{"id":327252,"date":"2026-07-06T20:24:10","date_gmt":"2026-07-06T20:24:10","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/website-scorecard\/"},"modified":"2026-08-02T21:28:03","modified_gmt":"2026-08-02T21:28:03","slug":"trustbeacon-auditor","status":"publish","type":"plugin","link":"https:\/\/sq.wordpress.org\/plugins\/trustbeacon-auditor\/","author":23516211,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.10","stable_tag":"0.1.10","tested":"7.0.2","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"TrustBeacon Email Delivery Auditor","header_author":"Jason Michael Canon","header_description":"Audits basic public trust signals including DNS, SSL, security headers, SPF, DMARC, DKIM, CAA, DNSSEC, CDN indicators, and visible WordPress security plugin signals.","assets_banners_color":"","last_updated":"2026-08-02 21:28:03","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/itechguide.com\/trustbeacon-auditor\/","header_author_uri":"https:\/\/itechguide.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":207,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.10":{"tag":"0.1.10","author":"fiatlux5775","date":"2026-08-02 21:28:03"},"0.1.7":{"tag":"0.1.7","author":"fiatlux5775","date":"2026-07-06 20:23:36"},"0.1.8":{"tag":"0.1.8","author":"fiatlux5775","date":"2026-07-22 18:40:46"},"0.1.9":{"tag":"0.1.9","author":"fiatlux5775","date":"2026-08-02 20:09:19"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-256x256.jpg":{"filename":"icon-256x256.jpg","revision":3598298,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.10","0.1.7","0.1.8","0.1.9"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3621765,"resolution":"1","location":"assets","locale":"","width":3700,"height":2122},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3621765,"resolution":"2","location":"assets","locale":"","width":3698,"height":1006}},"screenshots":{"1":"Admin audit dashboard with trust score gauge, category cards, and grouped findings.","2":"Pre-audit introductory panel shown before the first audit is run."}},"plugin_section":[],"plugin_tags":[6930,145801,267,48589,145798],"plugin_category":[54],"plugin_contributors":[270394],"plugin_business_model":[],"class_list":["post-327252","plugin","type-plugin","status-publish","hentry","plugin_tags-dkim","plugin_tags-dmarc","plugin_tags-email","plugin_tags-email-delivery","plugin_tags-spf","plugin_category-security-and-spam-protection","plugin_contributors-fiatlux5775","plugin_committers-fiatlux5775"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/trustbeacon-auditor\/assets\/icon-256x256.jpg?rev=3598298","icon_2x":"https:\/\/ps.w.org\/trustbeacon-auditor\/assets\/icon-256x256.jpg?rev=3598298","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/trustbeacon-auditor\/assets\/screenshot-1.png?rev=3621765","caption":"Admin audit dashboard with trust score gauge, category cards, and grouped findings."},{"src":"https:\/\/ps.w.org\/trustbeacon-auditor\/assets\/screenshot-2.png?rev=3621765","caption":"Pre-audit introductory panel shown before the first audit is run."}],"raw_content":"<!--section=description-->\n<p>TrustBeacon Email Delivery Auditor identifies publicly visible DNS, email-authentication, and domain-configuration problems that can interfere with WordPress email transmission and delivery.<\/p>\n\n<p>If WordPress messages are failing, being rejected, or landing in spam, TrustBeacon provides a single plain-English audit of the public configuration affecting your domain and email. Every finding includes an explanation, a recommendation, and the potential business impact.<\/p>\n\n<p>The plugin checks email-delivery and domain-trust signals such as:<\/p>\n\n<h4>Email transmission and receipt<\/h4>\n\n<ul>\n<li>MX records<\/li>\n<li>Public mail-domain configuration<\/li>\n<\/ul>\n\n<h4>Email authentication and deliverability<\/h4>\n\n<ul>\n<li>SPF records and enforcement strength<\/li>\n<li>Common DKIM selectors<\/li>\n<li>DMARC policies and enforcement strength<\/li>\n<\/ul>\n\n<h4>Supporting domain and website trust<\/h4>\n\n<ul>\n<li>SSL certificate availability<\/li>\n<li>HTTP security headers<\/li>\n<li>CAA records<\/li>\n<li>DNSSEC indicators when supported by the server<\/li>\n<li>Cloudflare indicators in public response headers<\/li>\n<li>Public security plugin indicators visible in page HTML<\/li>\n<\/ul>\n\n<p>The report includes:<\/p>\n\n<ul>\n<li>An overall Trust Score<\/li>\n<li>Separate category ratings<\/li>\n<li>Passing, warning, failing, and informational findings<\/li>\n<li>Plain-English explanations<\/li>\n<li>Recommended corrective actions<\/li>\n<li>Business-impact explanations<\/li>\n<\/ul>\n\n<p>TrustBeacon is read-only. It reports findings and recommendations but does not automatically change DNS records, email settings, or website configuration.<\/p>\n\n<p>Important: TrustBeacon evaluates publicly visible configuration and trust indicators. It does not send a test email, inspect private mail-server settings, guarantee inbox placement, or provide a security certification, penetration test, malware scan, or compliance audit.<\/p>\n\n<h3>Admin Dashboard<\/h3>\n\n<p>The Trust Auditor admin page presents results as a dashboard rather than a single wide table:<\/p>\n\n<ul>\n<li>An overall Trust Score is shown as a circular gauge alongside the trust grade and counts of passing, warning, failing, and informational findings, all derived directly from the current audit's findings.<\/li>\n<li>Email Authentication, Website Security, Visitor Protection, and DNS Security are shown as separate summary cards using the plugin's existing category ratings (Excellent, Good, Fair, Needs Attention, or Additional Review Recommended).<\/li>\n<li>Findings are grouped by category. Each finding keeps its category, check, status, score, message, recommendation, and business impact; recommendation and business impact are available in an expandable \"Recommendation and business impact\" section.<\/li>\n<li>Status is always shown as visible text (PASS, WARN, FAIL, INFO) in addition to color, and a small status dot is decorative only.<\/li>\n<li>Before an audit has been run, an introductory panel explains what will be checked. It does not display a score or findings, so nothing can be mistaken for real results.<\/li>\n<li>The dashboard styling loads only on the Trust Auditor admin page and does not affect the rest of the WordPress admin area.<\/li>\n<li>The dashboard works without JavaScript. Recommendation and business impact sections use the browser's native expand\/collapse control.<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>TrustBeacon Auditor performs remote HTTPS requests to websites selected\nby the site administrator in order to audit publicly available trust\nsignals.<\/p>\n\n<p>The plugin connects directly to the website being audited to inspect\ninformation such as:<\/p>\n\n<ul>\n<li>SSL certificate availability<\/li>\n<li>HTTP response headers<\/li>\n<li>Cloudflare detection<\/li>\n<li>Security plugin indicators<\/li>\n<\/ul>\n\n<p>Data transmitted:<\/p>\n\n<ul>\n<li>The domain name entered by the administrator.<\/li>\n<li>Standard HTTP request headers, including a User-Agent string.<\/li>\n<\/ul>\n\n<p>These requests occur only when an administrator initiates an audit.<\/p>\n\n<p>No personal visitor information is collected, stored, or transmitted.<\/p>\n\n<p>The plugin does not use any third-party commercial APIs.<\/p>\n\n<p>Privacy Policy:\nhttps:\/\/itechguide.com\/privacy-policy\/<\/p>\n\n<p>Terms of Use:\nhttps:\/\/itechguide.com\/terms-of-use\/<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to the <code>\/wp-content\/plugins\/<\/code> directory, or install the plugin ZIP through the WordPress Plugins screen.<\/li>\n<li>Activate the plugin through the Plugins screen.<\/li>\n<li>Open the Trust Auditor page in the WordPress admin menu.<\/li>\n<li>Click Run Audit.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20trustbeacon%20send%20a%20test%20email%3F\"><h3>Does TrustBeacon send a test email?<\/h3><\/dt>\n<dd><p>No. TrustBeacon examines publicly visible DNS, email-authentication, and domain-trust configuration. It does not send a message through the WordPress mail system or guarantee delivery to a particular recipient.<\/p><\/dd>\n<dt id=\"can%20trustbeacon%20explain%20what%20needs%20attention%3F\"><h3>Can TrustBeacon explain what needs attention?<\/h3><\/dt>\n<dd><p>Yes. Every finding includes a plain-English message, a recommended action, and an explanation of the potential business impact.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20scan%20private%20files%20or%20private%20server%20data%3F\"><h3>Does this plugin scan private files or private server data?<\/h3><\/dt>\n<dd><p>No. It checks public trust indicators for the installed site.<\/p><\/dd>\n<dt id=\"does%20a%20high%20score%20prove%20my%20site%20is%20secure%3F\"><h3>Does a high score prove my site is secure?<\/h3><\/dt>\n<dd><p>No. A high score means the checked public trust signals look good. It does not prove that the site is secure.<\/p><\/dd>\n<dt id=\"does%20a%20low%20score%20prove%20my%20site%20was%20hacked%3F\"><h3>Does a low score prove my site was hacked?<\/h3><\/dt>\n<dd><p>No. A low score means that one or more public trust signals may be missing, weak, or unavailable.<\/p><\/dd>\n<dt id=\"why%20does%20dkim%20detection%20say%20no%20common%20selector%20was%20found%3F\"><h3>Why does DKIM detection say no common selector was found?<\/h3><\/dt>\n<dd><p>DKIM selectors vary by mail provider. The plugin checks several common selectors, but some providers use custom selector names.<\/p><\/dd>\n<dt id=\"why%20is%20dnssec%20sometimes%20informational%3F\"><h3>Why is DNSSEC sometimes informational?<\/h3><\/dt>\n<dd><p>Some PHP environments cannot query DNSSEC records reliably. In that case, the plugin avoids punishing the score for a check it cannot verify.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.10<\/h4>\n\n<ul>\n<li>Fixed the dashboard version display by synchronizing the internal version constant with the plugin release.<\/li>\n<li>Updated the WordPress admin page title, menu label, dashboard heading, explanatory text, and limitation notice to reflect the email-delivery focus.<\/li>\n<li>The displayed plugin version is supplied through the shared version constant rather than a separate dashboard value.<\/li>\n<li>No changes to audit checks, scoring, category ratings, or stored data.<\/li>\n<\/ul>\n\n<h4>0.1.9<\/h4>\n\n<ul>\n<li>Repositioned the plugin around its primary benefit: identifying public configuration problems that can affect WordPress email transmission and delivery.<\/li>\n<li>Improved the title, short description, tags, feature organization, and directory description.<\/li>\n<li>Clarified that every finding includes a recommendation and business-impact explanation.<\/li>\n<li>Clarified the distinction between public configuration auditing and sending an actual test email.<\/li>\n<li>No changes to audit checks, scoring, category ratings, or stored data.<\/li>\n<\/ul>\n\n<h4>0.1.8<\/h4>\n\n<ul>\n<li>Redesigned the admin results page as a dashboard: a circular Trust Score gauge, finding-status counts, category summary cards, and findings grouped by category with expandable recommendation\/business impact detail.<\/li>\n<li>Added a dedicated pre-audit introductory panel explaining what the audit checks, shown before any audit has been run.<\/li>\n<li>Added a scoped admin stylesheet that loads only on the Trust Auditor admin page.<\/li>\n<li>No changes to audit checks, scoring, or category-rating calculations. This is a presentation-only update.<\/li>\n<\/ul>\n\n<h4>0.1.3<\/h4>\n\n<ul>\n<li>Revised scoring so INFO findings are excluded and WARN findings receive partial credit instead of harsh zero-point treatment.<\/li>\n<li>Adjusted grade labels to better reflect public trust signals rather than full security certification.<\/li>\n<\/ul>\n\n<h4>0.1.1<\/h4>\n\n<ul>\n<li>Standardized plugin name, slug, text domain, prefix, contributor metadata, licensing, and WordPress.org readme format.<\/li>\n<li>Replaced mixed class prefixes with TBAUD-prefixed classes.<\/li>\n<li>Replaced raw HTTP header fetching with the WordPress HTTP API.<\/li>\n<li>Added safer DNS lookup wrapper and defensive handling for unavailable DNS constants.<\/li>\n<li>Added escaping, sanitization, nonce name, capability checks, and translatable admin strings.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial development version.<\/li>\n<\/ul>","raw_excerpt":"Find public DNS and authentication problems that can affect WordPress email delivery, including MX, SPF, DKIM, and DMARC.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/sq.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/327252","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sq.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/sq.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/sq.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=327252"}],"author":[{"embeddable":true,"href":"https:\/\/sq.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/fiatlux5775"}],"wp:attachment":[{"href":"https:\/\/sq.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=327252"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/sq.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=327252"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/sq.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=327252"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/sq.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=327252"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/sq.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=327252"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/sq.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=327252"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}