The diagnosis is paid. If we then run the site, the fee is credited.
We do not start operating a site blind. First we look at what is there: from outside, or — with access — from inside and on the server too. The result is a written WPdoki Lelet, which is yours even if no subscription follows.
Example. The numbers are an illustration, not a real site's results.
Overall state
Availability99
Security73
Backup94
Performance58
Maintainability72
WP-017Outdated pluginHighOpen
Affected component
Plugin (example)
WPdoki can fix
Yes
Problem
The installed version is several releases behind the current one, and the release notes show a security fix it is missing.
Risk
A known, publicly documented flaw can be exploited for as long as the update is postponed.
Recommendation
Update tested in staging, a backup beforehand, a functional check afterwards.
Why is the assessment required?
Because a plan cannot responsibly be put on a site we do not know. The assessment tells us the state of the WordPress installation and the infrastructure, what the real risk is, and which plan fits. It is a standalone technical service with a standalone result.
What you receive
A written WPdoki Lelet: an overall score and one per area
Every finding with an ID, severity, risk and recommendation
A priority order: what is worth doing first
Marked: what we can fix, and what belongs to someone else
A recommendation on which plan fits the site — or that none does
Four depths
Access decides what we can inspect. The same report format, with more data at every level.
External diagnosis
29 900 Ft+ ÁFA
Requires: The site's address only
Availability, certificate, DNS, redirects
Security headers and WordPress exposure
Performance and Core Web Vitals
Publicly visible versions and known vulnerabilities
The assessment is a standalone technical service. Subscribe to any WPdoki plan within 30 days and its full fee is credited against your first invoices.
Prices are net, VAT is added.
Access levels
What can we see at each level of access?
How deep the monitoring goes depends on what you give us access to. A great deal is visible from outside; WordPress admin opens up the internal state; server access opens up the whole infrastructure.
Level 1 — public
Only the site's address. No admin, no server access.
Everything measurable from outside: availability, certificate, DNS, security headers, WordPress exposure, performance, and synthetic tests of the functions that matter.
Availability and response time
Certificate and DNS
Security HTTP headers
WordPress exposure
Core Web Vitals
Synthetic function tests
Full list
Availability
HTTP and HTTPS, status code, uptime
Redirect chain, response time
DNS lookup, TCP connect, TLS handshake, TTFB, page load
Everything from level 1, plus the internal state of WordPress: versions, updates, vulnerabilities, users, file integrity, database health and WooCommerce.
WP-Cron jobs, failed cron, Action Scheduler, object cache status
WooCommerce
WooCommerce version, database schema, scheduled and failed actions
Payment gateway state, webhook errors, REST, checkout and mail health
Third-party integration status
WordPress: Core version, pending updates, auto-update settings; Site Health, WP-Cron, loopback requests, REST health, permalink issues Plugins: Installed versions, update status, latest version; Vulnerability data, CVEs, abandoned plugins, repository status, compatibility; Inactive and unnecessary plugins Themes: Active, parent and child theme; Updates, vulnerabilities, unused themes Users: Administrators, new admins, role changes; Inactive admins, weak admin usernames, two-factor state where measurable File integrity: Modified core, plugin and theme files; Unexpected PHP files, executable files among uploads Application health: Database size, revisions, transients, autoloaded options, orphan metadata; WP-Cron jobs, failed cron, Action Scheduler, object cache status WooCommerce: WooCommerce version, database schema, scheduled and failed actions; Payment gateway state, webhook errors, REST, checkout and mail health; Third-party integration status
Level 3 — server / root
An SSH key to the server. Root or sudo where possible.
Everything from the previous levels, plus the whole infrastructure: operating system, services, PHP, web server, database, Redis, filesystem and server-level security.
Failed and successful SSH logins, root login, new Linux users, sudo usage, SSH key changes
Firewall and open port changes, fail2ban, brute force, suspicious processes and outbound connections
Malware and rootkit checks, cron/crontab changes
Operating system: Uptime, CPU, RAM, swap, load, disk, inode, IO wait, disk latency; Filesystem, kernel, reboot required, OS version and lifecycle; Package and security updates Services: Nginx, Apache, PHP-FPM, MySQL/MariaDB, Redis, cron, fail2ban; Postfix where relevant PHP: Version and lifecycle, extensions, memory_limit, max_execution_time, upload limits; OPcache and its hit rate, worker count, saturation, queues, max_children, slowlog Nginx / Apache: Requests/sec, connections, 2xx/3xx/4xx/5xx ratios, upstream errors, timeouts, latency; Worker saturation, access log anomalies, error logs MySQL: Connections and max_connections, slow queries, query latency, deadlocks, aborted connections; InnoDB buffer pool and hit ratio, temp tables, disk temp tables, locks; Database size, table growth, binlog growth, replication, backup state, corruption checks; WordPress-specific: wp_options and autoload size, postmeta and options growth, Action Scheduler tables, revisions, transients Redis: Availability, memory, hit ratio, evictions; Connected clients, expired keys, fragmentation, maxmemory Filesystem: File integrity, unexpected PHP, wp-config modifications, permissions, owner/group; World-writable files, .env, logs, executable uploads, symlink changes Security: Failed and successful SSH logins, root login, new Linux users, sudo usage, SSH key changes; Firewall and open port changes, fail2ban, brute force, suspicious processes and outbound connections; Malware and rootkit checks, cron/crontab changes
The same team, the same report — more simply becomes visible at every level.
Let us start with a report.
Send us your site's address and we will decide which assessment level fits. The result is a written WPdoki Lelet — and if we then run the site, the fee is credited.
No advertising cookies, no third-party tracker, and nothing passed to anyone else — it all stays on our own server. What we measure is how the site is to use, so that we can make it better.