Template · 30-minute audit

Find the gaps before
a client — or an incident — finds them for you.

Eight categories, one score per site. A structured way to find outages, security exposure, lost margin and client surprises hiding across a WordPress portfolio.

Last reviewed 17 August 2026 by the Stack2 team — we run our own agency hosting operation the same way.

What an unaudited portfolio actually costs

The gaps that cause outages are rarely the ones you're watching.

A site nobody's looked at in months is where the outdated plugin, the ex-employee's still-active login, and the backup that quietly stopped running all live. An audit surfaces them on your terms, not the client's.

The eight audit categories

Run each site through these eight checks.

Category What to check
Ownership Client, internal owner, service tier, renewal date and commercial scope.
Infrastructure Host, domain/DNS owner, SSL, PHP version and production/staging status.
Access Admin ownership, MFA, shared credentials, former-team access and recovery path.
Maintenance Core/plugin/theme status, update policy, exclusions and rollback capability.
Protection Backup recency, off-site status, retention, restore test and uptime monitoring.
Risk Known vulnerabilities, unsupported plugins, compatibility concerns and unresolved errors.
Reporting Last client report, evidence delivered, recommendations and next review date.
Economics Price, monthly delivery time, software allocation and gross margin estimate.

The scoring model

Score each category red, amber or green per site:

  • Red — a genuine gap: no backup retention, shared credentials, an unsupported plugin still active.
  • Amber — partially in place: backups exist but untested, access is documented but not reviewed recently.
  • Green — fully in place and confirmed, not assumed.

Roll the eight category scores into one overall Control score per site — the number of green categories out of eight is enough for most agencies; weight categories by risk if you want more nuance. Sort your portfolio by Control score and you have an instant priority list.

The Control score is an operational prioritisation aid, not a security certification, penetration test, or legal/compliance advice.
Free toolkit

Get the editable audit spreadsheet

This audit as an editable spreadsheet — prebuilt fields, RAG score formulas and an example site — plus the pricing calculator and maintenance SOP.

  • Portfolio Audit Sheet (XLSX) — RAG scoring, priority view and an example row
  • Care Plan Profit Calculator (XLSX) — inputs, formulas and a worked example
  • Agency Maintenance SOP (DOCX) — daily/weekly/monthly/quarterly tasks with owners and escalation fields

Free, no obligation. Delivered immediately — no call required.

Instant access. Practical agency templates. Unsubscribe anytime.

From snapshot to live inventory

An audit is a snapshot. Inventory is a live view.

Once you've run the audit, connect your sites in Stack2 so ownership, access, maintenance and monitoring status stay current automatically — instead of going stale the moment the spreadsheet is saved.

14 days free. No credit card required.

FAQ

Common questions

Is the Control score a security certification?
No. It's an operational prioritisation aid — a way to see which sites need attention first, based on the categories in this audit. It isn't a penetration test, a compliance certification, or legal or security advice.
How long does the audit actually take?
About 30 minutes per site the first time, faster once you're familiar with the categories. Most of that time goes into confirming access and backup status — the categories that are hardest to answer from memory.
What counts as a red flag in the access category?
Shared logins with no individual accountability, no multi-factor authentication on an admin account, and access still active for a former team member or former agency. Any one of these is enough to mark the category red.
Should I audit every site the same way regardless of size?
Use the same eight categories for every site, but weight urgency by what's actually at risk — a low-traffic brochure site failing on Protection matters less than an e-commerce site failing the same category. The scoring model flags the gap either way; your judgement decides what to fix first.