Theme Check Scanner
Opens a theme .zip in your browser and runs the checks the directory runs: required files and headers, forbidden functions, plugin territory, missing hooks.
This tool needs JavaScript: the zip is opened and read in your browser, and nothing is uploaded.
Reading the archive…
No theme yet. This runs the kind of checks the theme directory runs, before you submit anything to it.
The checks the WordPress theme directory runs, on a theme that has not been uploaded anywhere. Drop in the zip and read the list.
Theme Check is normally a plugin: install WordPress, install the theme, install the checker, read the output. This does the same kind of reading on the files in the archive, in your browser, which means it works before the theme is near a site and without handing an unreleased theme to anybody.
How to use
Choose the zip, or drop it on the box. Nothing is uploaded: the archive is opened and decompressed in this tab, and closing the page discards it.
Example
acme-starter · 13 files · 18.4 KB
0 required · 1 worth fixing · 0 worth knowing
WORTH FIXING
No screenshot
the themes screen shows a grey box, and the directory wants 1200 by 900
A theme with real problems reads like this:
REQUIRED
eval() in functions.php
running arbitrary code, which is an automatic rejection and usually means something got in
REQUIRED
header.php does not call wp_head()
plugins hook it, the admin bar needs it, and without it half the plugin directory silently stops working
WORTH FIXING
register_post_type() in functions.php
a post type in a theme means the content disappears when the theme changes
Pitfalls
Nothing found is not the same as approved. These are the mechanical checks. A human reviewer also reads the code, tries the theme, and has opinions about design and accessibility that no pattern match can hold.
Plugin territory is the rejection nobody expects. Post types, taxonomies, shortcodes and meta boxes have to survive a theme switch. Put them in a companion plugin and the theme becomes a theme again.
wp_head() and wp_footer() are not optional, and the failure is silent: everything looks fine
until a plugin that needed the hook does nothing.
GPL applies to everything bundled. A theme that ships a commercial slider, an icon font under a different licence or a stock photograph without a compatible one is rejected for the bundle rather than the code.
node_modules in the zip is the commonest packaging mistake. So is .git. Build the archive from a
clean export rather than zipping your working folder.
The superglobal warning is a hint, not a finding. A $_GET read with sanitising three lines later is
fine; the check cannot see that far, and neither can a reviewer skimming. It is listed so you can point
at the line and say why it is safe.
A child theme is checked as a theme. The Template header is what makes it a child, and the parent’s
files are not in the archive, so anything the parent provides will look missing.
Compatibility
Everything happens in your browser. The zip is opened with a reader written for this, using the
platform’s own DecompressionStream for deflated entries, which every current browser has had since
2023. Nothing is uploaded and nothing is stored.
Limits: 40MB for the archive, 1MB for any single file read as text, 400 text files. Past those, a theme has a packaging problem the checker is about to mention anyway. Binary files are counted but not read.
What is checked: the required files and header fields, a GPL-compatible licence, the screenshot, the
functions that get a theme rejected outright, the ones that belong in a plugin, short open tags,
hard-coded wp-content paths, remote requests made outside the HTTP API, wp_head, wp_body_open,
wp_footer, a missing comments.php where comments_template() is called, development files left in
the archive, the archive size, and whether everything sits inside one folder.
The test suite runs the checker over a theme this site’s own starter theme generator produces, and expects nothing but the screenshot warning. Two tools in the same repo disagreeing would be caught by that test rather than by somebody submitting a theme.
Frequently asked questions
Is this the official Theme Check?
Does it check block themes?
wp_head and functions.php assume a classic
theme, and a block theme legitimately has neither header.php nor footer.php.Will it find security problems?
eval, base64_decode, shell functions, unsanitised superglobals. It is a
packaging and conventions checker, not a security audit.