# WordPress Final-Pass Fine-Tooth-Comb Audit Prompt

- Source conversation: Refresh project context
- Conversation ID: `6a86031f-ba3c-83e8-928e-3c01333a9d07`
- Conversation created: 2026-08-19
- ChatGPT writing-block ID: `58324`
- Recovery status: Exact writing-block body; publication review pending

---

You are performing a **comprehensive final-pass audit of this WordPress website** before it is considered production-ready.

Your job is to **fine-tooth-comb the entire WordPress installation and every website component you can access**. Do not merely look for obvious visual problems. Inspect the site systematically at the page, post, media, theme, plugin, settings, metadata, accessibility, SEO, integration, form, and connected-service levels.

## Primary objective

Determine:

1. What is complete and correctly configured.
2. What is missing.
3. What contains placeholder, outdated, inconsistent, duplicated, or incorrect information.
4. What fields exist but have been left blank when they should contain information.
5. What information is present but could be improved.
6. What components are installed or connected but not fully configured.
7. What may cause accessibility, SEO, usability, security, privacy, performance, or maintainability problems.
8. What should be fixed before the site is considered finished.

**Do not make changes unless I explicitly authorize them. Audit first and report your findings.**

---

# 1. WORDPRESS CORE AND GENERAL SETTINGS

Inspect all relevant WordPress settings, including:

- Site Title
- Tagline
- WordPress Address
- Site Address
- Administration Email
- Site Language
- Timezone
- Date format
- Time format
- Week-start setting
- Membership settings
- Default user role
- Reading settings
- Homepage assignment
- Posts page assignment
- Search engine visibility
- Discussion/comment settings
- Media settings
- Permalink structure
- Privacy page assignment
- Any custom settings introduced by the active theme or plugins

Flag settings that are:

- Blank
- Incorrect
- Inconsistent with the site's intended identity
- Still using defaults
- Unnecessary
- Potentially unsafe
- Not appropriate for a production website

---

# 2. PAGES AND POSTS

Inspect **every published page, draft, private page, post, custom post type, landing page, template, and relevant archive**.

For each item, check:

- Title
- URL slug
- Page status
- Author
- Publication/update dates
- Featured image
- Excerpt
- Page template
- Parent/child relationships
- Menu placement where applicable
- Heading hierarchy
- Page copy
- Buttons
- Calls to action
- Internal links
- External links
- Contact information
- Addresses
- Phone numbers
- Email addresses
- Business/service information
- Copyright information
- Any placeholder text
- Dummy content
- Repeated content
- Broken formatting
- Empty sections
- Hidden sections
- Desktop/mobile inconsistencies

Verify that page content agrees with information elsewhere on the site.

Identify orphaned pages, duplicate pages, obsolete pages, test pages, sample WordPress content, unused drafts, and content that should probably be deleted or redirected.

---

# 3. MEDIA LIBRARY

Inspect the WordPress Media Library as thoroughly as possible.

For each image or other important media asset, review:

- File name
- Media title
- Alt text
- Caption
- Description
- Attachment metadata
- File dimensions
- File format
- File size where relevant
- Whether the file appears compressed appropriately
- Whether the image is actually used anywhere
- Whether duplicate versions exist
- Whether outdated versions exist

## Alt-text audit

Pay particular attention to alt attributes.

For every meaningful image:

- Determine whether alt text exists.
- Determine whether the alt text accurately describes the image's purpose in context.
- Flag generic alt text such as "image," "photo," filenames, keyword stuffing, or irrelevant descriptions.
- Identify decorative images that should intentionally use empty alt text.
- Identify linked images whose alt text should communicate the destination or purpose.
- Identify logos requiring appropriate treatment.
- Identify images containing meaningful text that may need that information represented elsewhere.

Do not assume that simply having something in the Alt Text field means it is correct.

---

# 4. SEO AND SEARCH METADATA

Inspect native WordPress SEO information and every relevant SEO plugin or integration.

For each indexable page or content item, verify where applicable:

- SEO title
- Meta description
- Canonical URL
- Robots directives
- Index/noindex status
- Follow/nofollow status
- Open Graph title
- Open Graph description
- Open Graph image
- Twitter/social-sharing metadata
- Schema markup
- Breadcrumb settings
- Focus keyword/keyphrase if the plugin uses one
- XML sitemap inclusion
- Image sitemap behavior
- Redirects
- 404 handling

Look for:

- Missing titles
- Duplicate titles
- Missing meta descriptions
- Duplicate descriptions
- Titles/descriptions that are too generic
- Old brand names
- Incorrect URLs
- Staging URLs
- Development-domain references
- Incorrect canonical tags
- Accidental noindex directives
- Conflicting SEO plugins or settings

Also determine whether search engines are currently permitted to index the finished site.

---

# 5. ACCESSIBILITY

Perform as comprehensive an accessibility review as the available access allows.

Inspect:

- Image alt attributes
- Heading hierarchy
- H1 usage
- Form labels
- Form instructions
- Required-field indicators
- Error messages
- Button labels
- Link text
- Keyboard accessibility
- Focus visibility
- Color contrast
- Text size
- Zoom behavior
- Skip links
- Landmark regions
- Navigation semantics
- ARIA labels and attributes
- Accessible names
- Modal/dialog behavior
- Accordions
- Menus
- Carousels/sliders
- Video captions
- Audio alternatives
- Tables
- Icon-only controls
- Screen-reader-only text

Flag vague links such as:

- Click here
- Learn more
- Read more

when their context does not provide a meaningful accessible name.

Where possible, distinguish between:

- Definite accessibility failures
- Likely accessibility concerns
- Items that require manual human testing

---

# 6. NAVIGATION AND SITE STRUCTURE

Inspect:

- Primary navigation
- Secondary navigation
- Mobile navigation
- Footer navigation
- Utility navigation
- Breadcrumbs
- Logo/home links
- Social links

Check that:

- Every menu item points to the intended destination.
- No menu links are broken.
- No navigation points to staging or development URLs.
- Menu labels are clear.
- Important pages are reachable.
- Unnecessary items are removed.
- The mobile menu contains the proper items.
- Footer and header information agree.
- Navigation hierarchy makes sense.

---

# 7. LINKS

Inspect internal and external links throughout the site.

Find:

- Broken links
- Redirect chains
- HTTP links that should use HTTPS
- Links to staging sites
- Links to localhost
- Links to old domains
- Incorrect anchors
- Empty links
- "#" placeholder links
- JavaScript placeholder links
- Buttons without destinations
- Social icons without URLs
- Telephone links with incorrect numbers
- Email links with incorrect addresses
- External links that should or should not open in a new tab

Report the exact page/component where each issue occurs.

---

# 8. FORMS

Inspect every form, including:

- Contact forms
- Newsletter forms
- Appointment/request forms
- Search forms
- Login forms
- Comment forms
- Checkout forms if applicable
- Plugin-generated forms
- Pop-up forms

For every form verify:

- Field labels
- Placeholder text
- Required fields
- Validation
- Error messages
- Success messages
- Recipient addresses
- Sender/from addresses
- Reply-to settings
- Subject lines
- Notification templates
- Autoresponders
- Spam protection
- CAPTCHA if used
- Privacy/consent wording
- Accessibility
- Mobile layout

Determine whether form submissions are actually deliverable and whether anything appears likely to fail due to email/SMTP configuration.

Do not submit destructive or live transactional forms without authorization.

---

# 9. THEME

Inspect the active theme and any child theme.

Review:

- Theme version
- Child-theme status
- Theme settings
- Customizer settings
- Global styles
- Typography
- Colors
- Header
- Footer
- Logo
- Favicon/site icon
- Templates
- Template parts
- Widget areas
- Custom CSS
- Theme-specific SEO fields
- Theme-specific social fields
- Theme-specific contact/business fields

Look for unused or conflicting settings and defaults that were never customized.

If an inactive theme contains configuration relevant to the finished site, note it, but do not confuse inactive-theme settings with the production configuration.

---

# 10. PLUGINS

Create an inventory of **every installed plugin**.

For each plugin identify:

- Plugin name
- Purpose
- Active/inactive status
- Whether it appears necessary
- Whether configuration is complete
- Important blank fields
- Warnings or errors
- Connected external accounts
- Duplicate functionality with another plugin
- Potential conflicts
- Whether it appears abandoned or obsolete
- Whether an update is available
- Whether removing it would affect the site

Then inspect the settings of every active plugin rather than merely listing them.

Pay special attention to plugins involving:

- SEO
- Caching
- Security
- Backups
- Forms
- SMTP/email
- Analytics
- Cookies/consent
- Social sharing
- Image optimization
- Redirects
- Page builders
- Accessibility
- Schema
- Spam prevention
- E-commerce
- Membership
- Booking
- Maps
- Embedded services

Report any field that appears to require site-specific information but is empty, defaulted, inconsistent, or obviously incorrect.

---

# 11. CONNECTED SERVICES AND INTEGRATIONS

Identify all detectable external integrations.

Examples include:

- Google Analytics
- Google Search Console
- Google Tag Manager
- Google Maps
- reCAPTCHA
- SMTP/email providers
- Newsletter platforms
- Facebook/Meta
- Instagram
- YouTube
- Payment providers
- Booking systems
- CRM systems
- Cloudflare
- CDN services
- Backup storage
- Security services
- Cookie-consent services
- External APIs
- Webhooks

For each integration determine:

- Whether it appears connected
- Whether credentials/settings appear present
- Whether the integration is actually functioning where observable
- Whether duplicate tracking scripts exist
- Whether old IDs or accounts remain
- Whether production and staging identifiers have been mixed up

**Never expose passwords, API secrets, private keys, tokens, or other sensitive credentials in your report.**

If credentials exist, simply report whether the relevant field appears configured.

---

# 12. BRAND AND BUSINESS INFORMATION CONSISTENCY

Search the entire site and configuration for business-identifying information.

Compare:

- Site/business name
- Person's name
- Logo
- Tagline
- Address
- Phone number
- Email address
- Hours
- Social profiles
- Service area
- Business description
- Copyright name
- Copyright year
- Legal/business name where applicable

Identify contradictions or variations.

Also search for old:

- Company names
- Domains
- Phone numbers
- Email addresses
- Addresses
- Social profiles
- Previous owners
- Developers
- Theme demo content
- Template company names

---

# 13. HEADER, FOOTER, AND GLOBAL COMPONENTS

Inspect all globally repeated elements.

Check:

- Header
- Footer
- Announcement bars
- Sidebars
- Widgets
- Floating buttons
- Cookie banners
- Pop-ups
- Mobile-only components
- Desktop-only components
- Reusable/global blocks
- Template parts

Because these components repeat across the site, treat errors here as high priority.

---

# 14. RESPONSIVE AND VISUAL QUALITY

Review representative pages at:

- Desktop width
- Tablet width
- Mobile width

Look for:

- Overflow
- Cropping
- Overlapping content
- Excessive whitespace
- Tiny text
- Broken columns
- Buttons extending off-screen
- Images with poor crops
- Menus that fail
- Pop-ups that cannot be closed
- Horizontally scrolling pages
- Inconsistent margins/padding
- Layout shifts
- Missing content at certain breakpoints

Do not judge merely according to personal aesthetic preference. Flag actual inconsistencies, defects, or areas that undermine clarity/usability.

---

# 15. PERFORMANCE

Look for obvious performance problems, including:

- Extremely large images
- Unoptimized image formats
- Duplicate scripts
- Excess plugins
- Unused plugins
- Excessive web fonts
- Render-blocking resources where detectable
- Missing caching
- Conflicting caching
- Excess third-party scripts
- Autoloaded plugin data concerns if visible
- Broken lazy loading
- Video/media loading problems

Separate genuine problems from optional optimization opportunities.

---

# 16. SECURITY AND MAINTENANCE

Perform a non-destructive configuration review.

Check for:

- WordPress/core updates
- Plugin updates
- Theme updates
- Inactive plugins
- Inactive themes
- Default admin-style usernames where visible
- Unnecessary accounts
- User roles that appear excessive
- HTTPS configuration
- Mixed content
- Backup configuration
- Security-plugin configuration
- Debug mode or visible debugging output
- Directory or server information exposed through the site
- Obvious spam accounts/comments
- XML-RPC exposure where relevant
- File-editing/admin configuration concerns where visible

Do **not** perform penetration testing, exploit attempts, password guessing, or destructive security testing.

---

# 17. PRIVACY, COOKIES, AND LEGAL-PRESENTATION ITEMS

Check whether the site's actual functionality is consistent with its visible privacy disclosures.

Inspect:

- Privacy Policy
- Cookie notice
- Cookie preferences
- Contact forms
- Analytics
- Tracking scripts
- Embedded third-party content
- Newsletter collection
- Consent checkboxes
- Terms/disclaimers if applicable

Do not provide legal conclusions. Flag apparent omissions, contradictions, or areas requiring human/legal review.

---

# 18. WORDPRESS DATABASE/CONTENT RESIDUE WHERE ACCESSIBLE

Without making destructive changes, look for indications of:

- Old staging URLs
- Old domain names
- Demo content
- Theme demo settings
- Shortcodes from removed plugins
- Broken embeds
- Orphaned widgets
- Unused reusable blocks
- Deprecated page-builder elements
- Leftover test data

Search broadly enough that an old URL or name hidden in an obscure setting is not overlooked.

---

# 19. ERROR AND EDGE-CASE TESTING

Check important site states such as:

- 404 page
- Search with results
- Search with no results
- Empty form submission
- Invalid form submission
- Thank-you/success states
- Missing-image behavior
- Mobile navigation
- Footer
- External links
- Browser title/tab display
- Social-share preview metadata where inspectable

Look for WordPress notices, JavaScript errors, missing resources, broken icons, and visible plugin errors.

---

# 20. FINAL FIELD-BY-FIELD SWEEP

After completing the category-based audit, perform one additional pass specifically looking for **configuration fields that were easy to overlook**.

Whenever you encounter an admin screen, plugin panel, theme panel, page settings panel, media item, reusable block, template, integration, or settings screen, ask:

- Does this field contain information?
- Should it?
- Is the information correct?
- Is it still a default?
- Does it contradict information elsewhere?
- Is there a better value that should be entered?
- Is this field intentionally blank?
- Could this setting affect another part of the site?

Do not assume blank fields are errors. Determine whether each blank field is actually relevant.

---

# REPORTING FORMAT

Do not give me one giant unsorted list.

Organize the final report into these sections:

## A. Executive Summary

Give me a concise assessment of overall readiness.

Include:

- Overall condition
- Major blockers
- Number of critical issues
- Number of important issues
- Number of minor issues
- Areas that appear complete

## B. Must Fix Before Launch

For each issue provide:

- Exact location
- Page/plugin/theme/component
- Field or setting
- Current condition
- Why it matters
- Recommended correction

## C. Should Fix

Use the same format.

## D. Optional Improvements

List worthwhile improvements that are not launch blockers.

## E. Missing or Incomplete Fields

Create a dedicated list of fields that need information entered.

For each one state:

- Where it is
- Field name
- What type of information belongs there
- Your recommended value when it can be confidently inferred
- `NEEDS OWNER INPUT` when it cannot be determined safely

## F. Alt-Text Audit

List every image that:

- Has missing alt text
- Has questionable alt text
- Has incorrect alt text
- Should probably have empty decorative alt text

Recommend corrected alt text where appropriate.

## G. Plugin and Integration Audit

Provide a table or structured list showing:

- Component
- Purpose
- Status
- Configuration status
- Issues
- Recommended action

## H. Consistency Problems

Report conflicting names, URLs, addresses, emails, phone numbers, branding, social links, and similar information.

## I. Things Requiring Human Verification

Clearly identify anything you could not conclusively test.

## J. Verified Good

Include important areas you inspected and found correctly configured.

This is important because I need to know what was actually checked, not just what failed.

---

# SEVERITY LABELS

Use these labels consistently:

**CRITICAL** — likely to break the site, prevent an important function, expose sensitive information, or cause a serious launch problem.

**HIGH** — should be corrected before launch.

**MEDIUM** — meaningful quality, accessibility, SEO, consistency, or maintenance issue.

**LOW** — polish or minor cleanup.

**INFO** — observation or optional improvement.

---

# AUDIT RULES

1. **Do not make assumptions simply to fill gaps.**
2. If something cannot be determined, say `UNVERIFIED`.
3. If information must come from the site owner, say `NEEDS OWNER INPUT`.
4. Do not report a feature as working unless you actually verified it to the extent possible.
5. Do not report a field as missing merely because it is blank; first determine whether that field matters.
6. Do not expose passwords, API keys, authentication tokens, database credentials, or private information.
7. Do not make changes during the audit.
8. Do not delete anything.
9. Do not deactivate plugins.
10. Do not update WordPress, plugins, or themes during this pass.
11. Do not submit purchases, payments, bookings, or other irreversible transactions.
12. Preserve existing data.
13. Record the exact location of every issue so another person can reproduce and fix it.
14. When one problem appears globally, identify the underlying global component instead of unnecessarily reporting the same defect once for every page.
15. Check both what visitors can see and the underlying WordPress/admin configuration where access permits.
16. Continue until you have exhausted every reasonably accessible WordPress area rather than stopping after finding the first group of issues.

The goal is not to tell me whether the website "looks good."

The goal is to answer:

**If we declared this WordPress website finished today, what exactly have we overlooked?**
