared only in this readme, as required.
1.1.0
- Added an optional AI provider that uses the WordPress core AI Client (WordPress 7.0+), so AI explanations can run through whichever provider is connected under Settings > Connectors instead of an API key entered into this plugin.
- Documented the third-party services this plugin can optionally contact, with links to each provider’s terms and privacy policy.
- Removed a redundant
load_plugin_textdomain()call; WordPress.org has served translations for this plugin automatically since WordPress 4.6.
1.0.0
- Initial release.
