Skip to main content
WP HealthKit
CRA deadline · September 202662 verification layersWordPress 7 ready

The compliance layer your WordPress agency is missing.

CRA, GDPR, WCAG, EAA — across every client site, every plugin, every update. 58 deterministic scanners and 4 AI engines run on every audit, with a fleet dashboard that surfaces score drops, new CVEs, and compliance shifts the morning they happen.

Unlimited scans · 1 free AI audit every month · No card required

Now scanningharbor-and-oak.com
[email protected]ZIP · 1.8 MB
  • Unpacking ZIP
  • Wordfence CVE DB
  • Secret scanner (22)
  • PHP 8.0–8.4 compat
  • PHPCS WordPress
  • REST auth scanner
  • GDPR scanner
  • AI security engine
  • AI accessibility
Audits completed
live count
Findings flagged
across all audits
Plugins graded
distinct wp.org plugins
Verification layers
0
58 deterministic + 4 AI
Audit data sourced fromWordfence IntelligenceWPScanOSV.devPackagist AdvisoriesPHPCSPHPStan L5WCAG 2.1 AAEU CRAWCAG 2.2Dynamic REST probeSARIF

62 verification layers

58 deterministic scanners. 4 AI engines. Zero guesswork.

We verify known facts first — CVEs, secrets, dependency advisories, REST authorization, GDPR, compatibility — before any AI looks at your code.

Deterministic scanners

58 · verifiable facts only

Every finding is cross-checked against a source of truth. If a scanner can't prove it, it doesn't report it.

Wordfence CVE DB412k records
WPScan + WPVulnerabilityadvisory feeds
Composer advisoriescomposer.json
npm / JS depsOSV.dev batch
Secret scanner22 patterns
PHP 8.0–8.4 compatdeprecations
PHPCS WordPresscoding standard
PHPStan level 5type safety
Semgrep + Psalmstatic analysis
REST API authorizationpermission_callback
GDPR scannerconsent + erasure
Gutenberg blocksrender_callback
Host compatibilityWPE / Kinsta / Flywheel
CRA complianceSECURITY.md / VDP
Multisite compatnetwork options
GPL / licenseComposer + npm
CodeCanyon / Envatosubmission rules
Theme scannerFSE / customizer
Hook wiring auditactions/filters
Performance patternsN+1, caching
i18n readinesstranslatable
Database schemamigrations
Malware scannersignature db
Plugin conflictsknown pairs
WooCommerce compatHPOS / blocks
WP version compat5.0–7.0
Dynamic REST auth probewe attack it live
AI agent securityprompt injection
WCAG 2.2EAA mandatory
Update channel safetysupply chain
Phone-home detectortelemetry
Uninstall verifierdata cleanup
ENGINE / 01

Security engine

7 dimensions, AI-code-safety included.

Authn / AuthzREST gapsCSRF / XSS / SQLiAI code patterns
ENGINE / 02

Quality-of-Life engine

9 dimensions of production readiness.

Error handlingSettings UXi18nUpdate hygiene
ENGINE / 03

Accessibility engine

WCAG 2.1 AA + EAA · WCAG 2.2 deterministic.

Semantics · ARIAWCAG 2.2 SC 2.5.8 / 3.3.8Color · contrast
ENGINE / 04

Theme engine

Activates automatically for theme ZIPs.

FSE / block themesCustomizerAsset security

Only on WP HealthKit

Proof, not patterns.

Every scanner on the market pattern-matches your code and guesses. We go further: live sandbox attacks, cross-validated AI, and verdicts you can act on.

Living Audits · Powered by Reverify

Your audit was true on Tuesday. Is it still true today?

A security audit is a snapshot — but the facts it rests on keep moving. Living Audits re-verifies your report's claims of safety and currency against ground truth, forever.

LIVING / 01Findings born with a whyEvery CRITICAL and HIGH finding carries a structured rationale: the evidence that grounds it, why it earned its severity, what was assumed, and what would change the assessment.
LIVING / 02Claims re-verified foreverYour minimum PHP, tested-up-to WordPress, and every pinned dependency are re-checked against OSV, endoflife.date, wp.org, and library docs on a decay-aware cadence.
LIVING / 03Challenges, never rewritesWhen a PHP version EOLs or a CVE lands in a library you bundle, a signed challenge with quoted evidence attaches to your report. The original audit is never edited.
How Living Audits works →

Report card

One grade for every buyer. Four grades for every reviewer.

Every audit produces an A–D letter across Security, Standards, Quality and Compatibility — plus an embeddable Submission Readiness badge.

HarborStripe@3.4.1
Submission-ready
96
/ 100 overall
Verified 4 minutes ago
Security
A · 96
Standards
A- · 91
Quality
B+ · 86
A11y
B · 82
wphealthkitA · 96submissionreadyCVEs0 / 412kembed · auto-updates

Ship with proof

embeddable badges
wphealthkitA · 96submissionreadyCVEs0 / 412k
<a href="https://wphealthkit.com/r/hs-341">
  <img src=".../badge/hs-341.svg"
       alt="Production-ready · Grade A" />
</a>

Live-updates on every re-audit — your wp.org listing never goes stale. Every grade links back to the public report it came from.

Free tools

Useful before you ever sign up.

All 5 tools →

Pricing · GBP

Audits that used to cost thousands. One free AI audit a month.

Deterministic scans are unlimited on every plan — you only spend tokens when the AI engines read your code.

Free
£0forever

The most generous free tier in WordPress security.

  • Unlimited deterministic audits
  • 1 AI audit/mo · all 58 scanners
  • Report card (A–D) + directory listing
Start free
Pro
£29/ month

For active plugin & theme authors.

  • 30 full audits a month
  • Fix Plan with every audit
  • Site monitoring (1 site) · GitHub Actions + CLI
Start 14-day trial
Enterprise
£999/ month

For platforms and hosts running WordPress at scale.

  • Unlimited Standard + Advanced audits · fastest queue < 2 min
  • 25 team seats + 500 monitored sites
  • Dedicated success manager + SLA
Talk to us
Most popular
Agency
£149/ month

Unlimited audits on your own AI keys (BYOK), fleet dashboard, 5 team seats.

  • Unlimited audits on your own AI keys · priority queue < 5 min
  • Fleet dashboard + morning digest
  • Finding assignment + 5 seats · white-label PDFs
Start free trial

BYOK Agency £149/mo on your own AI keys · Credit top ups: £4.99/audit · token packs from £99/25 · Enterprise £999/mofull comparison →

Ship with the receipts. Not with your fingers crossed.

Your next audit is two minutes away — upload a ZIP, get a verifiable grade, and put the badge where your buyers can see it. Every audit mints a signed provenance receipt anyone can verify.

62 verification layers · 58 deterministic scanners + 4 AI engines · Results in ~2 minutes