Skip to content

Technical assessment

The diagnosis is paid. If we then run the site, the fee is credited.

We do not start operating a site blind. First we look at what is there: from outside, or — with access — from inside and on the server too. The result is a written WPdoki Lelet, which is yours even if no subscription follows.

WPdoki Lelet

Example. The numbers are an illustration, not a real site's results.
87
Overall state
  • Availability99
  • Security73
  • Backup94
  • Performance58
  • Maintainability72
WP-017Outdated pluginHighOpen
Affected component
Plugin (example)
WPdoki can fix
Yes
Problem
The installed version is several releases behind the current one, and the release notes show a security fix it is missing.
Risk
A known, publicly documented flaw can be exploited for as long as the update is postponed.
Recommendation
Update tested in staging, a backup beforehand, a functional check afterwards.

Why is the assessment required?

Because a plan cannot responsibly be put on a site we do not know. The assessment tells us the state of the WordPress installation and the infrastructure, what the real risk is, and which plan fits. It is a standalone technical service with a standalone result.

What you receive

  • A written WPdoki Lelet: an overall score and one per area
  • Every finding with an ID, severity, risk and recommendation
  • A priority order: what is worth doing first
  • Marked: what we can fix, and what belongs to someone else
  • A recommendation on which plan fits the site — or that none does

Four depths

Access decides what we can inspect. The same report format, with more data at every level.

External diagnosis

29 900 Ft+ ÁFA

Requires: The site's address only

  • Availability, certificate, DNS, redirects
  • Security headers and WordPress exposure
  • Performance and Core Web Vitals
  • Publicly visible versions and known vulnerabilities

Full WordPress diagnosis

59 900 Ft+ ÁFA

Requires: WordPress admin access

  • Everything in the external diagnosis
  • Plugins, themes, versions, vulnerabilities, abandoned components
  • Users, roles, file integrity
  • Database health, WP-Cron, Action Scheduler, WooCommerce

WordPress + server audit

119 900 Ft+ ÁFA

Requires: Admin + SSH / root access

  • Everything in the full WordPress diagnosis
  • OS, PHP, web server, MySQL and Redis state and configuration
  • Filesystem integrity and server-level security
  • Capacity, lifecycle and backup situation

Complex WooCommerce / infrastructure

149 900 Ftfrom + ÁFA

Requires: By agreement

  • Several servers, several sites or complex integrations
  • Checkout, payments, webhooks and scheduled actions examined separately
  • Load and scaling
  • A custom quote for the scope of the assessment

30-day credit

The assessment is a standalone technical service. Subscribe to any WPdoki plan within 30 days and its full fee is credited against your first invoices.

Prices are net, VAT is added.

Access levels

What can we see at each level of access?

How deep the monitoring goes depends on what you give us access to. A great deal is visible from outside; WordPress admin opens up the internal state; server access opens up the whole infrastructure.

Level 1 — public

Only the site's address. No admin, no server access.

Everything measurable from outside: availability, certificate, DNS, security headers, WordPress exposure, performance, and synthetic tests of the functions that matter.

  • Availability and response time
  • Certificate and DNS
  • Security HTTP headers
  • WordPress exposure
  • Core Web Vitals
  • Synthetic function tests
Full list

Availability

  • HTTP and HTTPS, status code, uptime
  • Redirect chain, response time
  • DNS lookup, TCP connect, TLS handshake, TTFB, page load

TLS

  • Certificate validity, expiry, chain
  • Hostname match, TLS version, HSTS

DNS

  • A, AAAA, CNAME, NS, MX, TXT
  • SPF, DMARC, DNSSEC
  • Record changes

HTTP security

  • HSTS, CSP, X-Frame-Options, X-Content-Type-Options
  • Referrer-Policy, Permissions-Policy, CORS
  • Cookie security

WordPress exposure

  • wp-login and wp-admin exposure, XML-RPC, wp-json, REST user enumeration
  • Version leakage, readme, license, directory listing, error leakage
  • Exposed backups, .git, .env, SQL and log files

Performance

  • TTFB, LCP, CLS, INP, FCP
  • Page size, request count, JS, CSS and image payload
  • Cache headers, compression, HTTP/2, HTTP/3, CDN

Synthetic tests

  • Homepage, contact page, search, contact form, login
  • WooCommerce cart, checkout, payment handoff
  • Critical API endpoints
Availability: HTTP and HTTPS, status code, uptime; Redirect chain, response time; DNS lookup, TCP connect, TLS handshake, TTFB, page load TLS: Certificate validity, expiry, chain; Hostname match, TLS version, HSTS DNS: A, AAAA, CNAME, NS, MX, TXT; SPF, DMARC, DNSSEC; Record changes HTTP security: HSTS, CSP, X-Frame-Options, X-Content-Type-Options; Referrer-Policy, Permissions-Policy, CORS; Cookie security WordPress exposure: wp-login and wp-admin exposure, XML-RPC, wp-json, REST user enumeration; Version leakage, readme, license, directory listing, error leakage; Exposed backups, .git, .env, SQL and log files Performance: TTFB, LCP, CLS, INP, FCP; Page size, request count, JS, CSS and image payload; Cache headers, compression, HTTP/2, HTTP/3, CDN Synthetic tests: Homepage, contact page, search, contact form, login; WooCommerce cart, checkout, payment handoff; Critical API endpoints

Level 2 — WordPress admin

Administrator access to WordPress.

Everything from level 1, plus the internal state of WordPress: versions, updates, vulnerabilities, users, file integrity, database health and WooCommerce.

  • Plugin and theme versions, vulnerabilities
  • Abandoned plugins
  • Administrators and roles
  • File integrity
  • WP-Cron, Action Scheduler
  • WooCommerce health
Full list

WordPress

  • Core version, pending updates, auto-update settings
  • Site Health, WP-Cron, loopback requests, REST health, permalink issues

Plugins

  • Installed versions, update status, latest version
  • Vulnerability data, CVEs, abandoned plugins, repository status, compatibility
  • Inactive and unnecessary plugins

Themes

  • Active, parent and child theme
  • Updates, vulnerabilities, unused themes

Users

  • Administrators, new admins, role changes
  • Inactive admins, weak admin usernames, two-factor state where measurable

File integrity

  • Modified core, plugin and theme files
  • Unexpected PHP files, executable files among uploads

Application health

  • Database size, revisions, transients, autoloaded options, orphan metadata
  • WP-Cron jobs, failed cron, Action Scheduler, object cache status

WooCommerce

  • WooCommerce version, database schema, scheduled and failed actions
  • Payment gateway state, webhook errors, REST, checkout and mail health
  • Third-party integration status
WordPress: Core version, pending updates, auto-update settings; Site Health, WP-Cron, loopback requests, REST health, permalink issues Plugins: Installed versions, update status, latest version; Vulnerability data, CVEs, abandoned plugins, repository status, compatibility; Inactive and unnecessary plugins Themes: Active, parent and child theme; Updates, vulnerabilities, unused themes Users: Administrators, new admins, role changes; Inactive admins, weak admin usernames, two-factor state where measurable File integrity: Modified core, plugin and theme files; Unexpected PHP files, executable files among uploads Application health: Database size, revisions, transients, autoloaded options, orphan metadata; WP-Cron jobs, failed cron, Action Scheduler, object cache status WooCommerce: WooCommerce version, database schema, scheduled and failed actions; Payment gateway state, webhook errors, REST, checkout and mail health; Third-party integration status

Level 3 — server / root

An SSH key to the server. Root or sudo where possible.

Everything from the previous levels, plus the whole infrastructure: operating system, services, PHP, web server, database, Redis, filesystem and server-level security.

  • CPU, memory, disk, inode, IO
  • Nginx / Apache, PHP-FPM, MySQL, Redis
  • OS and PHP lifecycle, security updates
  • Slow queries, buffer pool
  • SSH logins, firewall, fail2ban
  • Filesystem integrity
Full list

Operating system

  • Uptime, CPU, RAM, swap, load, disk, inode, IO wait, disk latency
  • Filesystem, kernel, reboot required, OS version and lifecycle
  • Package and security updates

Services

  • Nginx, Apache, PHP-FPM, MySQL/MariaDB, Redis, cron, fail2ban
  • Postfix where relevant

PHP

  • Version and lifecycle, extensions, memory_limit, max_execution_time, upload limits
  • OPcache and its hit rate, worker count, saturation, queues, max_children, slowlog

Nginx / Apache

  • Requests/sec, connections, 2xx/3xx/4xx/5xx ratios, upstream errors, timeouts, latency
  • Worker saturation, access log anomalies, error logs

MySQL

  • Connections and max_connections, slow queries, query latency, deadlocks, aborted connections
  • InnoDB buffer pool and hit ratio, temp tables, disk temp tables, locks
  • Database size, table growth, binlog growth, replication, backup state, corruption checks
  • WordPress-specific: wp_options and autoload size, postmeta and options growth, Action Scheduler tables, revisions, transients

Redis

  • Availability, memory, hit ratio, evictions
  • Connected clients, expired keys, fragmentation, maxmemory

Filesystem

  • File integrity, unexpected PHP, wp-config modifications, permissions, owner/group
  • World-writable files, .env, logs, executable uploads, symlink changes

Security

  • Failed and successful SSH logins, root login, new Linux users, sudo usage, SSH key changes
  • Firewall and open port changes, fail2ban, brute force, suspicious processes and outbound connections
  • Malware and rootkit checks, cron/crontab changes
Operating system: Uptime, CPU, RAM, swap, load, disk, inode, IO wait, disk latency; Filesystem, kernel, reboot required, OS version and lifecycle; Package and security updates Services: Nginx, Apache, PHP-FPM, MySQL/MariaDB, Redis, cron, fail2ban; Postfix where relevant PHP: Version and lifecycle, extensions, memory_limit, max_execution_time, upload limits; OPcache and its hit rate, worker count, saturation, queues, max_children, slowlog Nginx / Apache: Requests/sec, connections, 2xx/3xx/4xx/5xx ratios, upstream errors, timeouts, latency; Worker saturation, access log anomalies, error logs MySQL: Connections and max_connections, slow queries, query latency, deadlocks, aborted connections; InnoDB buffer pool and hit ratio, temp tables, disk temp tables, locks; Database size, table growth, binlog growth, replication, backup state, corruption checks; WordPress-specific: wp_options and autoload size, postmeta and options growth, Action Scheduler tables, revisions, transients Redis: Availability, memory, hit ratio, evictions; Connected clients, expired keys, fragmentation, maxmemory Filesystem: File integrity, unexpected PHP, wp-config modifications, permissions, owner/group; World-writable files, .env, logs, executable uploads, symlink changes Security: Failed and successful SSH logins, root login, new Linux users, sudo usage, SSH key changes; Firewall and open port changes, fail2ban, brute force, suspicious processes and outbound connections; Malware and rootkit checks, cron/crontab changes

The same team, the same report — more simply becomes visible at every level.

Let us start with a report.

Send us your site's address and we will decide which assessment level fits. The result is a written WPdoki Lelet — and if we then run the site, the fee is credited.

Technical assessment — a WPdoki Lelet for your WordPress site | WPdoki