New 24/7 monitoring and daily cloud backups now included in every Shield Pro plan.

Free tool · Online stores

WooCommerce Health Checker

The WooCommerce health checker reviews the public side of your store for visible WooCommerce clues, secure access and page responses. Start with your store address to identify the next checks to make inside WordPress.

Free WooCommerce health check

Enter your shop or product page URL and we will check for WooCommerce signals, HTTPS and insecure page resources.

Free to use without an account. View the result here and choose whether to receive it by email.

What the tool covers

Review public store access

Public WooCommerce clues, HTTPS and insecure script or stylesheet references in the submitted page.

Visible WooCommerce clues

The page is checked for public WooCommerce markup and asset references. A store that hides these clues cannot be confirmed from that page alone.

A secure connection

The inspected response is checked for HTTPS, the secure connection visitors need when using a store. This does not test payment processing.

Insecure active resources

Script and stylesheet references using HTTP are flagged for review. The checker reads the page source rather than executing those resources in a browser.

Transactional limits

The report keeps order and payment health unverified because stock, shipping, checkout and email delivery need authenticated or controlled transaction tests.

Understand the limits

The tool does not place an order, test a payment gateway or confirm stock, tax, shipping or order emails. Hidden store software remains unverified.

Understanding your result

Connect public store findings with a real shopping test

The scan gives you a first look at the submitted page. Follow it with a controlled review of the journey customers use, particularly after changing plugins, hosting or checkout settings.

Recognised WooCommerce is a software clue

It establishes that the public page contains recognised WooCommerce signals. It does not confirm that every store setting is correct or that an order can complete.

Insecure references need their source corrected

Find where the HTTP address is generated, such as page content, theme settings or a plugin. Confirm the resource works over HTTPS, update it at the source and inspect the page again after clearing relevant caches.

Payment and order checks stay separate

Use a staging store and your payment provider's test mode to check basket totals, shipping, tax and confirmation. Verify the resulting order and emails rather than treating a successful page response as proof.

Begin with the customer-facing store

A store needs accessible pages and secure connections before customers can buy. This checker reads public responses and WooCommerce signals without adding products to a basket or submitting an order. A page response is evidence of access, not a complete shopping test.

Review insecure resources on secure pages

An HTTPS store page can still reference a script or stylesheet through an insecure HTTP address. The report flags whether it found those references without listing their addresses. Inspect the page source or ask a developer to review the browser console, then correct the setting or content that generates the HTTP address. Browser behaviour and redirects affect whether a resource loads, so verify the corrected page in a private browser window.

Finish with a controlled checkout test

Use your payment provider's test mode on staging to check product selection, basket totals, shipping, tax and order confirmation. Confirm that the order appears in WooCommerce and that expected emails arrive. Review the WooCommerce status report and logs when a step fails.

Questions about this tool

Does the WooCommerce health checker make a purchase?

No. It reads public pages and signals. It does not add products, submit checkout forms, charge a card or create an order.

Can it prove my payment gateway works?

No. Payment testing requires a controlled checkout journey and the appropriate test credentials. Use your provider's test mode on a staging store.

What does an insecure resource finding mean?

The checked page references an HTTP script or stylesheet. Review the source of that address and test an HTTPS replacement. The checker does not execute the page in a browser.

Does this replace the WooCommerce status report?

No. The status report inside WordPress has access to settings and server information that a public scanner cannot read.

Can I email the store health findings?

Yes. Start the check and use the optional email form to receive the result for your own records or a developer's review.

Free website widget

Add this tool to your website

Let visitors use the WooCommerce Health Checker on your own page, including the option to email their results. Copy the code into an Elementor HTML widget or a WordPress Custom HTML block, then preview the published page.

Get the embed code
Preview the widget

The widget fits the width of its container. Increase the height value if you want more of the report visible at once; longer results can be scrolled inside the widget.

BugShield hosts and runs the tool. Results and email addresses stay inside the widget and are not shared with the page embedding it. If your editor removes the code or your site blocks external widgets, ask your website administrator to allow frames from bugshield.co.uk.

Need help with the next step?

A BugShield developer can review the findings and help you decide what your WordPress site needs.

Explore WordPress support