WordPress website audit checklist for a new client site
Short answer
Before you promise anything on a site you didn’t build, check five things: access (who has admin, hosting and domain logins), backups (do they exist, can you restore one), files (do WordPress and its plugins match the official versions), PHP (which version, when it ends, and whether the plugins are ready for the next one), and health (Site Health, error log, plugins no longer maintained). What you find sets the price and the first month’s work.
1. Access
Access
- WordPress administrators listed; unknown or former accounts noted for removal
- Hosting panel login, and who else has it
- Domain registrar and DNS: who controls them, when the domain renews
- Email delivery: which service sends the site’s emails
- Premium plugins and theme: licences, accounts, renewal dates
To keep it on paper, print this page: the website’s menus are left out.
2. Backups
Backups
- Where backups are stored, how often, how long they are kept
- One backup restored somewhere safe (a staging copy or a local site)
- Files and database included
To keep it on paper, print this page: the website’s menus are left out.
3. Files: does the code match the official versions?
WP-CLI compares WordPress and plugin files with the checksums wordpress.org publishes. On our test site:
Terminal · WP-CLI 2.12.0 on our test site (WordPress 7.1.2), 9 October 2026; real output
$ wp core verify-checksums
Success: WordPress installation verifies against checksums.
$ wp plugin verify-checksums hello-dolly
Success: Verified 1 of 1 plugins.Changed WordPress files, or plugins from wordpress.org whose files differ, are a red flag: someone edited them (and the next update will undo it), or something worse. Run wp plugin verify-checksums --all on the site you audit; premium and custom plugins have no published checksums and are skipped. The rest of the WP-CLI routine is in WP-CLI: update plugins safely.
4. PHP: version, end date, readiness
PHP
- PHP version from Tools → Site Health → Info → Server
- Its security end date on php.net (PHP 8.2: 31 December 2026)
- Every plugin and the theme checked for the next PHP version
- Plugins without an update in a long time listed: the usual cause of PHP problems
To keep it on paper, print this page: the website’s menus are left out.
This is the part of an audit most often skipped, and the one that turns into an emergency when the host announces a PHP upgrade. The dates are on php.net; which version to aim for is in the best PHP version for WordPress.
5. Health
Health
- Tools → Site Health → Status: critical issues and recommended improvements
- The PHP error log, or the WordPress debug log: fatal errors and warnings
- Required PHP modules present (what “required modules missing” means)
- Plugins installed but inactive: remove the ones nobody needs
To keep it on paper, print this page: the website’s menus are left out.
Site Health groups what it finds into “critical issues recommended improvements and passed tests” (wordpress.org).
Write it up
Give the client one page: what you checked, what’s fine, what needs work and in which order, and your price for it. The audit becomes the start of a maintenance plan, and the PHP findings are often its first project.
Key takeaways
- Access first: admin users, hosting, domain, DNS, email, premium licences.
- A backup only counts once you have restored it somewhere safe.
wp core verify-checksumsandwp plugin verify-checksums --allshow files that differ from the official ones.- Note the PHP version, its end date, and whether every plugin and the theme are ready for the next version.
- Write the findings up for the client: they justify the price and the first month’s work.
Frequently asked questions
How long does a WordPress audit take?
It depends on the size of the site and what you find. Time your first few audits and use the average in your quotes; plan more for sites with custom code.
Should I charge for the audit?
Many agencies do, or include it in the first month of a plan. Either way, it protects you from promising a price before you know the site.
What is the most common surprise?
Plugins that haven’t been updated in years, and a PHP version close to the end of its security fixes. Both are cheap to find early and expensive to discover when the host moves the site.
Check your own site before you upgrade
CompatNav is a free WordPress plugin. It reads the code of your plugins and themes on your own server and tells you, in plain words, what will break and what will only show notices on the PHP version you choose. It never changes your code. It can’t see problems that only appear while code runs with real data, so a quick check of your site after the upgrade still matters.
Sources
- developer.wordpress.org: wp plugin verify-checksums
- wordpress.org: Site Health screen
- php.net: Supported Versions
About the code examples: each output is the real output of the code shown, run with the official PHP builds, without a php.ini, with all errors reported and displayed. Only the file path was replaced by a neutral server path.