Site Lockdown Security is free on WordPress.org Get It Free
Auditor Features Guide

Auditor FeaturesExplained

The auditor reports which folders and files are found inside a WordPress website so unexpected items are easier to review. It gives site owners and support teams a clean map of content, plugin, theme, uploads, and .htaccess areas, making it easier to spot leftovers, unfamiliar paths, misplaced files, and changes that deserve attention before cleanup decisions are made.

Health Score
Review the audit status and folder issue totals.
Folder Review
Review content, plugin, theme, and upload folders.
File Decisions
Review found files before ignoring or deleting.
Cleanup Confidence
Review the site again after cleanup changes.
Audit Hub

Folder & File Auditor

The main auditor screen summarizes file and folder problems across the installation and gives quick links into the exact areas that need review.

Audit Health Score

What it means: The score gives a fast read on how clean or risky the current folder and file state appears.

How to use it: Treat it as a triage signal. Open the problem buttons, inspect the items, then rerun checks after cleanup to confirm the score improves.

Problem Buttons

What it means: Each button jumps to a specific audit area with files, folders, or rules that need attention.

How to use it: Work through the highest-risk areas first: executable files in uploads, unknown plugin/theme folders, and suspicious .htaccess rules.

Cleanup Workflow

What it means: The auditor is designed to guide review, not blindly delete anything unfamiliar.

How to use it: View or download questionable files, confirm whether folders are legitimate, ignore known-safe custom items, and delete only confirmed unwanted or malicious items.

Important: The score is a guide. Always review the actual file or folder before making destructive changes.

wp-content Review

Content Folder Auditor

The Content Folder Auditor reviews folders and files detected directly inside wp-content so unexpected directories, hidden files, and cleanup leftovers can be investigated.

Unexpected wp-content Folders

What it means: The auditor highlights folders that may not belong in a normal wp-content structure.

How to use it: Confirm whether each folder belongs to a plugin, theme, cache, backup, custom workflow, or cleanup artifact before taking action.

Ignore Or Include Decisions

What it means: Known-safe items can be excluded from future warnings so the score reflects real risk.

How to use it: Ignore items only after confirming ownership. Include items when they are expected and should be recognized as part of the site baseline.

Cleanup Timing

What it means: This audit is most useful before locking the site and after cleanup work.

How to use it: Run the check, fix confirmed issues, then rerun it before enabling stricter prevention so the baseline starts clean.

Important: Never remove a folder just because it is unfamiliar. Confirm it is not used by a plugin, theme, cache, backup, or custom workflow.

Plugin Directory Review

Plugins Folder Auditor

The Plugins Folder Auditor helps identify unknown plugin folders, leftover directories, hidden files, and suspicious content inside the plugins directory.

Unknown Plugin Folders

What it means: Folders that do not clearly match expected installed plugins can be reviewed as potential leftovers or suspicious additions.

How to use it: Compare the folder name with the active and inactive plugin list, then inspect files before deleting anything.

Leftover Plugin Cleanup

What it means: Old plugin directories can remain after failed removals, migrations, or manual cleanup.

How to use it: Remove only folders confirmed to be unused, backed up, and unrelated to mu-plugins or custom site functionality.

Important: Custom plugins and mu-plugin helpers can look unfamiliar. Verify ownership before deleting.

Theme Directory Review

Themes Folder Auditor

The Themes Folder Auditor reviews the themes directory so unused themes, modified theme folders, unknown directories, and extra files can be cleaned up safely.

Inactive Theme Review

What it means: Unused themes increase maintenance noise and can create cleanup confusion.

How to use it: Confirm the active theme, parent theme, and child theme first. Remove only themes that are unnecessary and backed up.

Unknown Theme Directories

What it means: Theme folders that do not match expected WordPress themes should be inspected carefully.

How to use it: Check for custom themes, staging leftovers, or injected files. View or download suspicious files before removing them.

Important: Child themes and custom themes may be required even if they do not come from WordPress.org.

Media Folder Review

Uploads Folder Auditor

The Uploads Folder Auditor reviews uploaded content for executable files, suspicious folders, and unexpected items that often appear after file upload abuse.

Executable File Checks

What it means: PHP, scripts, archives, and other risky file types inside uploads can indicate abuse or cleanup leftovers.

How to use it: Review suspicious files manually and delete only confirmed malicious or unnecessary items.

Unexpected Upload Folders

What it means: Upload directories outside the normal media pattern may deserve closer review.

How to use it: Compare against media plugins, backup tools, importers, and form upload paths before deleting anything.

Important: Uploads folders are often large. Treat auditor findings as leads that need confirmation.

Rule File Review

.htaccess Auditor

The .htaccess Auditor helps locate and review .htaccess files so redirect rules, access controls, and suspicious injected directives can be inspected before changes are made.

Redirect Rule Inspection

What it means: Suspicious .htaccess redirects can send visitors or search traffic to unwanted destinations.

How to use it: View or download the file, compare rules against known-good WordPress and host rules, then remove only confirmed bad directives.

Access Control Review

What it means: .htaccess rules can block, allow, rewrite, or protect specific paths.

How to use it: Check whether rules belong to WordPress, the host, caching, security, or redirects before changing them.

Safe Edit Process

What it means: A bad rule edit can break permalinks, logins, admin access, redirects, or static assets.

How to use it: Keep a backup, make one change at a time, test the front end and admin area, then rerun auditor and scanner checks.

Important: A bad .htaccess edit can break the site. Keep a backup before changing rules.

GET PROTECTED

Lock down WordPress without opening your wallet

Install Site Lockdown Security and get Premium WordPress protection at no cost.