Weio Site Check

وەسف

Weio Site Check runs eleven read-only checks on your own site and explains every result in plain English: what was found, why it matters, and how to fix it yourself. It changes nothing on your site.

What makes it different: most security plugins scan files for known malware signatures. Weio Site Check also looks at what visitors and Google actually receive: spam shown only to a Googlebot user agent, redirects only for visitors arriving from Google, spam URLs in your sitemap, an SSL certificate that is about to expire, and whether a WooCommerce shopper can reach checkout over https. It is one read-only page with no account, no scanning service and no settings to learn.

Open Tools > Site Check and click Run checks now. A run takes up to about 30 seconds.

The checks

  1. HTTPS in WordPress settings: both WordPress addresses start with https://.
  2. http to https redirect: the http:// address sends visitors to https:// with a permanent (301 or 308) redirect.
  3. SSL certificate: connects to your domain on port 443 from your server and reads the certificate it is given: days until it expires, whether it matches your domain, and whether browsers trust it (self-signed or incomplete chain).
  4. Outside-in HTTPS check (optional, off by default): asks the Weio service to load your domain and its www twin from the public internet, the way a visitor would. It also tests the www version of your address, which the local checks do not, and reports what a visitor sees, such as a “Not secure” label. Its view can differ from your server’s when your host resolves your own domain to itself or blocks the site from loading itself. If your site is on a subdomain and has no www version, that is reported as normal. See “External services” below.
  5. Mixed content: http:// scripts, styles, frames, images and media in your homepage HTML.
  6. WordPress core files: compares every core file with the official WordPress.org checksums, and lists extra PHP files in wp-admin and wp-includes.
  7. PHP files in uploads: lists PHP files in the uploads folder and flags code patterns that are typical of backdoors.
  8. Spam and cloaking signs: looks for injected casino, pharmacy and similar spam text, spam hidden with CSS, spam links, pages shown only to a Googlebot user agent (cloaking), redirects only for visitors arriving from Google, the “Japanese keyword hack”, spam URLs in your sitemap, and published posts with spam titles. Single ambiguous words (for example one news headline about a casino) are reported only as “worth a look”. These are signs, not proof of a hack. To compare views, the plugin loads your homepage once with a Googlebot user agent from your own server; a firewall may log or block this. Cloaking that checks a visitor’s IP address, not only the user agent, cannot be seen from your server.
  9. New administrator accounts: administrators registered in the last 30 days.
  10. WooCommerce store pages (only when WooCommerce is active): cart, checkout and account pages are set and published, checkout loads for a guest over https, and at least one payment method is enabled. A guest with an empty cart being sent from checkout to the cart is normal and reported as OK.
  11. Homepage response time and size, measured from your own server.

Optional daily monitoring (off by default): runs the same checks once a day with WP-Cron and emails the site admin address only when a check newly becomes a problem.

What this plugin is not

  • It does not remove malware and it is not a firewall.
  • A pass is not a guarantee that a site is secure, and a warning is not proof of a hack.
  • It loads only your own site’s address (and its www version). If a page redirects to another site, the plugin reports the redirect and does not follow it. It never fetches addresses that someone types in.

Privacy

Apart from the WordPress.org checksum lookup (WordPress’s own service, used by the core file check), nothing is sent outside your site unless you turn on the outside-in check. The plugin has no tracking, no analytics and no ads, and it adds nothing to your public pages. Most checks load your own homepage, sitemap and checkout page from your own server, the same way a visitor would.

About Weio

Weio (weio.ai) is an AI-operated company that makes this plugin. Next to a check with a problem, the results page shows a “Have Weio fix it” link to a matching paid service: HTTPS and SSL fix ($99 fixed price), hacked site cleanup ($199 for one site; complex cases are quoted first) or WordPress speed fix ($249 fixed price). The HTTPS and speed links also appear next to a warning from those checks; the cleanup link never appears next to a warning. These services are optional; every check and every fix instruction works without them.

External services

This plugin can connect to two external services.

1. Weio HTTPS check API (weio.ai), only if you turn it on

  • What it is: the outside-in HTTPS check (check 4). It is provided by Weio, the maker of this plugin, at https://weio.ai/api/https-check
  • When it is used: only when you have ticked “Outside-in HTTPS check” in Tools > Site Check (off by default), and then only during a check run: when you click “Run checks now”, or once a day if you also turned on daily monitoring. It is never called on activation, on page loads or in the background otherwise.
  • What is sent: your site’s domain name (for example example.com), a user agent string naming this plugin, and, only if you saved one, your Weio API key in an Authorization header. No user data, email addresses, content, plugin list or WordPress version is sent. As with any web request, Weio sees the IP address of your server.
  • What Weio keeps: the domain name, the time and the result of each check. Your server’s IP address is used only in memory for rate limiting and is not stored. Weio’s web server keeps short-lived request logs that identify the caller by a salted one-way hash, never the IP address. For calls made with a key, the domain is logged with a short prefix of a one-way hash of the key, and a key is linked to the email used to buy it.
  • Limits and keys: without a key the check is free, within a service-side rate limit (currently 5 checks per minute and 20 per day per server IP address, and a pool of 300 per day shared by all free users, including the free check page on weio.ai). When the limit is reached the plugin says so and the check works again the next day. An optional API key ($9 for 1,000 checks, valid 12 months, https://weio.ai/services/site-check-api.html) is not subject to the shared free limit. The key unlocks no code in this plugin; all other checks never need a key or registration.
  • Terms of use: https://weio.ai/terms.html#api
  • Privacy policy: https://weio.ai/privacy.html#api

2. WordPress.org checksums API (api.wordpress.org)

  • What it is: the official list of checksums of WordPress core files, used by the core file check (check 6). It is the same service WordPress itself uses for updates.
  • When it is used: during each check run (manual, or daily if monitoring is on).
  • What is sent: your WordPress version and site language (locale), in a request to https://api.wordpress.org/core/checksums/1.0/ with a user agent naming this plugin. Your site address is not sent.
  • Terms and privacy: https://wordpress.org/about/privacy/

Links to weio.ai on the results page (service pages, the free speed report form, API key information) are ordinary links. Following them sends nothing from your site; the free speed report is a form you fill in yourself on weio.ai.

دامەزراندن

  1. Install and activate the plugin from Plugins > Add New, or upload the weio-site-check folder to /wp-content/plugins/.
  2. Go to Tools > Site Check and click “Run checks now”.
  3. Optional: in the Settings section of the same page, turn on the outside-in HTTPS check or daily monitoring.

پهد

Is it free?

Yes. All eleven checks are free and work without an account, key or registration. The optional outside-in check runs on the Weio service with a free, shared daily limit; if you want to run it more often, a paid API key ($9 for 1,000 checks) lifts that limit. The fix services linked from the results page are optional and priced separately.

Does it change anything on my site?

No. The checks only read files, settings and your own pages. The plugin stores its settings and the last results in the WordPress database and deletes them when you uninstall it.

Who can run the checks?

Users with the manage_options capability (administrators). On multisite, only super admins, because the core file check reads files that all sites of the network share.

A check says “skipped”. Why?

Some checks do not apply to every site (for example WooCommerce, or the redirect check on a site without https). Others are skipped when your host blocks the site from loading its own pages, or when a service does not answer in time. The result explains which.

The spam check found a warning. Am I hacked?

Not necessarily. Weak signs, such as one gambling word or one link to a casino, are often legitimate. Strong signs, such as spam hidden with CSS or content shown only to Googlebot, deserve a closer look. Use the URL Inspection tool in Google Search Console to see what Google sees.

My firewall logged a fake Googlebot from my own server. Is that this plugin?

Yes, if it happened during a check run. To compare what search engines and visitors see, the spam check loads your homepage once with a Googlebot user agent. A firewall may log or block that request; that is harmless, and you can allow your server’s own IP address if you want the comparison to run.

Why does the SSL check fail on my local or staging site?

Local sites usually run on http:// or with a self-signed certificate, so the HTTPS checks report that. That is expected and harmless on a site that is not public.

Do you offer support?

Yes. Use the support forum for this plugin on WordPress.org.

پێداچوونەوەکان

هیچ پێداچوونەوەیەک نەنووسراوە بۆ ئەم پێوەکراوە.

بەشداربووان و گەشەپێدەران

“Weio Site Check” نەرمەواڵەیەکی سەرچاوە کراوەیە. ئەم کەسانەی خوارەوە بەشدارییان تێدا کردووە.

بەشداربووان

“Weio Site Check” وەربگێڕە بۆ زمانەکەی خۆت.

دەتەوێت بەشداربیت لە گەشەپێدان؟

گەڕان لە کۆدەکەدا بکە، سەیری تەمارگەی (SVN) بکە، یان بەشداربە لە ڕووداوتۆماری گەشەپێدان لە ڕێگەی (RSS).

ڕووداوتۆمارگەریی گۆڕین

1.0.0

  • First release: eleven checks, optional outside-in HTTPS check, optional daily monitoring with email on new problems.