Sitelemetry Audit connects your site to the hosted Sitelemetry audit service. From Settings > Sitelemetry you run an audit of your site and read the result inside WordPress: a score and grade, every finding with its severity, location and fix, and a clear list of what was not measured.
Audit kinds
What the plugin does
Plans and allowance
A Free Sitelemetry account includes the security audit with the public security modules and a monthly number of security scans; the public plan catalogue at sitelemetry.com/api/plans is the source of truth and the plugin reads it for the plan and usage box. When the connected account does not include an audit kind or has used its monthly allowance, the audit is not started, no allowance is used and the results page says so.
Ownership
Audit only websites you own or are explicitly authorized to test. Every audit is performed by Sitelemetry against the live target and is recorded on the connected account. Protected checks (for example HTTP methods and exposed files) require ownership verification of the domain in the Sitelemetry app; results list the checks that were left unmeasured for this reason. Unmeasured checks are not passes.
Thin client
The plugin bundles no libraries and runs no scanner on your server. It sends requests to sitelemetry.com with the WordPress HTTP API and renders the response.
External service
This plugin relies on the hosted Sitelemetry service (https://sitelemetry.com) operated by Sitelemetry. It sends requests to the service only when you run an audit or after you have stored an API key, as described in the Privacy section below. The terms of service are published at https://sitelemetry.com/terms and the privacy policy at https://sitelemetry.com/privacy.
When you run an audit, the plugin sends to sitelemetry.com the target URL and the audit options you configured (the audit kind), authenticated with your API key. Every request also identifies the client in its User-Agent header (sitelemetry-audit-wordpress/ and the plugin version); no WordPress version, site name, user, plugin list or other data from your site or your server is sent. Sitelemetry then audits the live target from its own infrastructure and records the audit on the connected account, as described in the Sitelemetry terms (https://sitelemetry.com/terms) and privacy policy (https://sitelemetry.com/privacy).
Once an API key is stored, the plugin also reads the public plan catalogue at sitelemetry.com/api/plans (no authentication, no data about your site beyond the same plugin User-Agent) to show the plan and usage box. Before a key is stored, the plugin makes no request to any external server.
The plugin stores in your WordPress database: the settings (API key, target, audit kind, weekly schedule), the last result of each audit kind (score, findings and coverage notes about the target) and, while an audit runs, the job state. It stores no data about visitors or users. Uninstalling the plugin removes all of it.