WP Front Door

The same report, as JSON

For scripts, dashboards and scheduled checks. One GET request, no key, and the response holds everything the report page shows. The API reads without Jev unless the check was started from the form on this site, so a script gets siteKind as null and the fix-first list in its default order.

Request

Shell
curl "https://wp-front-door.hamzaahmadaslam.com/api/check?url=example.com"

url takes a domain or a full address, the same as the form. The address rules on how the check works apply: public sites only, standard ports, no credentials.

Response

A JSON object with Cache-Control: no-store, shortened here:

JSON
{
  "url": "https://example.com/",
  "finalUrl": "https://example.com/",
  "status": 200,
  "hops": 0,
  "ttfbMs": 412,
  "wordpress": true,
  "theme": "twentytwentyfive",
  "plugins": ["contact-form-7", "woocommerce"],
  "scores": { "security": 65, "caching": 75, "performance": 90, "overall": 76 },
  "findings": [
    {
      "id": "users",
      "area": "security",
      "severity": "bad",
      "title": "User names are listed by the REST API",
      "detail": "/wp-json/wp/v2/users answers with account names ...",
      "fix": "Restrict the users endpoint to logged-in requests ..."
    }
  ],
  "fixFirst": [ ... ]
}
url
The address as the checker understood it.
finalUrl
Where the redirects ended.
fetchedAt
When the check ran, as an ISO 8601 time in UTC.
status
The HTTP status of the final response.
hops
How many redirects came before the page.
ttfbMs
Time to first byte on the final hop, in milliseconds.
https
Whether the final address is HTTPS.
wordpress
Whether the page looks like WordPress.
generator
The generator meta tag, or null.
theme
The theme folder name seen in the page, or null.
plugins
Plugin folder names seen in the page's file paths.
thirdParties
Host names, other than the site's own, that serve scripts.
htmlBytes
The size of the HTML document.
scores
overall, security, caching and performance, each 0 to 100.
findings
Every finding: id, area, severity (good, warn, bad or info), title, detail and, where there is one, fix.
fixFirst
Up to five findings to fix first, in order.
siteKind
Jev's reading of the kind of site, with a probability, or null.
jevSkipped
Why Jev was not asked: ai-text, budget, unverified (the check was not started from the form), or null.

Finding ids are stable, so a script can watch for one, for example users or page-cache. Each has a fix guide.

Errors and limits

Errors come back as { "error": "..." } with a status that says why:

  • 400 for an address it will not check or cannot find: a private one, a non-standard port, a name that does not resolve.
  • 429 after ten checks in a minute from one address, or twenty checks of one site in ten minutes.
  • 502 when the site could not be reached: it timed out after eight seconds, refused or dropped the connection, or has an invalid HTTPS certificate.

The limits count per server instance and are there to keep the checker polite to the sites it visits. For regular monitoring, once an hour per site is plenty.