Audit a WordPress site you just inherited with AI
Get a full read-only inventory of the theme, plugins, admin users, custom code, and risks on a site you just took over.
Prerequisites
A connected site. No backup needed, since this recipe only reads and reports.
I just inherited this WordPress site and need to understand what I am working with. Give me a full inventory. Read only, and change nothing. Cover: 1. The WordPress and PHP versions, and the active theme, noting whether it is a child theme or a page-builder theme. 2. Every plugin: name, version, active or inactive, and whether an update is available. 3. Every administrator account: username and email. 4. Custom code touchpoints: must-use plugins, code-snippet plugins, and anything in the theme functions that stands out. 5. A risk list: outdated or abandoned plugins, plugins installed but left inactive, admin accounts that look unexpected, and anything security-relevant. Present it as a clear report I can act on, and do not make any changes. I will decide what to do from your risk list.
Already connected to WPVibe?
Skip the copy-paste. Just ask your AI for the “Audit a WordPress site you just inherited with AI” recipe, or describe the task, and WPVibe runs these steps on your own site.
You just took over a site you did not build. A new client, a new job, a handoff from someone who has already moved on, and no map of what is actually running. Which plugins, which theme, who still has admin access, what custom code is wired in, and what is quietly out of date and risky. Piecing it together by clicking through wp-admin takes an afternoon, and you will still miss the things that do not announce themselves, like a plugin that is installed but inactive or an extra administrator nobody mentioned.
WPVibe produces the whole inventory in one read-only pass. It lists the active theme and whether a child theme is in play, every plugin with its version and whether an update is waiting, every administrator account, and the WordPress and PHP versions the site is on. Then it flags the risks: outdated or abandoned plugins, plugins left installed but inactive, admin accounts that look unexpected, and anything that touches security. It changes nothing. It only reports what is there.
Run the prompt and read the report before you touch anything. It is safe on a live site because nothing is written. Treat the risk list as your first-week punch list: remove the admin accounts you do not recognize, update or retire what is stale, and decide deliberately what stays. You will know the site in ten minutes instead of a week of surprises.
Outcome
A read-only inventory of the theme, plugins, admin accounts, custom code, and security risks, ready to act on.