Sajjetti – AI Audit
Sajjetti – AI Audit is a security-first code scanner for WordPress plugins and themes. It performs static analysis of PHP, HTML, CSS, and JS files to detect vulnerabilities, performance issues, and coding standard problems before they become real risks. Privacy by design – Nothing runs automatically; all scans are triggered manually by the site owner. – Files are analyzed statically — never executed. – Remote analysis is disabled by default. No code leaves your site until you explicitly enable “Allow remote analysis” in Settings. – When enabled, selected file contents are sent securely over HTTPS to the Sajjetti API. Analysis data is temporary and discarded after results are returned. – Complies with WordPress.org privacy and consent guidelines. What it helps you find – Security: unescaped output, missing nonces and capability checks, unsafe file operations, risky SQL patterns, and other common vulnerabilities. – Performance: expensive loops, heavy queries, oversized assets, and inefficient patterns that slow down page loads. – Code quality and compatibility: deprecated APIs, version-specific pitfalls, and conflicts with WordPress coding standards. Optional AI assistance When remote analysis is enabled, the Sajjetti API provides AI-powered suggestions with context-specific recommendations. Results are presented with file-by-file drill-down, risk levels, and actionable insights. Human review is always recommended before making changes. Key Features Detects vulnerabilities, warnings, and performance issues Provides optional AI-assisted analysis with actionable suggestions Offers file-by-file drill-down and detailed reports Built with a security-first design, including VIP-compliant validation and sanitization Security Considerations All scans are user-initiated; nothing runs automatically. File contents are analyzed statically (never executed). REST endpoints require capability checks and nonces. All external requests use HTTPS with nonce and referer validation. Uninstall removes plugin data (options and tables) cleanly. All user-facing strings are escaped and translatable. Pricing and API Access The plugin includes a small allowance of free scans. Additional scans require an API key, available through a paid subscription. Privacy When you initiate a scan with remote analysis enabled, this plugin may transmit selected file contents (Base64-encoded PHP, HTML, CSS, and JS), limited file metadata (filename, relative path, size, cryptographic hash such as SHA-256), your site IP address and URL (for license validation), and your Sajjetti API username to the Sajjetti API for static analysis. No WordPress user account data, passwords, or database content is transmitted or stored. Temporary analysis data is deleted after results are returned. For details, see the included privacy.md file. Remote analysis is disabled by default. Scans cannot start until the site owner explicitly enables Allow remote analysis in Settings. External services This plugin connects to the Sajjetti Hub API (https://sajjetti.ai) to validate license status, manage usage limits, upload code snippets for analysis, and fetch audit results. Data sent: – License key and username when validating or checking usage. – Website URL and IP address when validating usage. – Selected PHP/JS/CSS source files when submitting for auditing. Data returned: – License type and remaining file quota. – Audit results (security, performance, and code quality insights). Legal & Privacy: – Terms of Service: https://sajjetti.ai/terms-of-service/ – Privacy Policy: https://sajjetti.ai/privacy-policy/
Top keywords
- analysis12×2.41%
- sajjetti9×1.81%
- api7×1.41%
- file7×1.41%
- data6×1.21%
- privacy6×1.21%
- remote6×1.21%
- remote analysis6×1.21%
- ai5×1.01%
- code5×1.01%
- https5×1.01%
- results5×1.01%
SEO Auditor Tools
Scan your WordPress site for SEO issues and get actionable fixes. Includes AI Helper, sitemap, robots.txt, LLMS.txt, Open Graph, cookie consent, analytics, UTM builder, QR code generator, image tools, caching, minification, security monitor, redirection manager, .htaccess editor, and chatbot. All features free – no Pro version. SEO Auditor Tools is a complete, no-paywall SEO and site management toolkit for WordPress. Run an automated site audit that crawls your pages and returns a fully scored report across four categories – SEO, Accessibility, Performance, and Best Practices – with plain-language issue cards and actionable fixes for every finding. Everything in this plugin is free. No feature is locked, no upsell gates your results. Full Audit Dashboard Run a single scan to get a four-category scored report covering your entire site: SEO score – H1 usage, heading hierarchy, missing alt text, empty links, broken assets, meta descriptions, canonical issues, and more. Accessibility score – Heading sequence violations, images missing alt attributes, empty interactive elements, and ARIA concerns. Performance score – Homepage response time, asset count, blocking scripts, third-party asset count, CSS/JS payload size, large assets, and unminified files. Best Practices score – Image dimension attributes, asset error rates, and general hygiene checks. Each issue card includes: * Severity badge (Critical / Warning) * Plain-language description of the problem * Concrete fix recommendation * Verification step so you know when it’s resolved The dashboard also shows: * PageSpeed Insights integration – connect your Google API key to pull live Lighthouse scores directly into the dashboard * LCP image detection – identifies the image most likely affecting Largest Contentful Paint * Crawl summary – discovered URLs, crawl depth, seed URLs, and error list * Site inventory – WordPress version, PHP version, active theme, plugin list, available updates * Score history – track how your scores change over time * Audit issues export – download a full CSV of all findings All Free Tools Included Audit Dashboard – Up to 200 pages crawled, 4-category scoring, detailed issue list, score history, and CSV export. Open Graph & Meta Description – Set global OG title, description, image, Twitter card, and fallback meta description. Includes a live Meta Tag Analyzer and OG Checker tool. Per-Page Meta – Override meta description and keywords on any post or page directly from the block editor sidebar. Sitemap Generator – One-click XML sitemap with full page list and auto-regeneration on publish. Robots.txt Editor – Edit or regenerate robots.txt with live preview and instant deploy. LLMS.txt Generator – Generate an llms.txt file at your site root to guide AI crawlers. Cookie Consent Banner – GDPR-friendly accept/reject banner with custom message, colours, positioning, and analytics/marketing consent defaults. Google Analytics & Tag Manager – Paste your GA4 or GTM snippet for automatic head injection. Additional tracking scripts (Bing, Yandex, others) also supported. IndexNow – Automatically ping Bing, Yandex, and compatible search engines whenever content is published or updated. UTM Campaign Builder – Build UTM-tagged marketing URLs and copy them in one click. QR Code Generator – Create QR codes for any URL. Download as PNG or copy Base64 inline. Settings Export – Export all plugin settings as JSON or CSV to migrate to another site in seconds. AI Helper – Use a self-hosted Ollama model to create structured meta-description proposals with preview, validation, approval, fix history, and undo. Security Monitor – File integrity checks, login hardening, HTTP security headers, and brute-force protection. Image Tools – Bulk add missing width/height dimensions, WebP conversion, regenerate thumbnails, and non-destructive image editing. Cache Tool – Server-side page caching with rules editor and pre-warming. Minify Tools – HTML, CSS, and JavaScript minification with per-file control. .htaccess Editor – Safe .htaccess editing with automatic backup and one-click restore. Redirection Manager – 301/302 redirect rules with import/export and first-login redirect support. Chatbot – Grounded website assistant using only public published content and explicitly approved document text, with optional AI-generated answers and source citations. Short Description SEO Auditor Tools is a complete, free, all-in-one SEO and site management toolkit for WordPress. All features free – no Pro version. External Services This plugin connects to the following third-party services: QR Server (api.qrserver.com) Used by the QR Code Generator tool to create QR code images on demand. When a user generates a QR code, the target URL is sent to the QR Server API and an image is returned. Service URL: https://api.qrserver.com/v1/create-qr-code/ Terms of Use: https://goqr.me/api/ Privacy Policy: https://goqr.me/de/rechtliches/datenschutz-goqrme.html Data sent: the URL you enter in the QR code generator. No personal data is transmitted. IndexNow (api.indexnow.org) Used by the IndexNow feature to notify Bing, Yandex, and other search engines when content is published or updated. This feature is opt-in and disabled by default. Service URL: https://api.indexnow.org/indexnow Terms of Use: https://www.indexnow.org/faq Privacy Policy: https://privacy.microsoft.com/en-us/privacystatement Data sent: the public URL of the updated page and your IndexNow API key. No personal data is transmitted. Google PageSpeed Insights (optional) Used when a PageSpeed Insights API key is configured. When a scan runs, the plugin sends the homepage URL to the PSI API and retrieves Lighthouse scores. This feature is disabled by default. Service URL: https://www.googleapis.com/pagespeedonline/v5/runPagespeed Terms of Use: https://developers.google.com/terms Privacy Policy: https://policies.google.com/privacy Data sent: your site’s homepage URL. No personal data is transmitted. Ollama (optional) AI Helper can connect to an Ollama endpoint configured by a site administrator. By default, only loopback hosts on the WordPress server are allowed. Remote hosts must be explicitly trusted with the seoautopro_ai_helper_allowed_ollama_hosts filter. Service URL: configured by the site administrator; the default is http://127.0.0.1:11434/api/generate Ollama documentation: https://docs.ollama.com/ Data sent: the selected page title, URL, excerpt, a limited plain-text content sample, current metadata, requested output language, and the generation instructions. For alt-text proposals, the image source URL, filename, nearby page text, and available attachment title or caption are also sent. When grounded chatbot AI is enabled, the visitor’s question and up to five relevant excerpts from public pages or administrator-approved document text are sent. Draft, private, password-protected, and unapproved content is never included. The image file and original chatbot document files are not uploaded by SEO Auditor Tools. AI Helper never applies model output automatically. Cloud AI providers (optional) When selected and configured by an administrator, AI Helper can send generation requests to Google Gemini, GroqCloud, OpenRouter, OpenAI, or Anthropic Claude. These services are disabled until the administrator selects one and supplies any required API key. Provider accounts, quotas, free tiers, and charges are managed by the provider. Google Gemini API: https://generativelanguage.googleapis.com/ — Terms: https://ai.google.dev/gemini-api/terms — Privacy: https://policies.google.com/privacy GroqCloud API: https://api.groq.com/ — Terms: https://groq.com/terms-of-use/ — Privacy: https://groq.com/privacy-policy/ OpenRouter API: https://openrouter.ai/api/ — Terms: https://openrouter.ai/terms — Privacy: https://openrouter.ai/privacy OpenAI API: https://api.openai.com/ — Terms: https://openai.com/policies/terms-of-use/ — Privacy: https://openai.com/policies/privacy-policy/ Anthropic API: https://api.anthropic.com/ — Terms: https://www.anthropic.com/legal/commercial-terms — Privacy: https://www.anthropic.com/legal/privacy Data sent: the selected page title, URL, excerpt, a limited plain-text content sample, current metadata, requested output language, and the generation instructions. For alt-text proposals, the image source URL, filename, nearby page text, and available attachment title or caption are also sent. When grounded chatbot AI is enabled, the visitor’s question and up to five relevant excerpts from public pages or administrator-approved document text are sent. Draft, private, password-protected, and unapproved content is never included. The image file and original chatbot document files are not uploaded by SEO Auditor Tools. The configured API key is sent only to authenticate with the selected provider. AI Helper never applies model output automatically. Custom OpenAI-compatible endpoint (optional) An administrator can configure a third-party or self-hosted endpoint that implements the OpenAI chat-completions request and response format. Remote endpoints must use HTTPS; loopback endpoints may use HTTP. The endpoint operator’s own terms and privacy policy apply. Data sent: the selected page title, URL, excerpt, a limited plain-text content sample, current metadata, requested output language, generation instructions, and an API key when configured. For alt-text proposals, the image source URL, filename, nearby page text, and available attachment title or caption are also sent. When grounded chatbot AI is enabled, the visitor’s question and up to five relevant excerpts from public pages or administrator-approved document text are sent. Draft, private, password-protected, and unapproved content is never included. The image file and original chatbot document files are not uploaded by SEO Auditor Tools. AI Helper never applies model output automatically.