Title: Klydexa Site Integrity Audit
Author: klydexa
Published: <strong>October 10, 2026</strong>
Last modified: October 10, 2026

---

Search plugins

![](https://ps.w.org/klydexa-site-integrity-audit/assets/banner-772x250.png?rev=
3737534)

![](https://ps.w.org/klydexa-site-integrity-audit/assets/icon-256x256.png?rev=3737534)

# Klydexa Site Integrity Audit

 By [klydexa](https://profiles.wordpress.org/klydexa/)

[Download](https://downloads.wordpress.org/plugin/klydexa-site-integrity-audit.1.3.0.zip)

 * [Details](https://wordpress.org/plugins/klydexa-site-integrity-audit/#description)
 * [Reviews](https://wordpress.org/plugins/klydexa-site-integrity-audit/#reviews)
 *  [Installation](https://wordpress.org/plugins/klydexa-site-integrity-audit/#installation)
 * [Development](https://wordpress.org/plugins/klydexa-site-integrity-audit/#developers)

 [Support](https://wordpress.org/support/plugin/klydexa-site-integrity-audit/)

## Description

Klydexa Site Integrity Audit audits the WordPress site it is installed on and explains
what it finds, with evidence.

Everything works locally. Twenty-four deterministic scanners read your plugin code,
database and configuration and produce findings that always cite a file, a line,
a query or a measurement. AI is optional: when you enable it, it explains and prioritises
findings the scanners already produced. It never replaces them, and the plugin is
fully usable with AI switched off.

**What it checks**

 * **Plugin inventory** – every plugin, must-use plugin and drop-in, with size, 
   update state, declared requirements and cached WordPress.org metadata.
 * **Security static analysis** – unprepared SQL, unsanitised request data, unescaped
   output, dynamic includes, `eval()`, shell execution, deserialisation, upload 
   handling and admin action authorisation.
 * **AJAX and REST authorisation** – handlers and routes missing nonce or capability
   checks, and publicly callable write endpoints.
 * **Vulnerability intelligence** – optional, consent-gated look-ups through a pluggable
   provider (WordPress.org listing status, Patchstack, WPScan, or your own endpoint).
 * **PHP compatibility** – removed and deprecated functions and language patterns
   for PHP 8.0 through 8.5, with explicit Confirmed / Likely / Potential labelling.
 * **WordPress compatibility** – declared support windows, block editor and REST
   surfaces, script modules, and WooCommerce HPOS declarations.
 * **Deprecated WordPress APIs** – catalogue-driven detection of deprecated functions,
   hooks, classes and constants.
 * **Database** – table sizes, plugin-created tables, tables left behind by removed
   plugins, revisions, spam and overhead.
 * **Autoloaded options** – total autoload payload, largest entries and plugin attribution.
 * **Scheduled events** – duplicates, very frequent schedules, overdue events, oversized
   payloads and events from inactive plugins.
 * **Transients and orphaned data** – expired transients, oversized cached payloads,
   and metadata whose parent record is gone.
 * **Unused plugins** – graded from level 1 (inactive) to level 5 (inactive, unreferenced,
   with a database footprint and no recent maintenance).
 * **Performance** – a single loopback measurement of the front page, plus an opt-
   in profiling session that records timing, memory and per-component query attribution
   for real requests.
 * **Assets** – registered and enqueued scripts and styles, missing files, unregistered
   dependencies, duplicate bundled libraries and handle collisions.
 * **JavaScript errors** – an opt-in browser diagnostics session that records uncaught
   errors, promise rejections and failed resource loads.
 * **Conflicts** – overlapping hooks, shortcodes, post types, REST namespaces, AJAX
   actions and duplicate symbols between plugins, scored with an explicit confidence
   percentage.
 * **Duplicate functionality** – plugins covering the same functional area, classified
   by slug, runtime signal or keyword.
 * **Code quality** – function length, nesting depth, duplicated symbols and files
   that could not be analysed.

**Honest reporting**

Every finding carries a severity _and_ a confidence level, so a heuristic is never
presented as a proven defect. When something cannot be determined, the plugin says“
Unable to verify” or “Not measured” rather than implying everything is fine. A quick
scan that skipped the security scanners shows those categories as unmeasured instead
of scoring them 100.

**Safe fixes**

Clean-up actions preview exactly what they will change, require explicit confirmation,
and store a rollback snapshot where a rollback is possible. Klydexa Site Integrity
Audit never edits third-party plugin source, never deletes a plugin, and never runs
a destructive action as a side effect.

### External services

Klydexa Site Integrity Audit makes **no external requests by default** and contains**
no telemetry**. Nothing is ever sent to the plugin authors.

Three optional features can make network requests. Each one is off by default and
requires both the master privacy switch and its own consent checkbox.

 1. **Vulnerability intelligence** – sends the plugin slug and installed version to
    the provider you configure, in order to look up published security advisories. 
    Supported providers:
 2.  * WordPress.org (api.wordpress.org, listing status only) – [Privacy Policy](https://wordpress.org/about/privacy/).
     * Patchstack (api.patchstack.com) – [Terms](https://patchstack.com/terms-and-conditions/),
       [Privacy Policy](https://patchstack.com/privacy-policy/).
     * WPScan (wpscan.com) – [Terms](https://wpscan.com/terms/), [Privacy Policy](https://automattic.com/privacy/).
     * A custom endpoint you supply – that operator’s own terms and privacy policy 
       apply.
        Disable under Settings, Security.
 3. **AI explanations** – sends structured scan findings (severity, category, title,
    plugin slug and, at the widest sharing scope, file paths and code snippets) to 
    an AI provider, in order to prioritise and explain findings in plain language. 
    Requests are routed through the **WordPress AI Client** (WordPress 7.0+): the provider
    is the one connected under Settings > Connectors, handled entirely by WordPress
    core. This plugin never sees or stores AI credentials, never contacts an AI service
    itself, and does not choose the destination; the site owner does, from whichever
    connector they add. Which provider’s terms and privacy policy apply depends on 
    the connector you choose. Disable under Settings, AI.

Endpoints for the optional vulnerability provider are checked before any request
is made. One that is, or resolves to, a private or reserved address is refused, 
so an endpoint field cannot be used to reach services inside your network.

 1. **Loopback measurement** – one HTTP request from your site to its own home page
    during a performance scan, so front-end assets and timing can be measured. No third
    party is involved. Disable under Settings, Performance.

Klydexa Site Integrity Audit never transmits passwords, authentication tokens, other
services’ API keys, post content, customer or order records, user data, or database
dumps.

## Screenshots

[⌊Dashboard with the health score, category scores and recommended next steps.⌉⌊
Dashboard with the health score, category scores and recommended next steps.⌉[

Dashboard with the health score, category scores and recommended next steps.

[⌊Running a scan, with live per-scanner progress.⌉⌊Running a scan, with live per-
scanner progress.⌉[

Running a scan, with live per-scanner progress.

[⌊A finding with its evidence, confidence and recommended action.⌉⌊A finding with
its evidence, confidence and recommended action.⌉[

A finding with its evidence, confidence and recommended action.

[⌊Database clean-up preview with the affected records and rollback state.⌉⌊Database
clean-up preview with the affected records and rollback state.⌉[

Database clean-up preview with the affected records and rollback state.

[⌊Settings, showing exactly what leaves the site and how to disable it.⌉⌊Settings,
showing exactly what leaves the site and how to disable it.⌉[

Settings, showing exactly what leaves the site and how to disable it.

## Installation

 1. Upload the `klydexa-site-integrity-audit` folder to `/wp-content/plugins/`, or 
    install the ZIP through Plugins, Add New, Upload Plugin.
 2. Activate the plugin.
 3. Open Klydexa Site Integrity Audit, Run scan, and choose a scan type. A standard
    scan is the usual starting point.

The plugin creates its own database tables and removes them on uninstall only if
you opt in under Settings, Advanced.

## FAQ

### Does it need an API key?

No. Every scanner runs locally. An API key is only relevant if you choose to enable
a vulnerability intelligence provider that requires one. AI explanations use the
WordPress AI Client (WordPress 7.0+) and whichever provider you have connected under
Settings > Connectors, so no AI key is ever entered into this plugin.

### Will it change my site?

Not by itself. Scanning is read-only. Clean-up actions exist, but each one previews
its effect, requires confirmation, and is reversible where technically possible.

### Does it modify plugin files?

Never. Klydexa Site Integrity Audit inspects, reports and recommends. The strongest
action it can take on a plugin is toggling activation, which WordPress itself supports
and which is recorded so it can be undone.

### A finding says my plugin might be insecure. Is it?

It means a risky pattern was found in the code, with a file and line reference. 
Static analysis cannot prove that a pattern is reachable or exploitable, which is
why every finding shows a confidence level. Read the evidence before acting, and
report genuine problems to the plugin developer.

### Is it safe on a big site?

Yes. Scans run in resumable steps with a time budget, results are cached against
file fingerprints, queries are indexed and bounded, and analysis of a very large
plugin stops at a limit and reports that it was incomplete rather than timing out.

### Does it work on multisite?

Yes. Data, settings and scans are per site. Tables are created for each site on 
first use. Network-activated plugins are identified as such, and their activation
state can only be changed by a network administrator.

### Can I export a PDF?

Reports render as a clean print-friendly page; use your browser’s print dialogue
to save as PDF. The plugin does not bundle a PDF library.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Klydexa Site Integrity Audit” is open source software. The following people have
contributed to this plugin.

Contributors

 *   [ klydexa ](https://profiles.wordpress.org/klydexa/)

[Translate “Klydexa Site Integrity Audit” into your language.](https://translate.wordpress.org/projects/wp-plugins/klydexa-site-integrity-audit)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/klydexa-site-integrity-audit/),
check out the [SVN repository](https://plugins.svn.wordpress.org/klydexa-site-integrity-audit/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/klydexa-site-integrity-audit/)
by [RSS](https://plugins.trac.wordpress.org/log/klydexa-site-integrity-audit/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.3.0

 * AI explanations now use only the WordPress core AI Client (WordPress 7.0+). The
   plugin no longer calls any AI provider’s API directly and no longer stores AI
   API keys; the directly-configured Anthropic and OpenAI-compatible providers were
   removed. Any AI key saved by an earlier version is discarded the next time AI
   settings are saved.
 * The profiler no longer defines `SAVEQUERIES`. Per-query attribution is used only
   when the site owner has already enabled it; otherwise only the total query count
   is recorded.
 * Directory locations (WordPress core, wp-content) are now discovered through WordPress
   APIs rather than hardcoded constants and folder names.
 * All database queries built by the plugin now use fixed, fully prepared SQL, including`%
   i` identifier placeholders for table names.

#### 1.2.0

 * Fixed a fatal error on PHP 7.4 – 7.x: several scanners and helpers called `str_starts_with()`/`
   str_contains()` / `str_ends_with()`, which are PHP 8.0+ only. The plugin now 
   includes polyfills for these functions so it runs cleanly on the minimum PHP 
   version it declares.
 * Removed the duplicate `Tested up to` plugin header from the main plugin file;
   it is now declared only in this readme, as required.

#### 1.1.0

 * Added an optional AI provider that uses the WordPress core AI Client (WordPress
   7.0+), so AI explanations can run through whichever provider is connected under
   Settings > Connectors instead of an API key entered into this plugin.
 * Documented the third-party services this plugin can optionally contact, with 
   links to each provider’s terms and privacy policy.
 * Removed a redundant `load_plugin_textdomain()` call; WordPress.org has served
   translations for this plugin automatically since WordPress 4.6.

#### 1.0.0

 * Initial release.

## Meta

 *  Version **1.3.0**
 *  Last updated **22 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [compatibility](https://wordpress.org/plugins/tags/compatibility/)[database](https://wordpress.org/plugins/tags/database/)
   [diagnostics](https://wordpress.org/plugins/tags/diagnostics/)[performance](https://wordpress.org/plugins/tags/performance/)
   [security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/klydexa-site-integrity-audit/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/klydexa-site-integrity-audit/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/klydexa-site-integrity-audit/reviews/)

## Contributors

 *   [ klydexa ](https://profiles.wordpress.org/klydexa/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/klydexa-site-integrity-audit/)