Skip to main content
WP HealthKit
CRA deadline · September 2026WordPress 7 readyFleet dashboardCRA · GDPR · WCAG · EAA46 verification layersMorning digest

The compliance layer
your WordPress agency
is missing.

CRA, GDPR, WCAG, EAA — across every client site, every plugin, every update. 42 deterministic scanners and 4 AI engines run on every audit, with a fleet dashboard that surfaces score drops, new CVEs, and compliance shifts the morning they happen.

See the compliance dashboard Audit a single plugin (free)Unlimited free audits · No card required · 14-day Agency trial
Now scanning
harbor-and-oak.com
Unpacking ZIP
Wordfence CVE DB
Secret scanner (22)
PHP 8.0–8.4 compat
PHPCS WordPress
REST auth scanner
GDPR scanner
AI security engine32%
AI accessibility
Provisional report
Verifiable facts only
A-
Production-ready
0 known CVEs · 0 hardcoded secrets · 2 warnings
Security
A96
Standards
A-91
Quality
B+86
A11y
B82
Audits completed
0
+1,284 this week
Vulnerabilities flagged
0
Across 412 CVEs
Sites monitored
0
24/7 companion plugin
Verification layers
0
42 deterministic + 4 AI
Audit data sourced fromWordfence IntelligenceWPScanOSV.devPackagist AdvisoriesPHPCSPHPStan L5WCAG 2.1 AAEU CRA

46 verification layers

42 deterministic scanners. 4 AI engines. Zero guesswork.

We verify known facts first — CVEs, secrets, dependency advisories, REST authorization, GDPR, compatibility — before any AI looks at your code.

Stage 1 · Deterministic
42 scanners
Verifiable
Wordfence CVE DB
412k records
WPScan + WPVulnerability
advisory feeds
Composer advisories
composer.json
npm / JS deps
OSV.dev batch
Secret scanner
22 patterns
PHP 8.0–8.4 compat
deprecations
PHPCS WordPress
coding standard
PHPStan level 5
type safety
Semgrep + Psalm
static analysis
REST API authorization
permission_callback
GDPR scanner
consent + erasure
Gutenberg blocks
render_callback
Host compatibility
WPE / Kinsta / Flywheel
CRA compliance
SECURITY.md / VDP
Multisite compat
network options
GPL / license
Composer + npm
CodeCanyon / Envato
submission rules
Theme scanner
FSE / customizer
Hook wiring audit
actions/filters
Performance patterns
N+1, caching
i18n readiness
translatable
Database schema
migrations
Malware scanner
signature db
Plugin conflicts
known pairs
WooCommerce compat
HPOS / blocks
WP version compat
5.0–7.0
Security engine
AI engine
7 dimensions, AI-code-safety included
Authn / AuthzREST gapsCSRF / XSS / SQLiAI code patterns
Quality-of-Life engine
AI engine
9 dimensions of production readiness
Error handlingSettings UXi18nUpdate hygiene
Accessibility engine
AI engine
WCAG 2.1 AA + EAA compliance
Semantics · ARIAKeyboardColor · contrast
Theme engine
AI engine
Activates automatically for theme ZIPs
FSE / block themesCustomizerAsset security

Report card

One grade for every buyer. Four grades for every reviewer.

Every audit produces an A–D letter across Security, Standards, Quality and Compatibility — plus an embeddable Submission Readiness badge.

A
Submission-ready
96/100 · Verified 4 minutes ago
Security
A96/100
Standards
A-91/100
Quality
B+86/100
A11y
B82/100
Embeddable badges
Ship with proof
wphealthkitA · 96
submissionready
CVEs0 / 412k
<a href="https://wphealthkit.com/r/hs-341">
  <img src=".../badge/hs-341.svg"
       alt="Production-ready · Grade A" />
</a>

Ship with the receipts.
Not with your fingers crossed.