DiveWP – Boost Site Performance with Clear, Actionable Steps
Compatibility: Requires WordPress 6.0 or later. Tested through WordPress 7.0 (full support on WordPress 7). Abilities API / MCP features need WordPress 6.9+ (included in WordPress 7); all other DiveWP features run on the minimum version. 📋 System Logs Central place to read and understand errors without opening raw log files. The System Logs screen merges WordPress debug.log, WooCommerce file logs, and the WooCommerce fatal error log (when present), with severity labels (fatal, error, warning, notice, info) and grouping by source (plugin, theme, WooCommerce, or core). What you get: * Latest — newest entries across all readable sources, with adjustable “show last” limits (50–500) * By Source — cards per source with severity counts; drill into entries for one source * WP Debug Log — focused view of wp-content/debug.log (when readable) * WooCommerce Logs — log files from WooCommerce’s log handler * Fatal Errors Log — WooCommerce fatal error log when available * Logs Access Help — guidance when logs are missing or not readable (permissions, host-managed paths) * Entry details — modal with full message/stack context and copy for support * Abilities API: divewp/system-logs — same views for AI assistants via MCP (latest, by source, per-source entries, filters, help status) 🔌 NEW: Plugins Management Monitor and manage all installed plugins from one place. DiveWP’s Plugins Management feature shows every plugin with active/inactive status, update availability, and “Up to date” state. View details and changelog from WordPress.org, and activate or deactivate plugins without leaving the dashboard. Plugins Management & Abilities API: Use the divewp/plugins-management ability so AI assistants can list plugins, fetch description and changelog for a plugin, or activate/deactivate a plugin by file path. What Plugins Management Delivers: * Unified plugin list – All installed plugins with status pills (Active, Inactive, Update Available, Up to date) * Dashboard overview – Green and red pill counts on the main dashboard for quick health overview * Details drawer – Overview, full description, and changelog from WordPress.org * Toggle activation – Activate or deactivate plugins from the card or drawer * Search – Filter plugins by name, author, or description * Abilities API – Operations: list (all plugins), details (wp.org info for one plugin), toggle (activate/deactivate) 🤖 NEW: AI Capabilities & WordPress Abilities API Talk to your WordPress site through AI! DiveWP integrates with the WordPress Abilities API and Model Context Protocol (MCP), so AI tools like Cursor, Claude, and ChatGPT can query your site’s health and diagnostics directly—no copy-paste needed. WordPress Abilities API & MCP: * 12 Diagnostic Abilities – Server insights, cron monitoring, plugins management, database health, security audits, system logs (debug/WooCommerce/fatal), and more via the Abilities API * Zero Copy-Paste – AI agents run diagnostics through MCP without manual log sharing * Secure Authentication – WordPress Application Passwords for safe, controlled access * Step-by-Step Setup – “AI Capabilities” tab guides you through 3-step configuration for Abilities API and MCP clients Available Abilities: * divewp/server-insights – Full server health & config check * divewp/cron-insights – Monitor WP-Cron and Action Scheduler; background tasks & overdue jobs * divewp/db-insights – Database size & optimization status * divewp/security-insights – Vulnerability & configuration audit * divewp/performance-checks – Caching & optimization discovery * divewp/theme-builder-insights – Theme and page builder health * divewp/woocommerce-best-practices – WooCommerce optimization * divewp/seo-optimization – SEO configuration audit * divewp/email-communications – Email delivery & SMTP status * divewp/hosting-benchmark-latest – Latest benchmark results * divewp/plugins-management – List installed plugins, fetch wp.org details/changelog, or toggle plugin activation (operations: list, details, toggle) * divewp/system-logs – WordPress debug log, WooCommerce logs, fatal error log; views: latest, by source, filters, help status ⏰ NEW: Cron Job Manager & WP-Cron Monitoring Take control of WordPress cron jobs and scheduled tasks. DiveWP’s Cron Job Manager gives you a clear view of WP-Cron and Action Scheduler so you can spot overdue jobs, slow hooks, and misconfigured cron setups. Cron Jobs & Abilities API: Use the divewp/cron-insights ability so AI assistants can inspect your cron status, overdue tasks, and recommendations without opening the admin. What the Cron Job Manager Delivers: * Real-time cron monitoring – WP-Cron and Action Scheduler in one dashboard * Hook performance – Execution time and memory per cron hook * Overdue & orphan detection – Find stuck or orphaned scheduled tasks * Execution history – Filterable, paginated cron run history * Health guidance – System health and cron configuration tips 🚀 Hosting Performance Benchmark – Know If You Need to Upgrade! Measure how your hosting handles your WordPress site! DiveWP’s comprehensive Hosting Performance Benchmark is a powerful enterprise-grade testing system that evaluates your hosting environment through real-world performance tests. What It Tests: * Database Performance – Tests INSERT, SELECT, UPDATE operations, datetime functions, and aggregate operations (8 comprehensive tests) * Server Resources – Evaluates CPU, memory, I/O, and network capabilities (5 resource tests) * Concurrency Handling – Measures how your hosting performs under multiple simultaneous requests (4 concurrency tests) * E-commerce Performance – Tests WooCommerce-like operations including price calculations, shipping, and inventory checks (3 performance tests) Key Benefits: * 20+ Individual Tests – Comprehensive evaluation across 4 major categories * Real-World Simulation – Tests simulate actual WordPress operations, not synthetic benchmarks * 6-Minute Complete Analysis – Get detailed insights in approximately 6 minutes * Actionable Results – Understand if your current hosting is sufficient or if you need to upgrade * Cross-Database Compatible – Works with MySQL, MariaDB, PostgreSQL, SQLite, and SQL Server * Optimized for Shared Hosting – Designed to work efficiently even on shared hosting environments Perfect For: * Site owners wondering if their hosting plan is sufficient * Users experiencing slow performance and wanting to identify bottlenecks * Anyone considering upgrading their hosting plan * Developers evaluating hosting performance for client sites 🎯 Transform Your WP Journey Discover your site’s true potential by understanding exactly what’s happening under the hood. DiveWP provides clear insights about Performance, Security, and Best Practices – all explained in plain English. Take control of your digital presence by learning as you optimize! 🔍 Key Features 🔌 NEW: Plugins Management * Unified list of all installed plugins with status (Active, Inactive, Update Available, Up to date) * Dashboard counts green (up to date) and red (updates available) pills for quick overview * Details drawer with overview, WordPress.org description, and changelog * Toggle plugin activation from card or drawer; search by name, author, or description * Abilities API: divewp/plugins-management (list, details, toggle) for AI-assisted plugin management ⏰ NEW: Cron Job Manager & WP-Cron Monitoring * Real-time WP-Cron and Action Scheduler tracking * Monitor hook performance and execution time * Detect orphaned and overdue tasks * Identify problematic cron hooks affecting performance * Complete execution history with filtering and pagination * Integrates with Abilities API via divewp/cron-insights for AI-assisted cron diagnostics 🤖 NEW: AI Capabilities & WordPress Abilities API * WordPress Abilities API and MCP let AI assistants query your site for diagnostics * 12 abilities for server, cron jobs, plugins, security, database, performance insights, and system logs * Works with Cursor, Claude Desktop, ChatGPT, and other MCP clients * Secure access via WordPress Application Passwords * Step-by-step setup guide in “AI Capabilities” tab 🚀 Hosting Performance Benchmark * Comprehensive hosting evaluation with 20+ real-world performance tests * Database, resource, concurrency, and e-commerce performance analysis * Determine if your hosting plan is sufficient for your site * Cross-database compatibility (MySQL, MariaDB, PostgreSQL, SQLite, SQL Server) * Optimized for shared hosting environments Deep Site Insights * Understand your site inside out * Comprehensive analysis of core functions * Database health monitoring * User activity tracking * Everything explained in plain English ⚡ Performance & Speed * Clear performance insights * Actionable optimization steps * Speed improvement recommendations * Learn what affects your site’s performance 🛡️ Security & Best Practices * Proactive security checks * Easy-to-follow hardening recommendations * Learn WordPress security best practices * Implement as you learn 📊 Database Health * Optimize database performance * Clear insights into tables and structure * Cleanup recommendations * Learn database management without being a tech expert 🎯 SEO & Visibility * Practical SEO recommendations * Essential optimization techniques * Improve search engine rankings * Learn while implementing 🛍️ WooCommerce Optimization * Specialized store insights * Performance optimization * Checkout process analysis * Shopping experience improvements 📧 Email System Monitor * Detailed logging and diagnostics * Track email system performance * Ensure reliable communication * Monitor delivery status 🎨 Theme & Builder Analysis * Theme performance insights * Page builder optimization * Visual elements analysis * Speed optimization guidance 💡 How It Works Install & Scan: Quick installation and automatic site analysis Get Clear Insights: Receive easy-to-understand explanations Learn Best Practices: Understand WordPress through your own site Implement Changes: Follow actionable recommendations Monitor Progress: Track improvements and keep learning 🎯 Perfect For WordPress Beginners: Finally understand what’s happening on your site Store Owners: Optimize WooCommerce performance and boost sales Agency Teams: Maintain multiple sites while learning best practices Content Creators: Improve site visibility while mastering WordPress 🌟 What’s New in 2.3.0 NEW: Plugins Management New “Plugins Management” feature: view all installed plugins with status pills (Active, Inactive, Update Available, Up to date) Dashboard overview counts green (up to date) and red (updates available) pills alongside other feature statuses Details drawer with overview, full description, and changelog from WordPress.org Activate/deactivate plugins from the card or drawer; search by name, author, or description NEW: Abilities API – divewp/plugins-management Operations: list (all plugins with status), details (wp.org description and changelog for one plugin), toggle (activate/deactivate by plugin file) AI assistants can list plugins, fetch plugin info, or change activation state via MCP 🌟 What’s New in 2.2.0 NEW: AI Capabilities & WordPress Abilities API New “AI Capabilities” tab with step-by-step setup guide 10 diagnostic abilities for AI agents (server, cron jobs, database, security, performance, and more) Support for Cursor, Claude Desktop, ChatGPT via Model Context Protocol (MCP) Secure access using WordPress Application Passwords NEW: Cron Job Manager & WP-Cron Monitoring Full cron jobs dashboard: WP-Cron and Action Scheduler in one place Hook performance, overdue and orphan detection, execution history Abilities API integration: divewp/cron-insights for AI-driven cron diagnostics NEW: REST API Access Logging in User Events Track API access via Application Passwords in the event log Monitor AI agent activity and external integrations Throttled logging to prevent flood from MCP bursts IMPROVED: Cron Jobs Feature Enhancements Aligned AJAX and server health calculations for consistent status display “Potential orphan” terminology for clearer task identification Added Alternate Cron explanation footnote Visual accent pills for Important/Recommendation notes in task modals Support Need help? We’re here for you! 📚 Documentation 💬 Support Forum 🐞 Bug Reports and Contact Privacy DiveWP respects your privacy and that of your users. We do not collect any personal data. All analysis is performed locally on your server. Credits DiveWP is proudly created and maintained by Oleg Petrov.
Top keywords
- wordpress28×1.68%
- divewp27×1.62%
- performance26×1.56%
- cron22×1.32%
- abilities21×1.26%
- api19×1.14%
- abilities api17×1.02%
- ai16×0.96%
- hosting15×0.90%
- site14×0.84%
- log13×0.78%
- status12×0.72%
SudoWP Radar
WordPress 7.0 introduced a new AI attack surface. Every plugin that registers an ability on your site declares a structured entry point for AI agents and MCP tools. SudoWP Radar audits that surface at runtime, flagging misconfigurations before they become incidents. It sits between reactive CVE scanners (which wait for a vulnerability to be disclosed) and developer-side static analysis tools (which run before deployment). Radar audits what is actually registered and executing on your live site, right now. What it audits Core ability rules (WP 6.9+) Open and weak permissions — abilities with no permission_callback, or one that passes any authenticated user through regardless of role. Missing or loose input schemas — abilities that accept unconstrained string inputs on fields like path, file, url, redirect, or slug. Common injection vector for path traversal and SSRF. REST overexposure — abilities marked show_in_rest with no or open permission control, reachable by unauthenticated callers. Orphaned callbacks — execute_callbacks referencing functions no longer loaded, typically left behind by deactivated plugins. Namespace collisions — duplicate ability names where the last registration silently overwrites the first, potentially downgrading the permission model. AI agent rules (WP 7.0+) AI prompt filter bypass (HIGH) — a plugin has disabled the sitewide AI prompt prevention gate. Any AI agent connected to your site bypasses this control. AI REST overexposure (CRITICAL/HIGH) — REST endpoints that invoke the AI client with no or weak permission checks. Directly exploitable by unauthenticated callers. AI missing version gate (MEDIUM) — plugins calling the WP 7.0 AI client without a compatibility check, causing fatal errors on sites not yet running 7.0. Hosting-injected ability (HIGH) — an ability registered by a plugin auto-installed by your hosting provider, without explicit site administrator consent, with REST exposure enabled. Requires premium vendor slug list via the SudoWP dataset. Connector key in database (HIGH) — an AI provider API key (OpenAI, Anthropic, Google, or similar) is stored as plaintext in your WordPress database via the WP 7.0 Connectors API. Any SQL injection or object cache exposure on your site leaks this key directly. The fix is to define it as an environment variable or PHP constant instead. Why this matters now WordPress 7.0 ships with native AI agent integration. Plugins can now register abilities that AI agents call directly, expose AI endpoints over REST, and connect to external AI providers via the Connectors API. Each of these is a new attack surface that existing security scanners do not cover — they match known CVEs, they do not audit AI agent architecture. Some hosting providers have begun auto-installing AI agent plugins on customer sites without explicit consent. If one of those plugins registers abilities with REST exposure, or stores an AI provider key in your database, Radar flags it. How it works Radar reads the live abilities registry after all plugins and themes have loaded. It applies its rule engine to each registered ability and returns a findings report with severity ratings (CRITICAL, HIGH, MEDIUM, LOW) and specific remediation guidance per finding. A risk score from 0-100 summarises the overall exposure. The audit runs on demand. It does not affect front-end performance. Security model Requires the radar_run_audit capability (administrators by default). All requests are nonce-gated. No public-facing endpoints. Findings are stored in user meta, not global options. Rate-limited to one audit per 30 seconds per user. Free vs premium The free plugin is a fully functional standalone auditor. An optional premium add-on (SudoWP Pro) extends it with vulnerability dataset matching (CVE references, CVSS scores, patch guidance), the hosting-injected vendor slug list, scheduled audits with email alerts, multi-site dashboard aggregation, and report export. None of the premium features are required to run the core audit. External Services When an API key is configured, SudoWP Radar connects to the SudoWP vulnerability dataset API (api.sudowp.com) to retrieve patch availability information for registered WordPress abilities. No data is transmitted without an API key being explicitly entered by the site administrator. When no key is present, the plugin makes zero external network requests. Data sent to the API: the ability name being looked up and your API key. No personal data, no site URL, no user data is transmitted. API key registration: https://sudowp.com/get-api-key/ Terms of service: https://sudowp.com/tos/ Privacy policy: https://sudowp.com/privacy-policy/