NX::Site SEO Audit

Description

NX::Site SEO Audit is a professional, all-in-one SEO and site health toolkit for WordPress. With a global SEO Site Score (0–100), page-by-page status classification, advanced DB Optimizer, Security Tools, full database Backup & Restore, CSS/JS Minification Analyzer, multilingual support in 6 languages, and automatic email notifications for new critical issues.

Developed by NETSOLEX — https://www.netsolex.com

Core Features

Dashboard & SEO Score.

A unified control panel showing your global SEO Site Score (0–100), categorised issue counts (Critical, Warning, Info), recent audit history, and a full page-by-page status overview. At a glance you know which pages are healthy, which need improvement, and which have critical problems.

Meta Tags Analyzer.

Audit every post and page for title tags, meta descriptions, Open Graph tags (og:title, og:description, og:image, og:type), Twitter Cards, canonical URLs, robots meta directives (index/noindex/follow/nofollow), and Schema.org structured data. Highlights missing or duplicate entries immediately.

NX Meta Generator.

A per-page custom meta tag generator accessible directly from the post/page list. Lets you define:
* SEO Title (injected as <title> tag and used via WordPress pre_get_document_title filter)
* Meta Description
* Robots directives (index/noindex, follow/nofollow)
* Open Graph title, description, and image
* Twitter Card title, description, and image
* Schema.org type (Organization, Article, Product, LocalBusiness, etc.)
* Viewport, theme-color, revisit-after, language, googlebot, bingbot
* Canonical URL
* Article published/modified dates
* Facebook publisher URL

The generator produces a live HTML preview in the editor and injects all tags directly into the page <head> on the frontend. Includes a full-screen editor mode (nxmeta_edit) for a distraction-free workflow.

Headings Structure (H1–H6).

Analyses the heading hierarchy of every post and page. Detects missing H1 tags, multiple H1s on the same page, skipped heading levels, and empty headings. Helps ensure your content structure is accessible and SEO-friendly.

Images Audit.

Scans all images across your site for missing or empty ALT text, decorative images without alt="", oversized images, missing lazy-load attributes, and non-WebP formats. Displays full image URL, context, and post title per finding.

Links Analysis.

Crawls internal and external links on every post and page. Detects broken links (404, 5xx), redirected links, missing rel attributes, and nofollow patterns. Supports a configurable allowlist to exclude known external domains from reporting.

Content Analysis.

Evaluates content quality page by page: word count, readability, thin content detection (configurable minimum word count), and duplicate or near-duplicate paragraphs. Configurable thresholds for minimum word count, title length, and description length.

Keywords Analysis.

Extracts and ranks keywords by frequency across all audited posts and pages. Identifies keyword density, over-optimised content, and missing focus keywords.

Keyword Cannibalization Detector.

Identifies groups of pages competing for the same keyword, which can split ranking authority and confuse search engines. Helps you decide which page to consolidate, redirect, or mark canonical.

Duplicate Content Detector.

Compares content across posts and pages using similarity algorithms. Flags pages with a high content similarity score so you can consolidate or differentiate them.

Internal Link Graph.

Visualises the internal linking structure of your site as an interactive node graph. Identify orphan pages (no internal links pointing to them), over-linked pages, and link clusters.

Image Converter (WebP).

Converts existing JPEG and PNG images in your Media Library to WebP format directly from the WordPress admin. Reduces file sizes significantly without quality loss, improving Core Web Vitals.

SEO Recommendations (SEO Tips).

A curated list of actionable SEO tips and best practices, organised by priority. Helps less technical users understand what improvements to make and why.

Technical SEO.

Covers technical health checks including: robots.txt validation, XML sitemap presence, HTTPS enforcement, redirect chains, canonical conflicts, and page speed indicators.

Reports & Export.

Generate and download audit reports in CSV or PDF format. Export full issue lists, per-page breakdowns, and summary dashboards for clients or team review.

Sitemap Generator (XML).

Automatically generates and updates an XML sitemap for posts, pages, and custom post types. Configurable priorities and change frequencies.

DB Optimizer.

A powerful database maintenance tool that cleans: post revisions, auto-draft posts, trashed posts, transients (expired and all), orphaned post meta, comment meta, spam comments, and more. All operations are listed with row counts before you confirm. Supports WP-Cron automation for scheduled cleanups.

Minify Analyzer.

Analyses your site’s CSS and JS assets for minification opportunities. Lists all enqueued scripts and styles with their sizes, minification status, and potential savings.

Security & SEO Tools.

XML-RPC Security — Disable XML-RPC completely to block DDoS amplification attacks, brute-force via pingbacks, and remote publishing exploits.
.htaccess File Management — View, edit, and save your .htaccess file directly from the admin. Create a new one from defaults if it is missing.
robots.txt File Management — View, edit, optimise, and save your robots.txt. Load default templates or add your sitemap reference automatically.
wp-config.php File Management — Read and edit wp-config.php with built-in safeguards.
File Permissions Manager — View and set correct file/folder permissions (755/644) for all WordPress core paths.
Force HTTPS — One-click redirect to enforce HTTPS site-wide via .htaccess.
Sitemap in robots.txt — Automatically append the sitemap URL to your robots.txt.

Backup & Restore.

Full database backup to a downloadable SQL file. Restore from a previously downloaded backup. Backups are stored in a protected uploads directory (with .htaccess and index.php guards).

NX Plugin Administrator.

A password-protected admin area within the plugin for managing advanced settings, rate limiting, and access control. Separate from the standard WordPress admin role system.

Email Notifications & SMTP.

Configure automatic email alerts when new critical SEO issues are detected. Supports custom SMTP configuration (host, port, TLS/SSL, authentication, from name/email) for reliable delivery.

Settings.

Configurable options include:
* Post types to audit (posts, pages, custom post types)
* Minimum word count threshold
* Maximum title length (default 60 characters)
* Maximum description length (default 160 characters)
* Audit batch limit
* Items per page for each module
* Plugin language
* Email notification address
* SMTP configuration
* Link allowlist
* WebP, lazy-load, and image dimension checks
* Show/hide developer badge on the frontend
* Delete plugin tables on deactivation

Multilingual Support
The plugin interface is fully translated into:
* English (default)
* Spanish (es_ES)
* German (de_DE)
* French (fr_FR)
* Italian (it_IT)
* Portuguese (pt_PT)

Language is selectable from the plugin Settings page, independently of the WordPress site language.

System Requirements

WordPress: 5.8 or higher (tested up to 7.0)
PHP: 7.4.3 or higher (PHP 8.3+ recommended)
MySQL / MariaDB: 5.6 or higher
Web Server: Apache (fully tested and supported). NGINX not tested — .htaccess-dependent features will not function on NGINX.
Browser: Any modern browser (Chrome, Firefox, Brave, Edge)
SSL: Recommended. The Force HTTPS feature requires an active SSL certificate.

Page Builder Compatibility:

✅ YOOtheme — Tested and confirmed working
* Elementor — Not yet tested
* WPBakery — Not yet tested
* Divi — Not yet tested

Privacy Policy & External Services

This plugin connects to external services in the following specific cases. All connections are either triggered explicitly by the user or are necessary for a core feature to work. No data is ever collected automatically in the background without user action.

  1. License Registration (voluntary — only when user submits the form)

When a user fills in and submits the License Registration form (Plugins Site SEO Audit License), the following data is sent to the NETSOLEX license server at https://www.netsolex.com/api/nxsa/register/:

  • Site domain (e.g. example.com)
  • Email address entered by the user
  • Name entered by the user (optional)
  • Plugin name and version number
  • A generated license key

This request is non-blocking — it does not slow down the page. No data is sent unless the user actively clicks the Register button.
The data is used solely to validate and record the license.
NETSOLEX Terms of Service: https://www.netsolex.com/terms-of-service/
NETSOLEX Privacy Policy: https://www.netsolex.com/privacy-policy/

  1. Plugin Update Checks (automatic — admin area only)

When a WordPress administrator visits the Plugins page or the Dashboard, WordPress performs its standard update check. This plugin participates in that check by contacting the NETSOLEX update API to verify whether a new version is available. The request includes the current plugin version and the site URL — no personal data is sent. This is standard WordPress plugin behaviour.
NETSOLEX Terms of Service: https://www.netsolex.com/terms-of-service/
NETSOLEX Privacy Policy: https://www.netsolex.com/privacy-policy/

  1. Sitemap Ping (automatic — only when sitemap is generated)

When an XML sitemap is generated or updated, the plugin sends a ping notification to https://www.google.com/ping and https://www.bing.com/ping with the public URL of your sitemap. This is standard search engine notification behaviour. No personal data is included.
Google Privacy Policy: https://policies.google.com/privacy
Microsoft/Bing Privacy Statement: https://privacy.microsoft.com/privacystatement

  1. External CSS/JS Asset Fetching (on-demand — admin only)

The Minify Analyzer fetches CSS and JS files from URLs already present on your site in order to analyse their minification status. These are requests to your own site assets or to public CDN URLs already loaded by your theme or plugins. No data is sent to NETSOLEX.

Screenshots

Installation

  1. Download the plugin ZIP file.
  2. In your WordPress admin go to Plugins Add New Upload Plugin.
  3. Choose the ZIP file and click Install Now.
  4. After installation click Activate Plugin.
  5. Navigate to Site SEO Audit in the left admin menu to start your first audit.

Alternatively, install via FTP by uploading the nx-site-seo-audit folder to /wp-content/plugins/ and activating from Plugins Installed Plugins.

FAQ

Does this plugin work with page builders?

YOOtheme — Tested and fully compatible.
Elementor — Not yet formally tested. The plugin operates at the WordPress core level (hooks and meta), so it should work in most cases, but compatibility is not officially guaranteed.
WPBakery (Visual Composer) — Not yet formally tested. Same considerations as Elementor apply.
Divi — Not yet formally tested. Same considerations as Elementor apply.

If you use one of the above builders and encounter issues, please report via the support tab.

What web server does this plugin support?

Apache — Fully tested and supported. .htaccess management features require Apache mod_rewrite.
NGINX — Not officially tested. The .htaccess and robots.txt file management features may not behave as expected on NGINX servers, as NGINX does not use .htaccess files. Other features (SEO audit, meta tags, backup) should still function normally.

Does the plugin slow down my site?

No. All audit operations run on demand from the admin area. The only frontend output is the meta tags injected into <head> (if NX Meta Generator is enabled for a page), which is negligible.

Will my data be deleted when I deactivate the plugin?

By default, no. You can enable the option Delete plugin database tables on deactivation from Settings if you want a clean uninstall.

Does it work with WooCommerce?

The plugin includes a dedicated eCommerce auditor (class-ecommerce-auditor.php) and can audit WooCommerce product pages when the product post type is added to the audit scope in Settings.

What PHP version is required?

PHP 7.4.3 or higher. PHP 8.3+ is recommended for best performance.

Is the plugin free?

Yes. Free for personal use without limits. Not licensed for commercial resale or redistribution.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“NX::Site SEO Audit” is open source software. The following people have contributed to this plugin.

Contributors

Translate “NX::Site SEO Audit” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

5.3.0

  • COMPLIANCE — Removed the free-form “paste your own code” input from the CSS/JS Minify & Unminify tool. It now only works on real, already-published CSS/JS files fetched from the site itself (via “Send to Minifier”), never on arbitrary typed/pasted code. The duplicate minifier previously also present in DB Optimizer has been removed; there is now a single tool, in Minify Analyzer.
  • SECURITY — Inline JSON passed to the Dashboard’s charts (wpsapPagesData, wpsapIssuesData) is no longer emitted with unescaped forward slashes, preventing a </script> sequence in page titles/URLs/issue text from being able to break out of the inline script block.
  • CODE QUALITY — Added a defensive shutdown-time safety net that flushes any output buffer the plugin may have left open, on top of auditing every ob_start()/ob_get_clean() pair in the codebase to confirm none of them can be interrupted by another component mid-buffer.
  • Renamed an unprefixed transient key in the upsell cache to use the plugin’s own prefix.

5.2.0

  • SECURITY/COMPLIANCE — Removed the wp-config.php raw code editor entirely. The plugin no longer offers any screen that saves free-form PHP into wp-config.php, .htaccess, or robots.txt. This also removed the associated backup/restore-by-timestamp feature for that editor, which is no longer needed.
  • COMPLIANCE — The plugin no longer writes to any file at the WordPress site root. The “Preventive Settings” tool in DB Optimizer (post revisions, autosave interval) now generates a ready-to-paste code snippet instead of editing wp-config.php directly. The Table Prefix Rename tool renames the database tables (unchanged) but no longer patches wp-config.php automatically; it now shows the exact $table_prefix line to paste in manually.
  • COMPLIANCE — robots.txt is now managed virtually through WordPress core’s own robots_txt filter when no physical robots.txt file exists at the site root, instead of writing a physical file. If a physical robots.txt already exists (owned by the site or another plugin), this plugin only offers to manage its file permissions and does not touch its content.
  • COMPLIANCE — .htaccess changes (Force HTTPS redirect, initial file creation) now go through WordPress core’s own insert_with_markers() and save_mod_rewrite_rules() functions instead of manual file read/write.
  • SECURITY — Completed a full sanitization pass across all AJAX and form-submission handlers: every $_POST/$_GET value is now explicitly wrapped with wp_unslash() before the appropriate sanitization function (sanitize_text_field(), sanitize_email(), sanitize_key(), absint(), etc.), including IP-detection headers used internally for rate limiting.
  • CODE QUALITY — Removed now-unused database-stored file-backup helper functions left over after the wp-config.php editor removal.

5.1.8

  • SECURITY — SMTP password now encrypted at rest.
    The SMTP password configured in Settings was previously stored in plain text in the WordPress database via update_option(). It is now encrypted using openssl_encrypt() with AES-128-CBC and WordPress-unique keys (wp_salt + AUTH_KEY) before being saved. The password is decrypted transparently when the mailer uses it. Falls back safely if OpenSSL is unavailable on the server.

  • SECURITY — SSRF protection added to Minify Analyzer endpoints.
    The AJAX endpoints that fetch CSS/JS assets accepted a URL from $_POST without validating the resolved IP address, which could allow requests to private or loopback network ranges. A new is_private_ip() helper now blocks requests to 127.0.0.1, 192.168.x.x, 10.x.x.x, 172.16.x.x and all reserved ranges using PHP’s FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE before any HTTP request is made.

  • CODE QUALITY — Documented sslverify disabled across all audit classes.
    Ten instances of ‘sslverify’ => false across class-ajax-handler.php, class-sitemap-generator.php, class-core.php, class-links-auditor.php, class-page-speed-auditor.php, and class-ecommerce-auditor.php now include inline comments explaining that SSL verification is intentionally disabled to support auditing of sites running on self-signed or locally-issued certificates in staging and local development environments.

5.1.7

  • BUG FIX — NX Meta Generator missing <title> tag on frontend: The SEO Title field was saved and visible in the NX Meta Generator preview, but the <title> tag was never injected into the actual page <head>. Added pre_get_document_title filter to override the WordPress default title, and added explicit <title> output inside output_meta_tags() when NX Meta Generator is enabled for a post/page.

5.1.6

  • Stable release. Meta Tags Generator with full Open Graph, Twitter Card, Schema.org, and robots directive support.
  • NX Meta Generator full-screen editor mode.
  • Sitemap Generator with WP-Cron support.
  • DB Optimizer with protected transient cleanup.
  • Security Tools: XML-RPC disable, .htaccess, robots.txt, wp-config.php management.
  • Backup & Restore with protected uploads directory.
  • Multilingual support: ES, DE, FR, IT, PT.
  • Internal Link Graph visualisation.
  • Keyword Cannibalization Detector.
  • Duplicate Content Detector.
  • Image Converter (WebP batch conversion).
  • Email Notifications with custom SMTP.
  • Rate Limiter and Admin Auth (NX Plugin Administrator).