Description
Generate a client ready WordPress plugin risk report in 60 seconds.
Risk Review helps WordPress site owners, freelancers, and agencies spot plugin maintenance risks before they become client emergencies.
Instead of manually checking every plugin, Risk Review turns common maintenance signals into a clear score, grade, executive summary, recommended action plan, grouped issue sections, CSV export, print friendly report, and safe standalone HTML report.
It is built for practical site maintenance, client reporting, and faster decision making.
Risk Review checks for things like:
- Available plugin updates
- Plugins not marked as tested with your current WordPress version
- Plugins that require newer versions of WordPress or PHP
- Plugins that look stale or potentially abandoned
- Inactive plugins still installed on the site
- Multiple active plugins in categories that commonly overlap, such as cache, SEO, security, analytics, and backup
- Autoloaded options size and basic environment signals
Features include:
- Client ready Risk Report screen with score, grade, executive summary, grouped issues, and recommended actions
- Recommended action plan to help you decide what to review first
- Agency and client report settings for agency name, prepared by, client or site label, and optional footer note
- Print friendly report layout
- Safe standalone HTML report download
- Plugin risk table with scores and grades
- CSV export
- Optional weekly email summary with selectable day and time
- Manual Send now and Send test email actions
Risk Review is a read only admin tool. It does not activate, deactivate, update, delete, or modify plugins. It helps you review the state of a WordPress site more quickly and make better maintenance decisions.
All checks run inside your WordPress admin. No telemetry or tracking is included. Public plugin metadata may be retrieved from WordPress.org using core WordPress APIs. Optional weekly, manual, and test emails are sent by your own WordPress site using its configured mail system.
Captures d’écrans

Client ready Risk Report with overall score, grade, executive summary, recommended action plan, and site details. 
Grouped update issues show affected plugins, severity labels, why each item matters, and recommended actions. 
Inactive plugin checks help identify low priority cleanup items and plugins that may no longer be needed. 
Healthy and environment signals show checks that passed, including compatibility and autoloaded options status. 
Dashboard overview with overall risk score, recommended next step, maintenance snapshot, and plugins needing attention. 
Weekly email settings, CSV export, and plugin risk table with status badges, update status, signals, scores, and grades.
Installation
- Upload the
nuwavelabs-risk-reviewfolder to/wp-content/plugins/ - Activate the plugin through the Plugins menu in WordPress
- Open NuwaveLabs Risk Review from the WordPress admin menu
- Open Risk Report to review or print a client-ready report
- Optional: enable weekly email reports and choose the schedule
FAQ
-
Does this plugin send data to external services?
-
NuwaveLabs Risk Review runs on your site. Public plugin metadata may be retrieved from WordPress.org using official WordPress core APIs. If enabled or triggered, weekly summaries and manual/test emails are sent by your WordPress site using wp_mail() to the configured recipient or site administrator. The plugin does not send report data to NuwaveLabs.
-
What happened to the Pro waitlist?
-
The Pro waitlist form is not included in this release. Earlier versions may have stored waitlist emails locally in the WordPress database; uninstall.php removes stored plugin options, including any legacy waitlist data.
-
Where are report settings stored?
-
Agency name, prepared by, client/site label, and report footer note are stored locally in your WordPress database. They are removed by uninstall.php when the plugin is uninstalled.
-
Does this plugin update or change other plugins?
-
No. NuwaveLabs Risk Review is read only. It does not update, activate, deactivate, or edit any plugins.
-
Why do I see « Not tested with current WordPress »?
-
This means the plugin author has not marked the plugin as tested with your current WordPress version. It does not automatically mean the plugin is broken, but it is something worth checking.
-
Is this plugin safe to use on multisite?
-
Yes. NuwaveLabs Risk Review respects multisite context and works inside the WordPress admin area.
Avis
Il n’y a aucun avis pour cette extension.
Contributeurs/contributrices & développeurs/développeuses
« NuwaveLabs Risk Review » est un logiciel libre. Les personnes suivantes ont contribué à cette extension.
ContributeursTraduisez « NuwaveLabs Risk Review » dans votre langue.
Le développement vous intéresse ?
Parcourir le code, consulter le SVN dépôt, ou s’inscrire au journal de développement par RSS.
Journal des modifications
0.13.0
- Added a client-ready Risk Report screen with overall score, grade, executive summary, site details, issue groups, and recommended actions.
- Added a Recommended Action Plan to help users understand what to review first.
- Improved the main dashboard with clearer score cards, maintenance snapshot, and report access.
- Added report settings for agency/client details.
- Added print-friendly and HTML report export options.
- Improved CSV export safety.
- Improved email validation and weekly/manual email handling.
- Improved Plugin Check compatibility with translator comments and line-ending cleanup.
- Updated Pro page to a simple roadmap without email capture.
- Updated readme accuracy and privacy/external service disclosure.
0.10.6
- Renamed plugin to NuwaveLabs Risk Review
- Updated text domain to nuwavelabs-risk-review
- Updated plugin naming for resubmission
0.10.5
- Removed updater code
- Fixed escaping and nonce handling issues raised during review
- Improved review compliance
- Tested on a clean install with WP_DEBUG enabled
- Passed Plugin Check for the resubmission build
0.10.4
- Admin UI markup corrections
- Output escaping and sanitization improvements
- Review compliance adjustments
- Documentation and version alignment
0.10.3
- Addressed WordPress.org review feedback
- Proper admin enqueue for CSS and JavaScript
- Improved sanitization, validation, and output escaping
- Removed WordPress.org directory assets from plugin ZIP
- Updated compatibility and documentation
0.10.1
- Initial public release
- Plugin risk table with scoring and signals
- CSV export
- Weekly email reports
- Conflict detection and autoloaded options size insight
