Policy

Privacy and data use

This page explains what the URL audit tool accesses, what it stores, and what it does not do with your data.

What the tool accesses

The tool requests page data from the public WordPress REST API for the site URL you enter. It reads page titles, slugs, URLs, and related metadata needed to build the audit table.

All requests originate from your browser and are transmitted directly to the WordPress site. No data is routed through Web Cheddar servers. The tool operates entirely client-side.

What the tool stores

The current version stores only local display preferences such as theme choice in your browser's localStorage. It does not create user accounts or maintain a server-side page audit history.

Session data (like your current audit results) is stored only in your browser's memory and is cleared when you close the page or browser tab. No sensitive information is persisted.

What the tool does not do

It does not log in to WordPress, modify pages, publish content, or attempt to bypass protected environments. It is intended for authorized diagnostic use only.

The tool cannot and does not: steal credentials, inject code, execute administrative functions, modify database records, or access non-public data. It reads only what the WordPress REST API exposes for published pages.

API access and permissions

The tool can only audit sites where the WordPress REST API is publicly available. Some sites restrict API access for security reasons, in which case the audit will fail gracefully with a clear error message.

If your site requires authentication or access permissions, you will need to configure those settings in WordPress before using this tool. Web Cheddar does not bypass any security restrictions.

Advertising and analytics

This site uses Google AdSense for advertising and Google Analytics for measurement. Visitors may receive personalized or contextual ad delivery and anonymized usage tracking according to Google's policies and your local consent requirements.

Google Analytics collects information about how you use this tool, including which pages you visit, how long you stay, and which actions you take (like exporting data or filtering results). This data is used to improve the tool and understand user behavior.

Your responsibilities

You agree to use this tool only on WordPress sites you own or have explicit permission to audit. Unauthorized site scanning, enumeration, or access attempts are prohibited and may violate applicable laws.

If you discover vulnerabilities in this tool or the WordPress sites you audit, please report them responsibly to the site owner or to Web Cheddar.

Data retention

Google Analytics retains aggregated, anonymized usage data according to its standard policies (typically 26 months). Your browser-local theme and preferences are retained indefinitely until cleared.

Web Cheddar does not retain or log audit results, IP addresses, or WordPress site URLs after your session ends.

Third-party services

This tool relies on:

  • Google Analytics 4: Usage tracking and anonymized analytics
  • Google AdSense: Ad serving and revenue (when approved)
  • WordPress REST API: Read-only access to published page data

Please review Google's privacy policies for details on how they process your data.

Questions or concerns?

If you have privacy questions or concerns about how this tool handles data, contact Web Cheddar directly.