AI-Ready Security & Health Reports for WordPress

The free Security Audit plugin generates site health, exposure, vulnerability, integrity, readiness, and performance reports for your WordPress site. Review them in the admin dashboard, or let Claude, ChatGPT, or Codex read them through secure, read-only REST and MCP endpoints. You use your own AI subscription — no API key required.

Download Free on WordPress.org See Pro Plans Contact

 

Read-only by design

The free plugin reports findings only. It does not perform cleanup, quarantine, updates, file edits, role changes, or any remediation — so AI agents can safely review your site without making changes.

Free

Security Audit
WordPress.org plugin

Current free package for read-only security, integrity, performance, readiness, and AI-agent reports.

Admin Scan, Settings, and Agents tabs
Token-protected REST JSON and Markdown reports
Token-protected read-only MCP tools for AI agents
Generic extension hooks for tabs, reports, findings, and Site Manager integrations

Pro

Security Audit Pro
For Promptaur Pro WP and Agency WP clients

Current Pro add-on package extends the free plugin with retained investigation workflows and a merged Pro interface. It still avoids destructive remediation.

Overview, History, Ignore Rules, Recommendations, Integrity, Remediation, and Pro Settings tabs
Per-finding changed-state and resolution history
Ignore and suppression rules with expiry and until-changed behavior
Ranked, non-executable recommendations with prerequisites and rollback guidance
Manual official-package integrity comparison for WordPress core, plugins, and themes
Remediation onboarding policy before future write actions are enabled
Site Manager integration for history, recommendations, integrity reports, and approved option tools

Free Plugin

Admin Scan tab with scan modes — full, critical/high/medium, critical-only
Site health, exposure, vulnerability, integrity, readiness & performance checks
JSON and plain-text Markdown report output
Issues-only or all-results report filters
Optional token-protected REST report endpoint
Optional token-protected read-only MCP endpoint for AI agents
Optional WPVulnerability API lookups for installed plugins
Per-minute rate limiting, IP allowlist, token rotation, scan cooldowns
Read-only integration with VideoWhisper Site Manager when both are active
Redacted AI report defaults to protect sensitive details

Pro Add-on

Merged Overview tab with actionable counters and top recommendations
Finding history for changed states and resolved issues
Ignore rules for accepted exceptions and future snapshot suppression
Recommendation plans that remain advisory and approval-required
Official WordPress.org package comparison for integrity review
Site Manager Pro option integration for connected-site administration
Remediation safety model settings without enabling destructive actions

Availability in Promptaur Plans

Security Audit remains free on WordPress.org. Security Audit Pro is planned for customers with a Promptaur WordPress Pro plan, alongside the other Pro WordPress AI plugins.

Individual

Promptaur Pro WP
1 site
$29
per year
AI Site Manager Pro
Agentic Optimization Pro
Security Audit Pro when available for Pro clients
Pro account on Promptaur Server
Automated updates, priority support, and installation assistance

Agency

Promptaur Agency WP
Up to 10 client sites + 1 server install
$199
per year
Everything in Pro WP, for up to 10 sites
Site Manager Server plugin
Centralized OAuth for all sites
Security Audit Pro for connected client sites when available
Automated updates, priority support, and installation assistance

What It Checks

Security Audit reviews local WordPress signals and turns them into clear, AI-readable findings:

Plugin & theme updates
Inactive plugins
Administrator account count
Expected database tables
Administrator role capabilities
Upload directory writability
Debug log file presence
Git metadata in web root
XML-RPC availability
Homepage security headers
Autoloaded option size & expired transients
WP-Cron disabled state
Permalink & search-engine visibility
Privacy Policy page presence
WooCommerce page readiness

Agent & API Reports

REST and MCP endpoints are disabled by default. When enabled, the plugin generates local tokens you can rotate at any time. The standalone MCP endpoint exposes read-only tools for security summary, vulnerability, exposure, integrity, performance risk, readiness, and Markdown audit reports. When VideoWhisper Site Manager is active, connected sites can expose Security Audit reports through the existing Site Manager authentication path instead of configuring a separate MCP server.

REST report endpoint
Token-protected JSON or Markdown reports. Choose scan mode (full, important, critical, changed) and report scope (issues or all).
MCP and Site Manager tools
Read-only tools for AI agents to pull security, vulnerability, exposure, integrity, performance, readiness, and audit reports.

Works With

Claude.ai
Web and mobile. Connect via MCP in Claude settings.
Claude Desktop
macOS and Windows app. Full MCP support.
Claude CLI / Codex
Terminal-based access for developers and automation.
ChatGPT
Read REST reports via Custom GPT actions, or use Site Manager workflows where available.

Informational only

Security Audit is not a firewall, malware cleaner, vulnerability-scan guarantee, or replacement for backups, monitoring, dedicated scanners, or experienced administrators. Findings and AI-generated recommendations may be incomplete or inaccurate — review them and consult an experienced security provider before making important changes. REST/MCP reports may expose sensitive operational details, so enable agent endpoints only when you understand where the data is sent and who holds the token.