| 开发者 | ozandikici |
|---|---|
| 更新时间 | 2026年9月27日 16:34 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
/.well-known/sitelemetry-verification.txt on this host with that code and nothing else, tests the file and asks Sitelemetry to check it; the page then says "Verification complete ✓ valid until" and the date, or which problem to fix. A verification lasts 30 days; the plugin renews it automatically in the background (WP-Cron) when it expires or when an audit reports that it must be renewed, never earlier, and shows a notice only if the renewal fails. Remove token stops publishing the file and the automatic renewal until you click Verify this site again or save a token. Where one-click verification is not available yet, the manual steps remain: in the Sitelemetry app open Verified Domains, enter the host and click Start verification, copy the verification code (the token) shown under HTTP verification file, paste it into Verify this site, click Test the file, then click Verify HTTP in the app (renew with Reverify in the app). Without a token the path answers 404. A DNS TXT record or Google Search Console work as alternatives. On a multisite network the web server behind a site's host serves the whole network, so only a network administrator can publish the file there.
Thin client
The plugin bundles no libraries and runs no scanner on your server. It sends requests to sitelemetry.com with the WordPress HTTP API and renders the response. There is no tracking and no analytics.
External service
This plugin relies on the hosted Sitelemetry service (https://sitelemetry.com) operated by Sitelemetry. It sends requests to the service only when you run an audit or after you have stored an API key, as described in the Privacy section below. The terms of service are published at https://sitelemetry.com/terms and the privacy policy at https://sitelemetry.com/privacy.
sitelemetry-audit folder to /wp-content/plugins/ or install it from the Plugins screen.No. Sitelemetry audits the live target from its own infrastructure. The plugin only starts the audit, polls its progress and shows the result.
A completed audit uses one unit of the monthly allowance of the connected Sitelemetry account. Polling a running audit uses nothing more. Audits that are not started (plan not included, allowance exhausted, verification required) use nothing.
Only to sitelemetry.com, and only after you store an API key: the target URL, the audit kind and the report language (from your WordPress admin language), authenticated with your API key, plus the plugin's User-Agent. For ownership verification the plugin sends this site's address (scheme and host). No site content, users, visitors, plugin list or WordPress version are sent. "Test the file" requests this site's own verification file from your server and contacts no other host. The Privacy section below lists every request.
Some checks need ownership verification of the target or a plan that includes them, or a measurement was unavailable for the target. The results page lists each of them under "What was not measured", with the likely cause when the site's own answers explain it. Use Verify this site in the plugin settings, a DNS record or Google Search Console to include the protected checks.
Sitelemetry proves that you control a host by fetching https://<host>/.well-known/sitelemetry-verification.txt and comparing it with a token it generated for your account. With one click the plugin requests that token with your API key, serves the file for this site's own host (only for exactly this host and path) and asks Sitelemetry to check it, so no FTP upload is needed; it renews the verification in WP-Cron when it expires and never replaces a verification that is still valid. When a check fails, the page names the cause and the fix: a web server that keeps /.well-known/ for itself, a firewall or password, a redirect between www and non-www, a cached or other file at that path, no answer in time, DNS or TLS problems, too many attempts or a key Sitelemetry did not accept. Where one-click verification is not available yet, paste the token from the app; "Test the file" fetches the file the way Sitelemetry will and reports redirects to another host, 404 answers from the web server, firewall or maintenance pages and wrong content. Local and private sites cannot be verified this way, and subdirectory installs usually cannot; use the DNS record instead. Sitelemetry fetches the default port of the host (443 or 80), so a site that runs on another port must also answer there. On a multisite network only a network administrator (the manage_network_options capability, filterable with sitelemetry_audit_verification_capability) can publish the file, because the server behind the host is shared by the whole network.
No. The prompt is built by WordPress from the stored result and the button only copies it to your clipboard. It contains the audited address and the findings, never your API key. You decide where to paste it.
The results page in WordPress is the result: Sitelemetry does not keep a separate report of audits run through the plugin. Run the audit again to refresh it.
The screens are translated into Turkish, Spanish, German (informal and formal), French, Portuguese (Brazil), Italian, Japanese and Simplified Chinese, and audit results arrive in your admin language when Sitelemetry supports it. The bundled translations work from WordPress 6.0; a language pack from translate.wordpress.org replaces them completely, so strings a pack does not translate yet appear in English. You can improve or add translations at translate.wordpress.org.
Long audits return a job id. While the results page is open, the browser asks WordPress every few seconds (as Sitelemetry suggests) for one progress step; each step is one request from your server to Sitelemetry with the job arguments unchanged. If you leave the page, a WP-Cron event finishes the job in the background. A total time budget of 20 minutes applies; when a job exceeds it, run the audit again later to get a result.
In the WordPress options table, like other plugin settings. The settings page shows it masked, it is never written to logs and it is sent only to sitelemetry.com as a Bearer token.
The target defaults to this site's address and can be changed to any URL you own or are authorized to test. Do not audit sites you are not authorized to test. The verification helper publishes the file only for this site's own host; verify other hosts in the Sitelemetry app.
WP-Cron runs when the site receives visits. If your host runs a system cron for WordPress (recommended), the weekly audit runs on time regardless of traffic.