Title: Ultimate Auditor
Author: Mayank Majeji
Published: <strong>2026 年 9 月 16 日</strong>
Last modified: 2026 年 9 月 25 日

---

搜尋外掛

![](https://ps.w.org/ultimate-auditor/assets/banner-772x250.png?rev=3701597)

![](https://ps.w.org/ultimate-auditor/assets/icon.svg?rev=3699295)

# Ultimate Auditor

 由 [Mayank Majeji](https://profiles.wordpress.org/mayankmajeji/) 開發

[下載](https://downloads.wordpress.org/plugin/ultimate-auditor.1.0.4.zip)

 * [詳細資料](https://tw.wordpress.org/plugins/ultimate-auditor/#description)
 * [使用者評論](https://tw.wordpress.org/plugins/ultimate-auditor/#reviews)
 *  [安裝方式](https://tw.wordpress.org/plugins/ultimate-auditor/#installation)
 * [開發資訊](https://tw.wordpress.org/plugins/ultimate-auditor/#developers)

 [技術支援](https://wordpress.org/support/plugin/ultimate-auditor/)

## 外掛說明

Ultimate Auditor connects your site to [Plugin Auditor](https://pluginauditor.com),
a plugin analysis service, and audits every plugin installed on your WordPress site.
Each plugin gets an overall score from 0 to 100, a score in six categories, and 
a list of issues pinned to the exact file and line, all without leaving your dashboard.

It is an automated code and standards audit, not a known-vulnerability (CVE) scanner.
It reads the plugin’s code and reports where it falls short.

### What it audits

Over 100 automated checks across six categories:

 * **Security**: nonces, capability checks, output escaping, input sanitisation,
   and safe database queries
 * **Code Quality**: WordPress coding standards, deprecated functions, and risky
   patterns
 * **Performance**: expensive operations, autoloaded options, and asset handling
 * **Compatibility**: PHP and WordPress version support
 * **Privacy**: data handling and external requests
 * **Accessibility**: markup and ARIA practices

It also flags plugins that are abandoned, closed on WordPress.org, or have an update
available.

### How results are presented

 * An overall score from 0 to 100 for each plugin, plus a score for each of the 
   six categories
 * Issue counts by severity: Critical, High, Medium, and Low
 * Maintenance flags: update available, abandoned, or closed on WordPress.org
 * A dashboard with site-wide category scores, the plugins that need attention, 
   and your scan quota
 * A link to the full report on pluginauditor.com, with every issue pinned to its
   file and line

### Good to know

 * This plugin is a client for Plugin Auditor. A free pluginauditor.com account 
   and API key are required to run scans.
 * Scanning is on demand. You trigger each scan; there is no background or scheduled
   scanning.
 * Full reports and version history are viewed on pluginauditor.com.
 * There is no WP-CLI interface; everything is done in the WordPress admin.

### Features

 * One-click scan for any single plugin
 * Bulk scan for all or selected plugins
 * Scores, category rings, and issue counts shown right on the Plugins page
 * A dashboard: site scores across six categories, plugins that need attention, 
   and recent scans
 * Real plugin icon, version and update status, and last-scan time per plugin
 * A score badge added to each plugin’s row in the WordPress Plugins list
 * Works with both WordPress.org-hosted and third-party (custom or premium) plugins
 * API key stored in the standard options table, never exposed in the front end
 * Connect and disconnect at any time from the Settings page

### External Services

This plugin connects to **pluginauditor.com**, a third-party plugin analysis service,
to scan your installed plugins. pluginauditor.com is developed and operated by the
same team that publishes this plugin.

Nothing is sent to pluginauditor.com until you enter an API key and click Connect.
Once connected, data is transmitted in the following situations:

**When you connect your account:**

 * Your API key, site URL (`home_url()`), site name, WordPress version, and this
   plugin’s version are sent to verify the key and register your site.

**When you run a scan (triggered by you):**

 * For plugins hosted on WordPress.org: the plugin slug and version number only,
   no files leave your server.
 * For third-party or premium plugins: a ZIP archive of the plugin folder is uploaded
   for analysis, then deleted from their servers after the scan completes.
 * Your API key and site URL accompany every scan request for authentication.

**Automatically, while connected:**

 * When any plugin on your site is activated, deactivated, or deleted, the plugin
   folder name and the new status (along with your API key and site URL) are sent
   to pluginauditor.com so your dashboard stays in sync. This happens only while
   an API key is connected.

**Inbound requests:**

 * While connected, the plugin registers REST API endpoints that pluginauditor.com
   can call to prepare a re-scan, download a plugin ZIP for analysis, or sync your
   installed-plugin list. These requests are authenticated with your API key (or
   a short-lived one-time token) before any action is taken.

Disconnecting your API key on the Settings page stops all communication with the
service.

**Service information:**

 * Service website: https://pluginauditor.com
 * Terms of Use: https://pluginauditor.com/terms
 * Privacy Policy: https://pluginauditor.com/privacy

### Plugin Languages

The plugin is currently available in English. To help translate it into your language,
visit the [translation page](https://translate.wordpress.org/projects/wp-plugins/ultimate-auditor/).

## 安裝方式

 1. Upload the `ultimate-auditor` folder to the `/wp-content/plugins/` directory, or
    install via the WordPress Plugins screen.
 2. Activate the plugin through the Plugins screen in WordPress.
 3. Go to **Ultimate Auditor > Settings** in your admin menu.
 4. Create a free account at [pluginauditor.com](https://pluginauditor.com) and copy
    your API key.
 5. Paste your API key and click **Connect**.
 6. Go to **Ultimate Auditor > Plugins** and start scanning.

## 常見問題集

### Is it free to use?

Yes. Ultimate Auditor is free. It connects to Plugin Auditor, where a free account
includes 30 scans per day, with full audit reports and shareable report links. Limits
reset daily and may change over time; see the [terms of use](https://pluginauditor.com/terms).

### What does it check, exactly?

Over 100 automated checks across six categories: Security, Code Quality, Performance,
Compatibility, Privacy, and Accessibility. Every finding is pinned to the exact 
file and line. It is a code and standards audit, not a known-vulnerability (CVE)
scanner.

### Does the plugin send my plugin files anywhere?

For plugins listed on WordPress.org, only the plugin slug and version number are
sent to the API, no files leave your server. For third-party or premium plugins 
that are not on WordPress.org, a ZIP of the plugin folder is uploaded for analysis
and deleted after the scan.

### What do the scores and severities mean?

Each plugin gets an overall score from 0 to 100, plus a score in six categories:
Security, Code Quality, Performance, Compatibility, Privacy, and Accessibility. 
Issues found are grouped by severity (Critical, High, Medium, and Low) so you can
prioritise what to fix first. Higher scores are better; a lower score or any Critical
or High issues mean the plugin needs attention.

### How many plugins can I scan?

The free plan allows 30 scans per day. Each single-plugin scan counts as one scan;
bulk scanning counts one scan per plugin. Limits reset daily and may change.

### Where can I see the full scan report?

After scanning, click the **View report** link on the plugin’s row. Reports open
on pluginauditor.com, where you can see the full breakdown of issues found, each
pinned to its file and line.

### Can I scan plugins that are not from WordPress.org?

Yes. Custom and premium plugins are supported. The plugin creates a ZIP of the plugin
folder and uploads it to the API for analysis, then it is deleted after the scan.

### Is my API key stored securely?

Your API key is stored in the WordPress database in the standard `wp_options` table,
the same place WordPress stores site settings. It is never exposed in front-end 
HTML or JavaScript.

### How do I stop the plugin from contacting pluginauditor.com?

Go to **Ultimate Auditor > Settings** and click Disconnect. This removes your API
key and stops all communication with the service.

### Where can I get support?

Ask in the [support forum](https://wordpress.org/support/plugin/ultimate-auditor/).

## 使用者評論

這個外掛目前沒有任何使用者評論。

## 參與者及開發者

以下人員參與了開源軟體〈Ultimate Auditor〉的開發相關工作。

參與者

 *   [ Mayank Majeji ](https://profiles.wordpress.org/mayankmajeji/)
 *   [ Mahesh Pawar ](https://profiles.wordpress.org/maheshpawar2012/)

[將〈Ultimate Auditor〉外掛本地化為台灣繁體中文版](https://translate.wordpress.org/projects/wp-plugins/ultimate-auditor)

### 對開發相關資訊感興趣？

任何人均可[瀏覽程式碼](https://plugins.trac.wordpress.org/browser/ultimate-auditor/)、
查看 [SVN 存放庫](https://plugins.svn.wordpress.org/ultimate-auditor/)，或透過 [RSS](https://plugins.trac.wordpress.org/log/ultimate-auditor/?limit=100&mode=stop_on_copy&format=rss)
訂閱[開發記錄](https://plugins.trac.wordpress.org/log/ultimate-auditor/)。

## 變更記錄

#### 1.0.4

 * Fixed scans of large plugins failing with “cURL error 28: Operation timed out”
   or “Server error (524)”. A scan is now submitted and its result checked every
   few seconds, so a plugin can take as long as it needs to audit. Update recommended.

#### 1.0.3

 * Fixed connecting and scanning on the live service. Update recommended.

#### 1.0.2

 * Clearer error messages when connecting a site or running a scan.

#### 1.0.1

 * Changed the API key format to `ultauditor_site_` followed by 40 hex characters.
   Reconnect with a new key from your pluginauditor.com account.

#### 1.0.0

 * Initial release.
 * Single-plugin and bulk scanning through the Plugin Auditor API.
 * Per-plugin score from 0 to 100 with six category scores and issue counts by severity.
 * Dashboard with site-wide category scores, plugins that need attention, recent
   scans, and scan quota.
 * Score badge and a Settings link in the WordPress Plugins list.
 * Connect and disconnect management on the Settings page.
 * Support for both WordPress.org-hosted and third-party plugins.
 * Help page with frequently asked questions.

## 中繼資料

 *  版本 **1.0.4**
 *  最後更新 **1 週前**
 *  啟用安裝數 **少於 10 次**
 *  WordPress 版本需求 ** 5.8 或更新版本 **
 *  已測試相容的 WordPress 版本 **6.9.9**
 *  PHP 版本需求 ** 7.4 或更新版本 **
 *  語言
 * [English (US)](https://wordpress.org/plugins/ultimate-auditor/)
 * 標籤:
 * [audit](https://tw.wordpress.org/plugins/tags/audit/)[code quality](https://tw.wordpress.org/plugins/tags/code-quality/)
   [scanner](https://tw.wordpress.org/plugins/tags/scanner/)[security](https://tw.wordpress.org/plugins/tags/security/)
 *  [進階檢視](https://tw.wordpress.org/plugins/ultimate-auditor/advanced/)

## 評分

這個項目尚無任何評論記錄。

[撰寫評分](https://wordpress.org/support/plugin/ultimate-auditor/reviews/#new-post)

[查看全部使用者評論](https://wordpress.org/support/plugin/ultimate-auditor/reviews/)

## 參與者

 *   [ Mayank Majeji ](https://profiles.wordpress.org/mayankmajeji/)
 *   [ Mahesh Pawar ](https://profiles.wordpress.org/maheshpawar2012/)

## 技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

 [檢視技術支援論壇](https://wordpress.org/support/plugin/ultimate-auditor/)