{"id":369460,"date":"2026-10-10T02:53:18","date_gmt":"2026-10-10T02:53:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/klydexa-coreguard\/"},"modified":"2026-10-10T02:52:49","modified_gmt":"2026-10-10T02:52:49","slug":"klydexa-site-integrity-audit","status":"publish","type":"plugin","link":"https:\/\/fur.wordpress.org\/plugins\/klydexa-site-integrity-audit\/","author":23506772,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.3.0","stable_tag":"1.3.0","tested":"7.1.3","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Klydexa Site Integrity Audit","header_author":"Klydexa","header_description":"Diagnose. Understand. Fix. Protect. Local-first WordPress health, security, compatibility, performance, database and plugin-conflict auditing with optional AI explanations.","assets_banners_color":"e8eff8","last_updated":"2026-10-10 02:52:49","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/klydexa.com\/site-integrity-audit\/","header_author_uri":"https:\/\/klydexa.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":64,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.3.0":{"tag":"1.3.0","author":"klydexa","date":"2026-10-10 02:52:49","revision":3737535}},"upgrade_notice":{"1.3.0":"<p>AI explanations now require WordPress 7.0+ and a provider connected under Settings &gt; Connectors. Direct Anthropic\/OpenAI-compatible API keys are no longer supported.<\/p>","1.2.0":"<p>Fixes a fatal error on PHP 7.4 - 7.x caused by PHP 8-only string functions. No action needed.<\/p>","1.1.0":"<p>Adds an optional, key-free AI provider for WordPress 7.0+ sites. No action needed; existing AI settings are unchanged.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3737534,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3737534,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3737534,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3737534,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.3.0"],"block_files":[],"assets_screenshots":{"screenshot-1.jpg":{"filename":"screenshot-1.jpg","revision":3737534,"resolution":"1","location":"assets","locale":"","width":1234,"height":609},"screenshot-2.jpg":{"filename":"screenshot-2.jpg","revision":3737534,"resolution":"2","location":"assets","locale":"","width":618,"height":595},"screenshot-3.jpg":{"filename":"screenshot-3.jpg","revision":3737534,"resolution":"3","location":"assets","locale":"","width":1337,"height":618},"screenshot-4.jpg":{"filename":"screenshot-4.jpg","revision":3737534,"resolution":"4","location":"assets","locale":"","width":1229,"height":616},"screenshot-5.jpg":{"filename":"screenshot-5.jpg","revision":3737534,"resolution":"5","location":"assets","locale":"","width":886,"height":510}},"screenshots":{"1":"Dashboard with the health score, category scores and recommended next steps.","2":"Running a scan, with live per-scanner progress.","3":"A finding with its evidence, confidence and recommended action.","4":"Database clean-up preview with the affected records and rollback state.","5":"Settings, showing exactly what leaves the site and how to disable it."}},"plugin_section":[],"plugin_tags":[3005,153,23519,247,600],"plugin_category":[54,59],"plugin_contributors":[275611],"plugin_business_model":[],"class_list":["post-369460","plugin","type-plugin","status-publish","hentry","plugin_tags-compatibility","plugin_tags-database","plugin_tags-diagnostics","plugin_tags-performance","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_category-utilities-and-tools","plugin_contributors-klydexa","plugin_committers-klydexa"],"banners":{"banner":"https:\/\/ps.w.org\/klydexa-site-integrity-audit\/assets\/banner-772x250.png?rev=3737534","banner_2x":"https:\/\/ps.w.org\/klydexa-site-integrity-audit\/assets\/banner-1544x500.png?rev=3737534","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/klydexa-site-integrity-audit\/assets\/icon-128x128.png?rev=3737534","icon_2x":"https:\/\/ps.w.org\/klydexa-site-integrity-audit\/assets\/icon-256x256.png?rev=3737534","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/klydexa-site-integrity-audit\/assets\/screenshot-1.jpg?rev=3737534","caption":"Dashboard with the health score, category scores and recommended next steps."},{"src":"https:\/\/ps.w.org\/klydexa-site-integrity-audit\/assets\/screenshot-2.jpg?rev=3737534","caption":"Running a scan, with live per-scanner progress."},{"src":"https:\/\/ps.w.org\/klydexa-site-integrity-audit\/assets\/screenshot-3.jpg?rev=3737534","caption":"A finding with its evidence, confidence and recommended action."},{"src":"https:\/\/ps.w.org\/klydexa-site-integrity-audit\/assets\/screenshot-4.jpg?rev=3737534","caption":"Database clean-up preview with the affected records and rollback state."},{"src":"https:\/\/ps.w.org\/klydexa-site-integrity-audit\/assets\/screenshot-5.jpg?rev=3737534","caption":"Settings, showing exactly what leaves the site and how to disable it."}],"raw_content":"<!--section=description-->\n<p>Klydexa Site Integrity Audit audits the WordPress site it is installed on and explains what it finds, with evidence.<\/p>\n\n<p>Everything works locally. Twenty-four deterministic scanners read your plugin code, database and configuration and produce findings that always cite a file, a line, a query or a measurement. AI is optional: when you enable it, it explains and prioritises findings the scanners already produced. It never replaces them, and the plugin is fully usable with AI switched off.<\/p>\n\n<p><strong>What it checks<\/strong><\/p>\n\n<ul>\n<li><strong>Plugin inventory<\/strong> - every plugin, must-use plugin and drop-in, with size, update state, declared requirements and cached WordPress.org metadata.<\/li>\n<li><strong>Security static analysis<\/strong> - unprepared SQL, unsanitised request data, unescaped output, dynamic includes, <code>eval()<\/code>, shell execution, deserialisation, upload handling and admin action authorisation.<\/li>\n<li><strong>AJAX and REST authorisation<\/strong> - handlers and routes missing nonce or capability checks, and publicly callable write endpoints.<\/li>\n<li><strong>Vulnerability intelligence<\/strong> - optional, consent-gated look-ups through a pluggable provider (WordPress.org listing status, Patchstack, WPScan, or your own endpoint).<\/li>\n<li><strong>PHP compatibility<\/strong> - removed and deprecated functions and language patterns for PHP 8.0 through 8.5, with explicit Confirmed \/ Likely \/ Potential labelling.<\/li>\n<li><strong>WordPress compatibility<\/strong> - declared support windows, block editor and REST surfaces, script modules, and WooCommerce HPOS declarations.<\/li>\n<li><strong>Deprecated WordPress APIs<\/strong> - catalogue-driven detection of deprecated functions, hooks, classes and constants.<\/li>\n<li><strong>Database<\/strong> - table sizes, plugin-created tables, tables left behind by removed plugins, revisions, spam and overhead.<\/li>\n<li><strong>Autoloaded options<\/strong> - total autoload payload, largest entries and plugin attribution.<\/li>\n<li><strong>Scheduled events<\/strong> - duplicates, very frequent schedules, overdue events, oversized payloads and events from inactive plugins.<\/li>\n<li><strong>Transients and orphaned data<\/strong> - expired transients, oversized cached payloads, and metadata whose parent record is gone.<\/li>\n<li><strong>Unused plugins<\/strong> - graded from level 1 (inactive) to level 5 (inactive, unreferenced, with a database footprint and no recent maintenance).<\/li>\n<li><strong>Performance<\/strong> - a single loopback measurement of the front page, plus an opt-in profiling session that records timing, memory and per-component query attribution for real requests.<\/li>\n<li><strong>Assets<\/strong> - registered and enqueued scripts and styles, missing files, unregistered dependencies, duplicate bundled libraries and handle collisions.<\/li>\n<li><strong>JavaScript errors<\/strong> - an opt-in browser diagnostics session that records uncaught errors, promise rejections and failed resource loads.<\/li>\n<li><strong>Conflicts<\/strong> - overlapping hooks, shortcodes, post types, REST namespaces, AJAX actions and duplicate symbols between plugins, scored with an explicit confidence percentage.<\/li>\n<li><strong>Duplicate functionality<\/strong> - plugins covering the same functional area, classified by slug, runtime signal or keyword.<\/li>\n<li><strong>Code quality<\/strong> - function length, nesting depth, duplicated symbols and files that could not be analysed.<\/li>\n<\/ul>\n\n<p><strong>Honest reporting<\/strong><\/p>\n\n<p>Every finding carries a severity <em>and<\/em> a confidence level, so a heuristic is never presented as a proven defect. When something cannot be determined, the plugin says \"Unable to verify\" or \"Not measured\" rather than implying everything is fine. A quick scan that skipped the security scanners shows those categories as unmeasured instead of scoring them 100.<\/p>\n\n<p><strong>Safe fixes<\/strong><\/p>\n\n<p>Clean-up actions preview exactly what they will change, require explicit confirmation, and store a rollback snapshot where a rollback is possible. Klydexa Site Integrity Audit never edits third-party plugin source, never deletes a plugin, and never runs a destructive action as a side effect.<\/p>\n\n<h3>External services<\/h3>\n\n<p>Klydexa Site Integrity Audit makes <strong>no external requests by default<\/strong> and contains <strong>no telemetry<\/strong>. Nothing is ever sent to the plugin authors.<\/p>\n\n<p>Three optional features can make network requests. Each one is off by default and requires both the master privacy switch and its own consent checkbox.<\/p>\n\n<ol>\n<li><p><strong>Vulnerability intelligence<\/strong> - sends the plugin slug and installed version to the provider you configure, in order to look up published security advisories. Supported providers:<\/p>\n\n<ul>\n<li>WordPress.org (api.wordpress.org, listing status only) - <a href=\"https:\/\/wordpress.org\/about\/privacy\/\">Privacy Policy<\/a>.<\/li>\n<li>Patchstack (api.patchstack.com) - <a href=\"https:\/\/patchstack.com\/terms-and-conditions\/\">Terms<\/a>, <a href=\"https:\/\/patchstack.com\/privacy-policy\/\">Privacy Policy<\/a>.<\/li>\n<li>WPScan (wpscan.com) - <a href=\"https:\/\/wpscan.com\/terms\/\">Terms<\/a>, <a href=\"https:\/\/automattic.com\/privacy\/\">Privacy Policy<\/a>.<\/li>\n<li>A custom endpoint you supply - that operator's own terms and privacy policy apply.\nDisable under Settings, Security.<\/li>\n<\/ul><\/li>\n<li><p><strong>AI explanations<\/strong> - sends structured scan findings (severity, category, title, plugin slug and, at the widest sharing scope, file paths and code snippets) to an AI provider, in order to prioritise and explain findings in plain language. Requests are routed through the <strong>WordPress AI Client<\/strong> (WordPress 7.0+): the provider is the one connected under Settings &gt; Connectors, handled entirely by WordPress core. This plugin never sees or stores AI credentials, never contacts an AI service itself, and does not choose the destination; the site owner does, from whichever connector they add. Which provider's terms and privacy policy apply depends on the connector you choose. Disable under Settings, AI.<\/p><\/li>\n<\/ol>\n\n<p>Endpoints for the optional vulnerability provider are checked before any request is made. One that is, or resolves to, a private or reserved address is refused, so an endpoint field cannot be used to reach services inside your network.<\/p>\n\n<ol>\n<li><strong>Loopback measurement<\/strong> - one HTTP request from your site to its own home page during a performance scan, so front-end assets and timing can be measured. No third party is involved. Disable under Settings, Performance.<\/li>\n<\/ol>\n\n<p>Klydexa Site Integrity Audit never transmits passwords, authentication tokens, other services' API keys, post content, customer or order records, user data, or database dumps.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>klydexa-site-integrity-audit<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the ZIP through Plugins, Add New, Upload Plugin.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Open Klydexa Site Integrity Audit, Run scan, and choose a scan type. A standard scan is the usual starting point.<\/li>\n<\/ol>\n\n<p>The plugin creates its own database tables and removes them on uninstall only if you opt in under Settings, Advanced.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20it%20need%20an%20api%20key%3F\"><h3>Does it need an API key?<\/h3><\/dt>\n<dd><p>No. Every scanner runs locally. An API key is only relevant if you choose to enable a vulnerability intelligence provider that requires one. AI explanations use the WordPress AI Client (WordPress 7.0+) and whichever provider you have connected under Settings &gt; Connectors, so no AI key is ever entered into this plugin.<\/p><\/dd>\n<dt id=\"will%20it%20change%20my%20site%3F\"><h3>Will it change my site?<\/h3><\/dt>\n<dd><p>Not by itself. Scanning is read-only. Clean-up actions exist, but each one previews its effect, requires confirmation, and is reversible where technically possible.<\/p><\/dd>\n<dt id=\"does%20it%20modify%20plugin%20files%3F\"><h3>Does it modify plugin files?<\/h3><\/dt>\n<dd><p>Never. Klydexa Site Integrity Audit inspects, reports and recommends. The strongest action it can take on a plugin is toggling activation, which WordPress itself supports and which is recorded so it can be undone.<\/p><\/dd>\n<dt id=\"a%20finding%20says%20my%20plugin%20might%20be%20insecure.%20is%20it%3F\"><h3>A finding says my plugin might be insecure. Is it?<\/h3><\/dt>\n<dd><p>It means a risky pattern was found in the code, with a file and line reference. Static analysis cannot prove that a pattern is reachable or exploitable, which is why every finding shows a confidence level. Read the evidence before acting, and report genuine problems to the plugin developer.<\/p><\/dd>\n<dt id=\"is%20it%20safe%20on%20a%20big%20site%3F\"><h3>Is it safe on a big site?<\/h3><\/dt>\n<dd><p>Yes. Scans run in resumable steps with a time budget, results are cached against file fingerprints, queries are indexed and bounded, and analysis of a very large plugin stops at a limit and reports that it was incomplete rather than timing out.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20multisite%3F\"><h3>Does it work on multisite?<\/h3><\/dt>\n<dd><p>Yes. Data, settings and scans are per site. Tables are created for each site on first use. Network-activated plugins are identified as such, and their activation state can only be changed by a network administrator.<\/p><\/dd>\n<dt id=\"can%20i%20export%20a%20pdf%3F\"><h3>Can I export a PDF?<\/h3><\/dt>\n<dd><p>Reports render as a clean print-friendly page; use your browser's print dialogue to save as PDF. The plugin does not bundle a PDF library.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>AI explanations now use only the WordPress core AI Client (WordPress 7.0+). The plugin no longer calls any AI provider's API directly and no longer stores AI API keys; the directly-configured Anthropic and OpenAI-compatible providers were removed. Any AI key saved by an earlier version is discarded the next time AI settings are saved.<\/li>\n<li>The profiler no longer defines <code>SAVEQUERIES<\/code>. Per-query attribution is used only when the site owner has already enabled it; otherwise only the total query count is recorded.<\/li>\n<li>Directory locations (WordPress core, wp-content) are now discovered through WordPress APIs rather than hardcoded constants and folder names.<\/li>\n<li>All database queries built by the plugin now use fixed, fully prepared SQL, including <code>%i<\/code> identifier placeholders for table names.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Fixed a fatal error on PHP 7.4 - 7.x: several scanners and helpers called <code>str_starts_with()<\/code> \/ <code>str_contains()<\/code> \/ <code>str_ends_with()<\/code>, which are PHP 8.0+ only. The plugin now includes polyfills for these functions so it runs cleanly on the minimum PHP version it declares.<\/li>\n<li>Removed the duplicate <code>Tested up to<\/code> plugin header from the main plugin file; it is now declared only in this readme, as required.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added an optional AI provider that uses the WordPress core AI Client (WordPress 7.0+), so AI explanations can run through whichever provider is connected under Settings &gt; Connectors instead of an API key entered into this plugin.<\/li>\n<li>Documented the third-party services this plugin can optionally contact, with links to each provider's terms and privacy policy.<\/li>\n<li>Removed a redundant <code>load_plugin_textdomain()<\/code> call; WordPress.org has served translations for this plugin automatically since WordPress 4.6.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Diagnose. Understand. Fix. Protect. Local-first health, security, compatibility, performance, database and plugin-conflict auditing for WordPress.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/369460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=369460"}],"author":[{"embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/klydexa"}],"wp:attachment":[{"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=369460"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=369460"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=369460"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=369460"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=369460"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/fur.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=369460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}