Title: Weio Site Check
Author: weioai
Published: <strong>October 4, 2026</strong>
Last modified: October 4, 2026

---

Search plugins

![](https://ps.w.org/weio-site-check/assets/banner-772x250.png?rev=3727422)

![](https://ps.w.org/weio-site-check/assets/icon-256x256.png?rev=3727422)

# Weio Site Check

 By [weioai](https://profiles.wordpress.org/weioai/)

[Download](https://downloads.wordpress.org/plugin/weio-site-check.1.0.0.zip)

 * [Details](https://wordpress.org/plugins/weio-site-check/#description)
 * [Reviews](https://wordpress.org/plugins/weio-site-check/#reviews)
 *  [Installation](https://wordpress.org/plugins/weio-site-check/#installation)
 * [Development](https://wordpress.org/plugins/weio-site-check/#developers)

 [Support](https://wordpress.org/support/plugin/weio-site-check/)

## Description

Weio Site Check runs eleven read-only checks on your own site and explains every
result in plain English: what was found, why it matters, and how to fix it yourself.
It changes nothing on your site.

**What makes it different:** most security plugins scan files for known malware 
signatures. Weio Site Check also looks at what visitors and Google actually receive:
spam shown only to a Googlebot user agent, redirects only for visitors arriving 
from Google, spam URLs in your sitemap, an SSL certificate that is about to expire,
and whether a WooCommerce shopper can reach checkout over https. It is one read-
only page with no account, no scanning service and no settings to learn.

Open **Tools > Site Check** and click **Run checks now**. A run takes up to about
30 seconds.

**The checks**

 1.  **HTTPS in WordPress settings**: both WordPress addresses start with https://.
 2.  **http to https redirect**: the http:// address sends visitors to https:// with
     a permanent (301 or 308) redirect.
 3.  **SSL certificate**: connects to your domain on port 443 from your server and 
     reads the certificate it is given: days until it expires, whether it matches your
     domain, and whether browsers trust it (self-signed or incomplete chain).
 4.  **Outside-in HTTPS check (optional, off by default)**: asks the Weio service to
     load your domain and its www twin from the public internet, the way a visitor 
     would. It also tests the www version of your address, which the local checks do
     not, and reports what a visitor sees, such as a “Not secure” label. Its view can
     differ from your server’s when your host resolves your own domain to itself or
     blocks the site from loading itself. If your site is on a subdomain and has no
     www version, that is reported as normal. See “External services” below.
 5.  **Mixed content**: http:// scripts, styles, frames, images and media in your homepage
     HTML.
 6.  **WordPress core files**: compares every core file with the official WordPress.
     org checksums, and lists extra PHP files in wp-admin and wp-includes.
 7.  **PHP files in uploads**: lists PHP files in the uploads folder and flags code
     patterns that are typical of backdoors.
 8.  **Spam and cloaking signs**: looks for injected casino, pharmacy and similar spam
     text, spam hidden with CSS, spam links, pages shown only to a Googlebot user agent(
     cloaking), redirects only for visitors arriving from Google, the “Japanese keyword
     hack”, spam URLs in your sitemap, and published posts with spam titles. Single
     ambiguous words (for example one news headline about a casino) are reported only
     as “worth a look”. These are signs, not proof of a hack. To compare views, the
     plugin loads your homepage once with a Googlebot user agent from your own server;
     a firewall may log or block this. Cloaking that checks a visitor’s IP address,
     not only the user agent, cannot be seen from your server.
 9.  **New administrator accounts**: administrators registered in the last 30 days.
 10. **WooCommerce store pages** (only when WooCommerce is active): cart, checkout 
     and account pages are set and published, checkout loads for a guest over https,
     and at least one payment method is enabled. A guest with an empty cart being sent
     from checkout to the cart is normal and reported as OK.
 11. **Homepage response time and size**, measured from your own server.

**Optional daily monitoring** (off by default): runs the same checks once a day 
with WP-Cron and emails the site admin address only when a check newly becomes a
problem.

**What this plugin is not**

 * It does not remove malware and it is not a firewall.
 * A pass is not a guarantee that a site is secure, and a warning is not proof of
   a hack.
 * It loads only your own site’s address (and its www version). If a page redirects
   to another site, the plugin reports the redirect and does not follow it. It never
   fetches addresses that someone types in.

**Privacy**

Apart from the WordPress.org checksum lookup (WordPress’s own service, used by the
core file check), nothing is sent outside your site unless you turn on the outside-
in check. The plugin has no tracking, no analytics and no ads, and it adds nothing
to your public pages. Most checks load your own homepage, sitemap and checkout page
from your own server, the same way a visitor would.

**About Weio**

Weio (weio.ai) is an AI-operated company that makes this plugin. Next to a check
with a problem, the results page shows a “Have Weio fix it” link to a matching paid
service: HTTPS and SSL fix ($99 fixed price), hacked site cleanup ($199 for one 
site; complex cases are quoted first) or WordPress speed fix ($249 fixed price).
The HTTPS and speed links also appear next to a warning from those checks; the cleanup
link never appears next to a warning. These services are optional; every check and
every fix instruction works without them.

### External services

This plugin can connect to two external services.

**1. Weio HTTPS check API (weio.ai), only if you turn it on**

 * What it is: the outside-in HTTPS check (check 4). It is provided by Weio, the
   maker of this plugin, at https://weio.ai/api/https-check
 * When it is used: only when you have ticked “Outside-in HTTPS check” in Tools 
   > Site Check (off by default), and then only during a check run: when you click“
   Run checks now”, or once a day if you also turned on daily monitoring. It is 
   never called on activation, on page loads or in the background otherwise.
 * What is sent: your site’s domain name (for example example.com), a user agent
   string naming this plugin, and, only if you saved one, your Weio API key in an
   Authorization header. No user data, email addresses, content, plugin list or 
   WordPress version is sent. As with any web request, Weio sees the IP address 
   of your server.
 * What Weio keeps: the domain name, the time and the result of each check. Your
   server’s IP address is used only in memory for rate limiting and is not stored.
   Weio’s web server keeps short-lived request logs that identify the caller by 
   a salted one-way hash, never the IP address. For calls made with a key, the domain
   is logged with a short prefix of a one-way hash of the key, and a key is linked
   to the email used to buy it.
 * Limits and keys: without a key the check is free, within a service-side rate 
   limit (currently 5 checks per minute and 20 per day per server IP address, and
   a pool of 300 per day shared by all free users, including the free check page
   on weio.ai). When the limit is reached the plugin says so and the check works
   again the next day. An optional API key ($9 for 1,000 checks, valid 12 months,
   https://weio.ai/services/site-check-api.html) is not subject to the shared free
   limit. The key unlocks no code in this plugin; all other checks never need a 
   key or registration.
 * Terms of use: https://weio.ai/terms.html#api
 * Privacy policy: https://weio.ai/privacy.html#api

**2. WordPress.org checksums API (api.wordpress.org)**

 * What it is: the official list of checksums of WordPress core files, used by the
   core file check (check 6). It is the same service WordPress itself uses for updates.
 * When it is used: during each check run (manual, or daily if monitoring is on).
 * What is sent: your WordPress version and site language (locale), in a request
   to https://api.wordpress.org/core/checksums/1.0/ with a user agent naming this
   plugin. Your site address is not sent.
 * Terms and privacy: https://wordpress.org/about/privacy/

Links to weio.ai on the results page (service pages, the free speed report form,
API key information) are ordinary links. Following them sends nothing from your 
site; the free speed report is a form you fill in yourself on weio.ai.

## Installation

 1. Install and activate the plugin from Plugins > Add New, or upload the weio-site-
    check folder to /wp-content/plugins/.
 2. Go to Tools > Site Check and click “Run checks now”.
 3. Optional: in the Settings section of the same page, turn on the outside-in HTTPS
    check or daily monitoring.

## FAQ

### Is it free?

Yes. All eleven checks are free and work without an account, key or registration.
The optional outside-in check runs on the Weio service with a free, shared daily
limit; if you want to run it more often, a paid API key ($9 for 1,000 checks) lifts
that limit. The fix services linked from the results page are optional and priced
separately.

### Does it change anything on my site?

No. The checks only read files, settings and your own pages. The plugin stores its
settings and the last results in the WordPress database and deletes them when you
uninstall it.

### Who can run the checks?

Users with the manage_options capability (administrators). On multisite, only super
admins, because the core file check reads files that all sites of the network share.

### A check says “skipped”. Why?

Some checks do not apply to every site (for example WooCommerce, or the redirect
check on a site without https). Others are skipped when your host blocks the site
from loading its own pages, or when a service does not answer in time. The result
explains which.

### The spam check found a warning. Am I hacked?

Not necessarily. Weak signs, such as one gambling word or one link to a casino, 
are often legitimate. Strong signs, such as spam hidden with CSS or content shown
only to Googlebot, deserve a closer look. Use the URL Inspection tool in Google 
Search Console to see what Google sees.

### My firewall logged a fake Googlebot from my own server. Is that this plugin?

Yes, if it happened during a check run. To compare what search engines and visitors
see, the spam check loads your homepage once with a Googlebot user agent. A firewall
may log or block that request; that is harmless, and you can allow your server’s
own IP address if you want the comparison to run.

### Why does the SSL check fail on my local or staging site?

Local sites usually run on http:// or with a self-signed certificate, so the HTTPS
checks report that. That is expected and harmless on a site that is not public.

### Do you offer support?

Yes. Use the support forum for this plugin on WordPress.org.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Weio Site Check” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ weioai ](https://profiles.wordpress.org/weioai/)

[Translate “Weio Site Check” into your language.](https://translate.wordpress.org/projects/wp-plugins/weio-site-check)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/weio-site-check/), 
check out the [SVN repository](https://plugins.svn.wordpress.org/weio-site-check/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/weio-site-check/)
by [RSS](https://plugins.trac.wordpress.org/log/weio-site-check/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * First release: eleven checks, optional outside-in HTTPS check, optional daily
   monitoring with email on new problems.

## Meta

 *  Version **1.0.0**
 *  Last updated **9 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [health check](https://wordpress.org/plugins/tags/health-check/)[https](https://wordpress.org/plugins/tags/https/)
   [malware](https://wordpress.org/plugins/tags/malware/)[security](https://wordpress.org/plugins/tags/security/)
   [ssl](https://wordpress.org/plugins/tags/ssl/)
 *  [Advanced View](https://wordpress.org/plugins/weio-site-check/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/weio-site-check/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/weio-site-check/reviews/)

## Contributors

 *   [ weioai ](https://profiles.wordpress.org/weioai/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/weio-site-check/)