VDL Site Leak Scanner – 404 & Broken Link Checker

Description

VDL Site Leak Scanner is a one-click broken-link and WooCommerce revenue-path checker for WordPress. It checks public sitemap URLs plus configured shop, cart, checkout, and account pages, then groups every result into Urgent, Review, or Informational priority.

For product details and scan help, visit the official VDL Site Leak Scanner page.

Use it before migrations, redesigns, SEO retainers, content cleanups, WooCommerce site reviews, or routine site audits.

What it finds

  • 404 pages (missing URLs)
  • Broken links and dead URLs that need redirects or cleanup
  • Redirect chains (multi-hop redirects)
  • Orphaned URLs (in sitemap but not discoverable through internal links)
  • Timeout and server-error signals returned by the scan service
  • Missing or unreachable configured WooCommerce shop, cart, checkout, and account pages
  • Revenue-critical redirects, timeouts, and server errors on those public paths
  • Informational proof when a configured revenue path is reachable

Why it is different

Many broken-link tools focus only on links found inside posts. VDL Site Leak Scanner compares sitemap URLs with crawl discovery, checks configured WooCommerce revenue paths explicitly, preserves the latest scan receipt for seven days, and creates an evidence report you can hand to a developer, SEO, or store owner.

WooCommerce-aware review signals

When WooCommerce appears active, the service checks the configured public shop, cart, checkout, and account URLs. A failed revenue path is prioritised as Urgent; ordinary broken links and uncertain results remain Review; healthy checks are Informational. These are public diagnostic checks only. They do not inspect orders, customers, payment credentials, Stripe keys, or WordPress passwords, and they do not confirm a payment loss.

What you get

  • One-click first scan with anonymous service setup handled automatically
  • Resumable scan jobs and a durable seven-day result receipt for the current administrator
  • Exact Urgent, Review, and Informational priorities owned by the scan service
  • Suggested next action for each issue
  • CSV export after a completed scan
  • Downloadable, self-contained HTML evidence report with checks, evidence, and suggested next steps
  • Optional single-URL test for quick checks
  • Service-backed scan execution for consistent results

Best first use

Run a scan before migrations, redesigns, SEO audits, WooCommerce launches, or content cleanups. Start with Urgent findings, then Review items. Informational rows are evidence that a check ran; they are not counted as issues.

Optional cleanup help

The plugin is free to install and run. When a WooCommerce revenue-critical finding exists, the results offer one optional paid next step: Payment Rescue. The link opens only when you choose it and passes campaign attribution plus aggregate Urgent/Review counts. It does not put your site URL in the handoff link. Site Leak Scanner does not connect to Stripe or duplicate the separate Woo Revenue Integrity product.

Screenshots

Installation

  1. Install the plugin from the WordPress Plugin Directory, or upload the plugin ZIP.
  2. Activate the plugin.
  3. Open VDL Site Leak Scanner in wp-admin.
  4. Select Scan Site Now. The plugin creates an anonymous service key automatically when needed.
  5. Review Urgent, Review, and Informational results, then download the evidence report or CSV.

FAQ

Does this plugin use external services?

Yes.

VDL Site Leak Scanner connects to the VaultDevLabs API for anonymous service authentication and scan execution.

What data is sent:
* Anonymous service key for status/activation checks.
* Site origin/host in request headers.
* Optional sitemap URL provided in plugin settings.
* Public URLs to check and whether WooCommerce shop, cart, checkout, and account pages are assigned.
* Scan job metadata and returned evidence (URL, status code, final URL, redirect hops, issue code, priority, evidence, and suggested next step).

The service does not receive orders, customer records, payment credentials, Stripe keys, WordPress passwords, or page content. Completed job receipts expire after seven days. The plugin keeps the current administrator’s latest bounded result receipt for the same period. Aggregate scan starts/completions/errors and campaign-tagged handoff visits provide funnel measurement without a separate tracking SDK or raw site URL in the paid handoff.

When it is sent:
* When the first scan requests an anonymous service key, or when you manually save/recover a key in Advanced service settings.
* When you start a scan.
* When the plugin polls scan job status/results.

Why it is sent:
* To authenticate the site with the scan service.
* To execute remote scan processing.
* To return scan results in wp-admin and CSV export.

Service provider:
* API endpoint: https://ai-seo-api-bey2.onrender.com
* Terms of Service: https://vaultdevlabs.com/terms
* Privacy Policy: https://vaultdevlabs.com/privacy

Can this plugin auto-fix issues for me?

No. It is a detection and triage tool. You review issues and apply fixes in your normal workflow.

Does this plugin access my Stripe account?

No. It checks configured public WooCommerce paths. It does not request Stripe API keys, inspect orders, reconcile payments, or access your Stripe account.

Does a revenue-critical signal mean I have a payment problem?

No. Revenue-critical signals are diagnostic findings only. They may justify manual review, especially on WooCommerce stores, but they do not confirm a payment issue or duplicate charge.

What is included in the evidence report?

The self-contained HTML evidence report includes the site and scan timestamps, URL totals, exact priorities, public URL checks, server evidence, and suggested next steps. It also states the data boundary and whether the local receipt had to be truncated to its one-megabyte storage limit.

How do I test locally in LocalWP?

  1. In LocalWP, open your site and go to Site Shell.
  2. Zip the plugin folder so the root is vdl-site-leak-scanner/.
  3. Upload and activate the ZIP in WordPress admin.
  4. Open VDL Site Leak Scanner, optionally set a sitemap URL, and run a scan.

Reviews

మే 4, 2026
Simple, clear and genuinely useful. It found broken URLs, redirect problems and orphan pages quickly, and made it easy to see what needed fixing first. Great little WordPress health-check tool.
మార్చి 1, 2026
I’ve been using VDL Site Leak Scanner and it’s a helpful tool that quickly finds 404 errors, redirect chains and orphaned URLs on my site. The scanner runs fast right in wp-admin and shows clear issue labels with suggestions on what to fix, and you can export results as a CSV. It’s simple to use and a great way to catch site issues you might otherwise miss.
Read all 2 reviews

Contributors & Developers

“VDL Site Leak Scanner – 404 & Broken Link Checker” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.2.0

  • Made the first scan one click by issuing an anonymous service key automatically and moving manual connection settings under Advanced service settings.
  • Added durable, resumable scan jobs with idempotent starts, bounded retries, progress polling, and seven-day server/local receipts.
  • Added explicit WooCommerce shop, cart, checkout, and account configuration and reachability checks without accessing order or payment data.
  • Replaced ambiguous severity labels with service-owned Urgent, Review, and Informational priorities.
  • Added a self-contained downloadable HTML evidence report.
  • Reduced commercial handoffs to one contextual Payment Rescue option and removed the raw site URL from that link.
  • Documented privacy-safe aggregate scan and campaign attribution measurement.

1.1.28

  • Added the canonical plugin product page and official scan-help link.

1.1.27

  • Updated WordPress.org positioning around 404s, broken links, redirect chains, orphan sitemap pages, and WooCommerce checkout-path issues.
  • Renamed the public plugin title to “VDL Site Leak Scanner – 404 & Broken Link Checker” while keeping the existing slug and text domain.
  • Added clearer first-use guidance for migrations, redesigns, SEO audits, WooCommerce checks, and content cleanups.

1.1.26

  • Added safe WordPress security and reliability signals for common headers, XML-RPC reachability, common exposed-file paths, REST API notes, and update counts.
  • Added Site Rescue Review positioning and review-pack context for broader WordPress security/reliability findings.
  • Changed results to show one contextual review panel: Payment Rescue Review for Woo/Stripe revenue-critical signals, Site Rescue Review for broader site/security signals.

1.1.24

  • Updated contextual review handoff links to the dedicated VaultDevLabs Payment Rescue Review page.
  • Passed plugin source context and finding counts into the review handoff while keeping the scanner read-only and diagnostic.

1.1.23

  • Improved wp-admin UI polish with product artwork, dashboard-style scan metrics, clearer status labels, and a stronger empty state.
  • Kept scan logic, external service behavior, and diagnostic claims unchanged.

1.1.22

  • Added WooCommerce-aware revenue-critical URL tagging for checkout, cart, account, order-pay, order-received, and payment-related endpoints.
  • Added passive WooCommerce and WooCommerce Stripe Gateway plugin detection.
  • Added contextual Woo + Stripe diagnostic CTAs only when relevant scan findings and active Woo/Stripe context are present.
  • Added escalation/review pack export with plugin status, scan findings, and a cautious manual-review brief.
  • Tightened diagnostic wording to avoid confirmed payment issue or overclaiming.

1.1.21

  • Added a WP.org-safe human review handoff from scan results to VaultDevLabs.
  • Kept the free scan, CSV export, filters, and actionable results available in the plugin.

1.1.20

  • Repositioned plugin copy around broken links, redirect chains, orphan pages, and audit-style cleanup.
  • Added clearer wp-admin guidance for scan outcomes and optional cleanup reporting.
  • Kept external service disclosure and free scan workflow unchanged.

1.1.19

  • Auto-issues a free service key on first scan when missing, then starts remote scan in the same request.
  • Removed manual service-key status/email action buttons from wp-admin and detached related route wiring.
  • Removed local cap fallback logic; cap messaging now appears only when cap data is returned by the scan service.

1.1.18

  • Restored text domain to vdl-site-leak-scanner to match current slug.
  • Renamed main plugin file to vdl-site-leak-scanner.php.
  • Standardized localized JS globals and prefixed self-test transient key.

1.1.17

  • Updated text-domain usage to match current reserved slug checks.
  • Added prefixed API base constant with backward compatibility alias.
  • Plugin Check compatibility pass for i18n domain mismatch warnings.

1.1.16

  • Added Recover Service Key flow in Connect Service.
  • Added neutral recovery messaging and improved service-key recovery UX.
  • Version and packaging refresh for cache-safe rollout.

1.1.15

  • Added Get Free Service Key flow for self-serve setup.
  • Switched scan workflow to remote service execution path.
  • Removed legacy local gating from plugin UX.

1.1.14

  • Updated Tested up to metadata to WordPress 7.0.

1.1.13

  • Release metadata and packaging consistency updates.
  • GitHub release workflow adjusted for WP.org-ready ZIP output.

1.1.12

  • WordPress.org compliance metadata improvements.

1.1.11

  • Security and sanitization hardening across admin handlers.
  • Plan label display improvements in license summary.
  • External service disclosure clarity for review.

1.1.10

  • Version metadata alignment.
  • External services disclosure added for directory review.
  • Removed background admin-side license prefetch hook.

1.0.4

  • Improved service key verification messaging.

1.0.0

  • Initial release with sitemap scanning, issue detection, and CSV export.