Theme Check Scanner

Opens a theme .zip in your browser and runs the checks the directory runs: required files and headers, forbidden functions, plugin territory, missing hooks.

This tool needs JavaScript: the zip is opened and read in your browser, and nothing is uploaded.

No theme yet. This runs the kind of checks the theme directory runs, before you submit anything to it.

The checks the WordPress theme directory runs, on a theme that has not been uploaded anywhere. Drop in the zip and read the list.

Theme Check is normally a plugin: install WordPress, install the theme, install the checker, read the output. This does the same kind of reading on the files in the archive, in your browser, which means it works before the theme is near a site and without handing an unreleased theme to anybody.

How to use

Choose the zip, or drop it on the box. Nothing is uploaded: the archive is opened and decompressed in this tab, and closing the page discards it.

Example

acme-starter · 13 files · 18.4 KB
0 required · 1 worth fixing · 0 worth knowing

WORTH FIXING
No screenshot
  the themes screen shows a grey box, and the directory wants 1200 by 900

A theme with real problems reads like this:

REQUIRED
eval() in functions.php
  running arbitrary code, which is an automatic rejection and usually means something got in

REQUIRED
header.php does not call wp_head()
  plugins hook it, the admin bar needs it, and without it half the plugin directory silently stops working

WORTH FIXING
register_post_type() in functions.php
  a post type in a theme means the content disappears when the theme changes

Pitfalls

Nothing found is not the same as approved. These are the mechanical checks. A human reviewer also reads the code, tries the theme, and has opinions about design and accessibility that no pattern match can hold.

Plugin territory is the rejection nobody expects. Post types, taxonomies, shortcodes and meta boxes have to survive a theme switch. Put them in a companion plugin and the theme becomes a theme again.

wp_head() and wp_footer() are not optional, and the failure is silent: everything looks fine until a plugin that needed the hook does nothing.

GPL applies to everything bundled. A theme that ships a commercial slider, an icon font under a different licence or a stock photograph without a compatible one is rejected for the bundle rather than the code.

node_modules in the zip is the commonest packaging mistake. So is .git. Build the archive from a clean export rather than zipping your working folder.

The superglobal warning is a hint, not a finding. A $_GET read with sanitising three lines later is fine; the check cannot see that far, and neither can a reviewer skimming. It is listed so you can point at the line and say why it is safe.

A child theme is checked as a theme. The Template header is what makes it a child, and the parent’s files are not in the archive, so anything the parent provides will look missing.

Compatibility

Everything happens in your browser. The zip is opened with a reader written for this, using the platform’s own DecompressionStream for deflated entries, which every current browser has had since 2023. Nothing is uploaded and nothing is stored.

Limits: 40MB for the archive, 1MB for any single file read as text, 400 text files. Past those, a theme has a packaging problem the checker is about to mention anyway. Binary files are counted but not read.

What is checked: the required files and header fields, a GPL-compatible licence, the screenshot, the functions that get a theme rejected outright, the ones that belong in a plugin, short open tags, hard-coded wp-content paths, remote requests made outside the HTTP API, wp_head, wp_body_open, wp_footer, a missing comments.php where comments_template() is called, development files left in the archive, the archive size, and whether everything sits inside one folder.

The test suite runs the checker over a theme this site’s own starter theme generator produces, and expects nothing but the screenshot warning. Two tools in the same repo disagreeing would be caught by that test rather than by somebody submitting a theme.

Frequently asked questions

Is this the official Theme Check?
No. It is the same kind of reading, done in a browser on the archive rather than by a plugin on an installed theme. The official plugin has more rules and is what the directory actually runs.
Does it check block themes?
Partly. The file and header checks apply; the checks about wp_head and functions.php assume a classic theme, and a block theme legitimately has neither header.php nor footer.php.
Will it find security problems?
Only the obvious ones: eval, base64_decode, shell functions, unsanitised superglobals. It is a packaging and conventions checker, not a security audit.
Why not upload the zip to a server?
Because there is no reason to. The work is reading text, the browser can do it, and an unreleased theme is exactly the sort of thing that should not be sitting on somebody else’s disk.
My theme has no errors but was rejected.
Read the reviewer’s notes: most rejections are about bundled licences, design decisions or accessibility, none of which a scanner can see.

From the people who built this tool

WP Adminify

The WordPress admin, rebuilt: a dashboard worth looking at, menu and column control, a real file manager and the login page your client sees.

See WP Adminify Free version on WordPress.org

Weekly drops

New tools, when there are new tools

One email when something worth using ships. No schedule to fill, so no filler.

Your address goes nowhere else, and one click unsubscribes.