# WP Auditor

> Audit any WordPress site for real performance issues — JS bloat, render-blocking scripts, unused CSS, oversized images, plugin overhead and more. Powered by a Playwright backend for deep network analysis.

Canonical page: [https://chrome-stats.com/d/wp-auditor](https://chrome-stats.com/d/wp-auditor)

## Overview

- **ID:** `wp-auditor`
- **Platform:** Firefox
- **Type:** Firefox add-on
- **Status:** Available
- **Publisher:** Aswin E
- **Category:** other
- **Daily users:** 1
- **Weekly downloads:** 1
- **Version:** 1.0.1
- **Last updated:** 2026-08-11
- **First published:** 2026-08-07
- **Size:** 30 KB
- **Data as of:** 2026-09-09
- **Store listing:** [Firefox Add-ons Store](https://addons.mozilla.org/firefox/addon/wp-auditor/)

## Description

WP Auditor is a developer tool that performs deep performance analysis on any 
webpage, with a focus on WordPress sites. Unlike generic tools, every issue 
comes with real evidence — actual file URLs, byte sizes, DOM paths, and 
plugin names — not vague suggestions.

HOW IT WORKS

The extension collects live data directly from the page you are viewing 
(DOM structure, scripts, stylesheets, images, WordPress signals) and sends 
it to a local Playwright backend, which runs a headless browser pass to 
measure real network sizes, CSS coverage, and load timing. Results appear 
in the sidebar alongside your page.

WHAT IT CHECKS

JavaScript
- Render-blocking scripts in  without defer or async
- jQuery and jQuery Migrate loaded in production
- Duplicate libraries loaded by competing plugins
- Excessive JS file count and total payload size
- Inline script count

CSS
- Total stylesheet count
- Large CSS files over 100KB
- Page builder stylesheets (Elementor, Divi, WPBakery, Beaver Builder)
- Estimated unused CSS percentage via Chrome Coverage API

Network
- Total HTTP request count and page weight
- Third-party domains adding connection overhead
- External domains missing preconnect hints
- Full page load time

DOM
- Total node count (flags above 1500)
- Maximum nesting depth (flags above 15 levels)

Media
- Images served larger than their display size
- Images missing lazy loading
- CSS background images used instead of proper img tags

WordPress-Specific
- Plugin detection via asset URL paths (30+ plugins recognised)
- admin-ajax.php used for frontend requests
- WordPress version detection

Anti-Patterns
- Multiple separate Google Fonts requests
- Excessive font file variants
- Unthrottled scroll and resize event listeners

SCORING

Each issue is weighted by severity (Critical, High, Medium, Low) and a 
score from 0 to 100 is calculated. The sidebar shows a breakdown by 
category so you can prioritise fixes.

REQUIREMENTS
<ul><li>Firefox 140 or higher</li><li>A local Node.js backend running on port 3001
  (included in the download — one command to start)</li></ul>
This tool is intended for developers, QA engineers, and performance 
auditors who need actionable evidence, not a traffic-light score.

WP Auditor is a developer tool that audits web pages for performance 
issues, with a focus on WordPress sites. It uses a hybrid architecture: 
the extension collects DOM/JS/CSS data from the active tab via a content 
script, then sends it to a locally-running Node.js backend (included with 
the extension) which performs a deeper network analysis using Playwright.

This extension requires a companion backend server running on 
<a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/3ef672eae7bc1445bb72eff13c3c3c764b69e695d4be6d6a5ae54a99d3b0caf1/http%3A//localhost%3A3001" rel="nofollow">http://localhost:3001</a> to function. The backend is a Node.js/TypeScript 
server (included in the downloadable package from our website) that the 
developer runs locally on their own machine. 

To start the backend:
  cd backend
  npm install
  npx playwright install chromium
  npx ts-node server.ts

The extension will show a red status dot and an error message if the 
backend is not running. No data is sent to any external server — all 
analysis happens locally on the user's machine.

The sidebar makes fetch() calls to <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/3ef672eae7bc1445bb72eff13c3c3c764b69e695d4be6d6a5ae54a99d3b0caf1/http%3A//localhost%3A3001" rel="nofollow">http://localhost:3001</a> to:
1. POST the collected DOM data for analysis
2. Poll for the audit result

This is entirely local — no third-party servers, no cloud services, no 
data leaves the user's machine.

<ul><li>activeTab      : Read the URL of the currently active tab</li><li>tabs           : Query the active tab to get its URL and send messages</li><li>storage        : Reserved for future settings persistence (not yet used)</li><li>http://<em>/</em>     : Required to inject the content script into HTTP pages
                   and to allow the sidebar to call localhost:3001</li><li>https://<em>/</em>    : Required to inject the content script into HTTPS pages
                   (most WordPress sites)</li></ul>

content.js is injected into the active tab only when the user clicks 
"Audit This Page" in the sidebar. It reads:
  - Script and stylesheet tags (src attributes only)
  - DOM element count and nesting depth
  - Image natural vs display dimensions
  - Computed background-image styles (decorative image detection)
  - window.jQuery global (version detection)
  - Inline script text content (pattern matching only)
  - Meta generator tag (WordPress version)

The content script does NOT:
  - Read form inputs or user-entered data
  - Access cookies or localStorage
  - Send any data to external servers
  - Persist any data

All collected data is passed to the local backend via the sidebar and 
discarded after the audit report is generated.

The sidebar (sidebar/sidebar.js) uses DOMParser + replaceChildren() 
for all dynamic HTML rendering — no innerHTML assignments. All user-facing 
strings are passed through escHtml() for XSS safety. All click handlers 
use event delegation via data-action attributes — no inline onclick handlers.

<ol><li>Install the extension temporarily via about:debugging</li><li>Start the backend: npx ts-node server.ts (requires Node.js 18+)</li><li>Navigate to any WordPress site (e.g. <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/f702627c47f0332feb02a0e2f69494b0107f6ae1d2632046009fe8ee86e99901/https%3A//wordpress.org" rel="nofollow">https://wordpress.org</a>)</li><li>Click the WP Auditor toolbar icon to open the sidebar</li><li>Click "Audit This Page"</li><li>The sidebar will show a 3-step progress indicator and then display 
   the audit report with scored issues, severity filters, and 
   expandable evidence for each finding</li></ol>
If the backend is not running, the extension gracefully shows an error 
message with setup instructions. No crashes or unhandled errors occur 
in the offline state.

The extension itself (manifest, background, content, sidebar files) has 
zero external dependencies and makes no network requests except to 
<a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/3ef672eae7bc1445bb72eff13c3c3c764b69e695d4be6d6a5ae54a99d3b0caf1/http%3A//localhost%3A3001" rel="nofollow">http://localhost:3001</a> (the user's own machine).

## Rankings

- #125,307 — Overall
- #141 — jquery

## Permissions and access

### Permissions

- `activeTab`
- `tabs`
- `storage`
- `http://*/*`
- `https://*/*`

### Content script matches

- `<all_urls>`

## Safety

- **Risk impact:** High risk impact
- **Risk likelihood:** High risk likelihood

### Analysis details

- Grants access to browser tabs, which can be used to track user browsing habits and history, presenting a privacy concern.
- This extension was recently updated in the past month. New updates may not be stable or safe.

> Some risk analysis details are omitted from this free response. [Upgrade to view the full analysis](https://chrome-stats.com/pricing).

## Similar extensions and apps

- [WPoptic | WordPress Theme and Plugins Detector](https://chrome-stats.com/d/wpoptic) — 1 users
- [WP Detective](https://chrome-stats.com/d/wp-detective) — 49 users
- [Website Performance Analyzer Tool](https://chrome-stats.com/d/performance-analyzer-tool) — 5 users
- [WP Hive - A better WordPress Repository](https://chrome-stats.com/d/wp-hive) — 156 users, 2.50 / 5
- [CMS & WordPress Detector](https://chrome-stats.com/d/cms-wordpress-detector) — 3 users, 5.00 / 5
- [Performance Analyzer](https://chrome-stats.com/d/performance-analyzer) — 1 users
- [Platform Detector](https://chrome-stats.com/d/platform-detector) — 16 users
- [WordPress Plugin & Theme Detector](https://chrome-stats.com/d/wp-plugin-theme-detector) — 47 users
- [Web Optimization Companion](https://chrome-stats.com/d/web-optimization-companion)
- [WP Engine Cache Inspector](https://chrome-stats.com/d/wp-engine-cache-inspector)
- [TD Site Inspector](https://chrome-stats.com/d/td-site-inspector) — 5 users
- [WordPress Detector+](https://chrome-stats.com/d/wordpress-inspector) — 5 users

---

Source: [Chrome-Stats](https://chrome-stats.com/d/wp-auditor)
