Title: 320px Site Audit
Author: appsmax
Published: <strong>8 سپتامبر 2026</strong>
Last modified: 8 سپتامبر 2026

---

جستجوی افزونه‌ها

![](https://ps.w.org/320px-site-audit/assets/banner-772x250.png?rev=3687068)

![](https://ps.w.org/320px-site-audit/assets/icon-256x256.png?rev=3687068)

# 320px Site Audit

 توسط [appsmax](https://profiles.wordpress.org/appsmax/)

[دانلود](https://downloads.wordpress.org/plugin/320px-site-audit.0.1.1.zip)

 * [جزئیات](https://fa.wordpress.org/plugins/320px-site-audit/#description)
 * [نقد و بررسی‌ها](https://fa.wordpress.org/plugins/320px-site-audit/#reviews)
 *  [نصب](https://fa.wordpress.org/plugins/320px-site-audit/#installation)
 * [توسعه](https://fa.wordpress.org/plugins/320px-site-audit/#developers)

 [پشتیبانی](https://wordpress.org/support/plugin/320px-site-audit/)

## توضیحات

320px Site Audit helps an administrator understand what needs attention, what
 is
fine, and what could not be tested. It analyses WordPress, PHP, the database, scheduled
tasks, installed components, selected source code, public pages, technical search
signals, rendered-page evidence, privacy-process answers, and optional server evidence.

The recommended Main audit contains 46 results: the 20-result Express local
 subset,
ten further local WordPress checks, and 16 analyses of one bounded same-site crawl.
Separate checks cover active custom code, 1–10 components chosen by the administrator,
a controlled rendered home page, and local server evidence through WP-CLI.

Reports lead with the observed fact and a concrete next action. Search findings

group the exact problem and show safe same-site page paths when privacy rules allow
them. Clean results stay available in a collapsed section. Method, coverage, confidence,
sources, and limitations remain available without obscuring the answer.

The plugin analyses and explains. It does not repair, delete, optimize, update,

or change audited content, users, settings, plugins, themes, server configuration,
or databases. It writes only its own bounded run, task, result, decision, and operation
records.

#### Local and optional checks

 * **Express:** 20 local WordPress and hosting-environment results.
 * **Main:** Express plus database, filesystem, components, privacy signals, and
   
   one confirmed, limited crawl of this site’s public pages.
 * **Custom code:** local tokenizer and lexical signals for the active/parent
    themes,
   MU plugins, drop-ins, and recognized active Code Snippets entries.
 * **Selected components:** the same bounded code triage for 1–10 installed
    plugins
   or themes explicitly selected and confirmed by the administrator.
 * **Rendered home page:** 20 aggregate DOM, layout, form, resource,
    accessibility,
   and data-handling signals from 1–17 confirmed anonymous GET requests to the site’s
   exact origin. It does not execute page JavaScript.
 * **Server continuation:** nine masked results from
    wp 320px-audit server-scan,
   run by the owner over SSH without giving the plugin SSH credentials.
 * **Optional browser CLI:** executed-JavaScript, responsive, and automated
    accessibility
   evidence at five fixed widths, run independently by the owner.

Static and automated findings are review signals, not proof of a vulnerability,

compatibility with every environment, search ranking, WCAG conformance, or legal
compliance. Missing or limited evidence is reported as not tested or partial, never
converted to a pass.

### Privacy

The complete base report works locally without an account, license, payment,
 email
gate, telemetry, or automatic report transfer. Opening the plugin, running local
checks, viewing or exporting reports, cron, activation, and uninstall do not contact
320px or another external service.

Stored evidence is bounded and masked. The plugin does not retain page HTML,
 visible
text, cookies, credentials, secret values, database content, or source code. A crawl
may retain a hostless, queryless page path only when its segments do not resemble
personal data, credentials, or opaque tokens. Reports and exports should still be
treated as private technical documents.

Every optional external operation is off by default. Before it runs, an
 authorized
administrator sees the receiver, purpose, data classes, and relevant terms, then
confirms that one operation. No scheduled task starts an external transfer.

### External services

The services below are optional and are not required for the local report.

#### WordPress.org checksums

Core integrity sends only the installed WordPress version and locale to
 https://
api.wordpress.org/core/checksums/1.0/. Plugin integrity sends only one administrator-
selected public plugin slug and version to https://downloads.wordpress.org/plugin-
checksums/{slug}/{version}.json. Ordinary network metadata is also visible to the
receiver. Neither operation sends the site URL, files, paths, component inventory,
report, cookies, or authorization. Each operation requires its own confirmation.
Privacy policy: https://wordpress.org/about/privacy/

#### Wordfence vulnerability feed

The optional owner-run WP-CLI continuation has a zero-request preview. Only
 after`--
confirm-network`, it sends the owner’s bearer API key, the minimal Site Audit user
agent, and ordinary network metadata to the fixed Wordfence Scanner Feed endpoint
at https://www.wordfence.com/api/intelligence/v3/vulnerabilities/scanner. It does
not send the site URL, component inventory or versions, report, or personal data.
The complete feed is matched locally and deleted immediately. The key is read from`
PX320_WORDFENCE_TOKEN` and is never stored. Terms: https://www.wordfence.com/wordfence-
intelligence-terms-and-conditions/ Privacy policy: https://www.wordfence.com/privacy-
policy/

#### Request a review from 320px

An administrator may voluntarily send a review request to
 https://wp-content.ru/
wp-json/wp-content-platform/v1/review-requests. Contact-only is the default. The
administrator may instead choose a short summary, selected results, or the redacted
full report. The exact payload and byte size are previewed locally before separate
consent and final confirmation. The site URL, local identifiers, credentials, and
private visual evidence are never included. There is no retry or background submission.
The response gives an opaque request ID, deletion link, and retention date of about
90 days. Terms: https://wp-content.ru/terms/ Privacy policy: https://wp-content.
ru/privacy/ Consent: https://wp-content.ru/personal-data-consent/

#### Optional browser CLI dependencies and page requests

The browser companion is human-readable source included in `cli/browser`; PHP
 and
wp-admin never install or execute it. The owner independently installs its pinned
packages. With default npm settings that contacts https://registry.npmjs.org/; npm
terms and privacy are at https://www.npmjs.com/policies/terms and https://www.npmjs.
com/policies/privacy. The Playwright installer provides a dry run that lists its
browser download URLs; documentation is at https://playwright.dev/docs/browsers 
and Microsoft privacy terms are at https://privacy.microsoft.com/privacystatement.

Without `--confirm-network`, the companion makes no page request. A confirmed
 run
loads only 1–5 explicit queryless pages in a fresh sandboxed Chromium context. The
pages and their ordinary first- or third-party resources receive normal browser/
network metadata and anything page scripts place in allowed GET request URLs or 
headers. Mutating HTTP methods, later document navigation, frames, popups, saved
downloads, WebSockets, WebRTC, WebTransport, and workers are blocked within fixed
request, byte, and time limits. Its ordinary JSON contains aggregates and keyed 
references, not URLs, text, HTML, selectors, field values, cookies, screenshots,
or response bodies. There is no upload or WordPress callback.

## عکس‌های صفحه

[⌊Russian start screen with the recommended Main audit, its Express subset, and 
separate additional checks.⌉⌊Russian start screen with the recommended Main audit,
its Express subset, and separate additional checks.⌉[

Russian start screen with the recommended Main audit, its Express subset, and separate
additional checks.

[⌊Russian Main report with a concrete observed result, affected page, and next action.⌉⌊
Russian Main report with a concrete observed result, affected page, and next action
.⌉[

Russian Main report with a concrete observed result, affected page, and next action.

[⌊English Express report with localized evidence, limitations, and actions.⌉⌊English
Express report with localized evidence, limitations, and actions.⌉[

English Express report with localized evidence, limitations, and actions.

[⌊Server continuation with the zero-network WP-CLI command and no SSH credential
form.⌉⌊Server continuation with the zero-network WP-CLI command and no SSH credential
form.⌉[

Server continuation with the zero-network WP-CLI command and no SSH credential form.

[⌊Russian privacy self-check with bundled sources and masked local comments.⌉⌊Russian
privacy self-check with bundled sources and masked local comments.⌉[

Russian privacy self-check with bundled sources and masked local comments.

[⌊Optional review preview with recipient, purpose, data classes, retention, payload,
and separate consent.⌉⌊Optional review preview with recipient, purpose, data classes,
retention, payload, and separate consent.⌉[

Optional review preview with recipient, purpose, data classes, retention, payload,
and separate consent.

## نصب

 1. In WordPress, open Plugins > Add New Plugin and install 320px Site Audit.
 2. Activate it, then open Site Audit in the main administrator menu.
 3. Choose a check and read its local/network boundary.
 4. Start the check and wait for the report. Interrupted work can be resumed.
 5. Open results that need attention; clean and unavailable results are grouped separately.

Only administrators with `manage_options` can open reports or start actions.

## سوالات متداول

### Does Site Audit fix or change my site?

No. It analyses and explains. It changes only its own removable operational
 records.

### Is an account, email, license, or report upload required?

No. The complete base report and local exports work without any of them. There
 
is no telemetry. Optional network actions are separately disclosed and confirmed.

### Why can a result be “not tested”?

The required evidence was unavailable, restricted, stale, or outside the
 selected
check. The result includes the exact reason and next step instead of guessing.

### Does a clean report prove security, SEO results, accessibility, or compliance?

No. It is bounded diagnostic evidence, not a guarantee, certification,
 penetration
test, ranking forecast, manual accessibility audit, or legal advice.

### How do I report a security issue or ask for support?

Read `SECURITY.md` and `SUPPORT.txt` in the installed plugin. Never send a live

site archive, database dump, credentials, or an unreviewed report.

## نقد و بررسی‌ها

نقد و بررسی‌ای برای این افزونه یافت نشد.

## توسعه دهندگان و همکاران

“320px Site Audit” نرم افزار متن باز است. افراد زیر در این افزونه مشارکت کرده‌اند.

مشارکت کنندگان

 *   [ appsmax ](https://profiles.wordpress.org/appsmax/)

“320px Site Audit” به 1 زبان ترجمه شده است. با تشکر از [مترجمین](https://translate.wordpress.org/projects/wp-plugins/320px-site-audit/contributors)
برای همکاری و کمک‌هایشان.

[ترجمه “320px Site Audit” به زبان شما.](https://translate.wordpress.org/projects/wp-plugins/320px-site-audit)

### علاقه‌ مند به توسعه هستید؟

[کد را مرور کنید](https://plugins.trac.wordpress.org/browser/320px-site-audit/)،
[مخزن SVN](https://plugins.svn.wordpress.org/320px-site-audit/) را بررسی کنید، یا
از طریق [RSS](https://plugins.trac.wordpress.org/log/320px-site-audit/?limit=100&mode=stop_on_copy&format=rss)
در [گزارش توسعه](https://plugins.trac.wordpress.org/log/320px-site-audit/) مشترک
شوید.

## گزارش تغییرات

#### 0.1.1

 * Corrected directory metadata, release translation packaging, custom-layout
    path
   handling, and direct web access protection following the WordPress.org review.

#### 0.1.0

 * First stable submission candidate: action-first RU/EN reports, bounded local
   
   WordPress and code checks, same-site technical search analysis, controlled rendered
   evidence, optional server/browser continuations, explicit coverage, local exports,
   and no telemetry or hidden report transfer.

## اطلاعات

 *  نگارش **0.1.1**
 *  آخرین به‌روزرسانی **3 روز پیش**
 *  نصب‌های فعال **کمتر از 10**
 *  نگارش وردپرس ** 6.4 یا بالاتر **
 *  آزمایش‌شده تا **7.1**
 *  نگارش PHP ** 7.4 یا بالاتر **
 *  زبان‌ها
 * [English (US)](https://wordpress.org/plugins/320px-site-audit/) و [Russian](https://ru.wordpress.org/plugins/320px-site-audit/).
 *  [به زبان خودتان ترجمه کنید](https://translate.wordpress.org/projects/wp-plugins/320px-site-audit)
 * برچسب
 * [accessibility](https://fa.wordpress.org/plugins/tags/accessibility/)[diagnostics](https://fa.wordpress.org/plugins/tags/diagnostics/)
   [privacy](https://fa.wordpress.org/plugins/tags/privacy/)[seo](https://fa.wordpress.org/plugins/tags/seo/)
   [site audit](https://fa.wordpress.org/plugins/tags/site-audit/)
 *  [نمایش پیشرفته](https://fa.wordpress.org/plugins/320px-site-audit/advanced/)

## امتیازها

هنوز هیچ نقدی ارسال نشده است.

[بررسی شما](https://wordpress.org/support/plugin/320px-site-audit/reviews/#new-post)

[مشاهدهٔ همهٔ بررسی‌ها](https://wordpress.org/support/plugin/320px-site-audit/reviews/)

## مشارکت کنندگان

 *   [ appsmax ](https://profiles.wordpress.org/appsmax/)

## پشتیبانی

چیزی برای گفتن دارید؟ نیاز به کمک دارید؟

 [مشاهده انجمن پشتیبانی](https://wordpress.org/support/plugin/320px-site-audit/)