Xpulse is a free, read-only health check for WordPress sites. It looks at your site’s server, security, speed, and database, and turns what it finds into a simple report. It was built by Xponent, the team behind Xcore managed hosting.
Installing it takes about 5 minutes. This guide covers what Xpulse checks, what it never does, and how to remove it if you change your mind.
What Xpulse checks #
Xpulse looks at the things that make WordPress sites slow, fragile, or vulnerable:
- PHP version and settings (outdated PHP is the most common problem we see)
- Security headers and basic hardening
- Database size and bloat
- Backups and large files
- Crashes and stuck background jobs
- Outdated plugins
- Site speed factors such as caching and image compression
None of these checks change anything on your site. They only read.
What Xpulse does not do #
- It does not change or repair anything automatically. It reports. You decide. (The one exception is the crash catcher, below.)
- It does not send your data anywhere. Nothing leaves your site until you click “Share my results” or “Request this migration” on the report. Only you can click those buttons.
- It does not track your visitors. No cookies, no ads, no analytics.
- It does not slow your site down. The checks run in the background and results are cached.
- It is not malware. It is a standard WordPress plugin from a South African agency, installed and removed like any other plugin.
The crash catcher #
Xpulse includes a safety net. If a plugin on your site crashes and takes the site down (the “white screen of death”), Xpulse catches it, logs it, and deactivates the broken plugin so your site comes back up. It only acts on an actual crash, and only for logged-in administrators. You can disable it in Xpulse Settings.
How to install #
- Download the Xpulse plugin (from the link you received, or the Xpulse page).
- In WordPress: Plugins → Add New → Upload Plugin, choose the zip file, Install, then Activate.
- Open the Xpulse menu in your admin sidebar. The dashboard widget shows the first health snapshot; click Refresh for live data.
That’s it. Your report is ready to generate.
How to remove it #
Deactivate Xpulse in Plugins, then delete it. Xpulse removes all of its settings, logs, and the crash catcher when deleted. Nothing is left behind.
Your data stays yours #
Xpulse stores everything it finds on your own site, in your own database. The only time anything leaves your site is when you explicitly choose to share it: “Share my results” or “Request this migration” sends your site’s report to the Xponent team so we can prepare a migration quote. Nothing is ever sent automatically.