The same report, as JSON
For scripts, dashboards and scheduled checks. One GET request, no key, and the response holds everything the report page shows. The API reads without Jev unless the check was started from the form on this site, so a script gets siteKind as null and the fix-first list in its default order.
Request
curl "https://wp-front-door.hamzaahmadaslam.com/api/check?url=example.com"url takes a domain or a full address, the same as the form. The address rules on how the check works apply: public sites only, standard ports, no credentials.
Response
A JSON object with Cache-Control: no-store, shortened here:
{
"url": "https://example.com/",
"finalUrl": "https://example.com/",
"status": 200,
"hops": 0,
"ttfbMs": 412,
"wordpress": true,
"theme": "twentytwentyfive",
"plugins": ["contact-form-7", "woocommerce"],
"scores": { "security": 65, "caching": 75, "performance": 90, "overall": 76 },
"findings": [
{
"id": "users",
"area": "security",
"severity": "bad",
"title": "User names are listed by the REST API",
"detail": "/wp-json/wp/v2/users answers with account names ...",
"fix": "Restrict the users endpoint to logged-in requests ..."
}
],
"fixFirst": [ ... ]
}- url
- The address as the checker understood it.
- finalUrl
- Where the redirects ended.
- fetchedAt
- When the check ran, as an ISO 8601 time in UTC.
- status
- The HTTP status of the final response.
- hops
- How many redirects came before the page.
- ttfbMs
- Time to first byte on the final hop, in milliseconds.
- https
- Whether the final address is HTTPS.
- wordpress
- Whether the page looks like WordPress.
- generator
- The generator meta tag, or null.
- theme
- The theme folder name seen in the page, or null.
- plugins
- Plugin folder names seen in the page's file paths.
- thirdParties
- Host names, other than the site's own, that serve scripts.
- htmlBytes
- The size of the HTML document.
- scores
- overall, security, caching and performance, each 0 to 100.
- findings
- Every finding: id, area, severity (good, warn, bad or info), title, detail and, where there is one, fix.
- fixFirst
- Up to five findings to fix first, in order.
- siteKind
- Jev's reading of the kind of site, with a probability, or null.
- jevSkipped
- Why Jev was not asked: ai-text, budget, unverified (the check was not started from the form), or null.
Finding ids are stable, so a script can watch for one, for example users or page-cache. Each has a fix guide.
Errors and limits
Errors come back as { "error": "..." } with a status that says why:
- 400 for an address it will not check or cannot find: a private one, a non-standard port, a name that does not resolve.
- 429 after ten checks in a minute from one address, or twenty checks of one site in ten minutes.
- 502 when the site could not be reached: it timed out after eight seconds, refused or dropped the connection, or has an invalid HTTPS certificate.
The limits count per server instance and are there to keep the checker polite to the sites it visits. For regular monitoring, once an hour per site is plenty.