What it does
Every site gets one honest number from 0 to 100. 100 means nothing needs attention; the score falls as real problems stack up, each with a capped deduction so no single factor can bury the rest. Click the score on a site's header to open the health score breakdown drawer and see exactly where the points went.
How to
Read the breakdown top to bottom — the first entries are usually what's "dragging the score down". More than two negative factors show a +N more pill that opens the same drawer instead of hiding them.
Limits & defaults
| Factor | Deduction |
|---|---|
| WordPress core update available | −10 |
| Each plugin update available | −3 each, capped at −24 |
| Each theme update available | −2 each, capped at −8 |
| No backup has ever completed | −15 |
| Last completed backup older than 7 days | −10 |
| No offsite backup destination configured | −10 |
| Each open uptime incident | −15 each, capped at −30 |
| PHP below 8.1 (the supported minimum) | −10 |
| PHP below 7.4 (end of life) | −20 |
| Open critical/high vulnerability | −10 each |
| Open medium/low/unknown vulnerability | −4 each — vulnerabilities capped at −25 total |
| Each failed hardening check | −3 each, capped at −12 |
Bands: Excellent 90–100 · Good 75–89 · Needs attention 50–74 · Critical 0–49. The Sites list's "needs attention" stat counts Needs attention + Critical.