Description
Awlware Link Checker finds links and images that are really broken and helps you fix them where they are used. Everything runs on your own server: there is no account, no cloud service and no limit on the number of links.
It tells “broken” apart from “the site refuses robots”. Social networks, marketplaces and job boards often answer automated requests with 403, 429, 999 or a captcha page while the page works fine in a browser. Those links are shown as Blocked (verify manually) instead of cluttering the Broken list. Server errors (5xx) and timeouts are rechecked later and reported as broken only if they repeat.
It looks where links actually are: posts, pages and public post types (content and excerpts), classic menus, block theme navigation, synced patterns and templates, custom fields you choose, Text, Custom HTML and Block widgets, pages built with Elementor, and (optionally) approved comments and commenters’ websites. Images (including srcset), iframes, video and audio sources are checked too.
Fix links from the report: Edit URL or Unlink in one or all places (menu items and navigation links stay as plain text), Remove image, Recheck, Dismiss. Posts keep a revision, every change is written to a log and can be undone. Elementor layouts are shown with a link to the Elementor editor.
Light on your site: checks run in short background slices (WP-Cron, 20 seconds every 5 minutes), one request at a time per external site with a pause between requests. Links to your own content are verified from the database instead of over HTTP. Nothing runs on visitor page views. Database tables are created and updated only through dbDelta under a lock, never on visitor requests.
How a link is judged
- Broken: 404 or 410, domain does not exist, redirect loop, missing anchor on one of your pages, or a server error / refused connection that repeated on separate checks.
- Unconfirmed: a server error or refused connection on the first check. It is checked again after an hour (then 2, 4… hours) and becomes Broken only if it fails again.
- Timeout: the server did not answer on repeated checks.
- Suspected: the page answers “200 OK” but looks like a “not found” page (soft 404): its title or text says so, WordPress shows its 404 template, or a deep link redirects to the home page. Never counted as broken.
- Blocked: anti-bot protection (Cloudflare, PerimeterX, DataDome, Akamai, Imperva, Sucuri, AWS WAF, captcha pages), rate limiting (429), login required (401), or a site known to refuse automated checks.
- Unknown: the answer does not prove anything (for example 403 without anti-bot signs or a TLS error).
- Redirect and OK: the link works.
WP-CLI
wp awlware-lc scan, `index`, `report --format=table|json|jsonl`, `where <url>`, `stats`, `reset`.
For developers
Actions and filters start with awlwlc_, for example awlwlc_user_agent, awlwlc_request_args, awlwlc_post_types, awlwlc_meta_keys, awlwlc_exclude_url, awlwlc_classify_result, awlwlc_verdict_changed, awlwlc_results_saved, awlwlc_report_tablenav, awlwlc_admin_tabs.
External requests
Checking links means requesting them, so this plugin makes outgoing HTTP requests. Here is exactly what it does:
- It requests only the URLs found in your own content (HEAD first, GET when needed) to see whether they work. Nothing else is fetched.
- No data is sent to the plugin author or to any third-party service. There are no Awlware servers involved, no telemetry, no license checks and no remote lists: the list of anti-bot sites ships with the plugin.
- Each request carries the User-Agent
Mozilla/5.0 (compatible; AwlwareLinkChecker/1.0.0; +https://awlware.com/link-checker/), so site owners can see who is checking. It can be changed with theawlwlc_user_agentfilter. The plugin never pretends to be a browser. - One request at a time per external site, with a pause between requests, and at most three attempts per URL per check (redirects are followed hop by hop). Soft-404 detection on other sites (one extra GET per working page) is off unless you enable it. A site that does not resolve or refuses connections is not asked again in the same run.
- All requests go through the WordPress HTTP API, so proxies,
WP_HTTP_BLOCK_EXTERNAL,WP_ACCESSIBLE_HOSTSand HTTP filters apply. - SSRF protection: addresses in private, loopback, link-local and reserved ranges (IPv4 and IPv6) are never requested, every redirect is checked again, and the checked address is pinned for the connection to prevent DNS rebinding.
Privacy
The plugin stores the list of links, where they are used, their check results and a log of fixes (who changed what, kept 90 days) in its own database tables on your site. No data leaves your site except the link-check requests described above. It does not use cookies and adds nothing to the public side of your site.
Screenshots





Installation
- Install and activate the plugin.
- Open Tools Link Checker. The first check starts in the background within a few minutes.
- Optional: in Settings, choose what to scan and add custom field names.
If WP-Cron is disabled on your site, run wp cron event run --due-now from a system cron job every 5 minutes, or use wp awlware-lc scan. While the report is open, checks also run in the browser tab.
FAQ
-
Why is a link “Blocked” and not “Broken”?
-
The site refused the automated check (anti-bot protection, rate limit or login). The page most likely works for people. Open it in your browser; if it really is gone, fix it or leave it. Blocked links are never counted as broken.
-
Why is a server error “Unconfirmed”?
-
Servers have short outages. A 5xx error, a refused connection or a timeout is checked again later and reported as broken only when it repeats, so a five-minute outage does not produce a false alarm.
-
Will it slow down my site?
-
No work is done on visitor page views. Background slices are short, links to your own site are verified from the database, and results are written in batches. On a test site with 2,000 posts and 26,000 links, building the index took about 2 seconds.
-
WP-Cron is disabled on my server.
-
See Installation: use a system cron job or WP-CLI. The report page shows a notice with instructions and keeps checking while it is open.
-
I am moving from another broken link checker.
-
Deactivate the old plugin, activate this one, and add the custom field names you want scanned under Settings. There is nothing to import: the index is built from your content automatically.
-
Does it support Elementor and comments?
-
Links in Elementor layouts are found and checked; change them in the Elementor editor (the report links to it). Comment scanning is off by default: enable it under Settings to check links in approved comments and commenters’ websites, and fix or unlink them from the report.
-
Does it change my content?
-
Only when you click Edit URL, Unlink or Remove image. Changes go through the normal WordPress API (posts get a revision), are logged, and can be undone from the Log tab.
-
What is removed when I delete the plugin?
-
By default all plugin tables, settings and scheduled events. You can keep the data by turning off “Delete all plugin data” in the settings before deleting.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Awlware Link Checker” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Awlware Link Checker” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.0
- First release.
