Using the checklist

4 min read

This page covers day-to-day use of WooCommerce > Maintenance Checklist: running scans, reading findings, ignoring intentional issues, and exporting CSV.

Run a scan

  1. Open WooCommerce > Maintenance Checklist (Checklist screen).
  2. Click Run scan.
  3. While the scan runs:
    • Run scan is disabled and shows Scanning…
    • A progress panel shows phase and percent complete
    • Previous findings stay visible but dimmed until the scan finishes
    • Click Cancel scan to stop further Action Scheduler batches

One scan at a time: if a scan is already running, a new start is rejected until it completes, fails, or is cancelled.

Stalled scans

If background batches stop making progress for about 8 minutes, the UI marks the scan as stalled and offers:

  • Retry — re-queue remaining catalog work (keeps findings already collected)
  • A link to WooCommerce → Status → Scheduled Actions
  • Cancel scan

Stalls usually mean WP-Cron or Action Scheduler is not running promptly on the host.

Provisional scores

Large catalogs are bounded (default 1000 products / 2000 variations — see Settings). If the bound is hit, or a cancel/fail leaves catalog work incomplete, the score is marked provisional. Raise bounds or re-run after fixing Criticals if you need a fuller catalog pass.

Read findings

Each open finding shows:

ElementMeaning
Severity badgeCritical, Warning, or Info
Title and whyPlain-language explanation
EvidenceSummary, count, and up to a few sample admin deep links
Primary actionFree WooCommerce / WordPress / hosting fix path
Further toolsOptional StoreCrafted product links (if enabled in Settings)
Area tagcatalog, payments, shipping, email, orders, or environment

Work order: Critical > Warning > Info. The checklist score is secondary to fixing money and trust risks.

Passed checks appear in a collapsible checks passed list at the bottom of the page (not in the open findings table).

Use the metric strip and table controls to focus the list:

  • Severity / metric filters — Open, Critical, Warning, or Info cards on the metric strip
  • Area — All areas, or one of catalog, payments, shipping, email, orders, environment
  • Status — Open findings, Ignored, or Open + ignored
  • Search — Match text in titles and related finding fields

If nothing matches, the table shows that no findings match the current filters.

Ignore and restore

Use ignore when a finding is intentional for this store (for example test mode on staging, or a catalog mode without shipping).

  1. On an open finding, click Ignore…
  2. Optionally enter a reason (max 200 characters).
  3. Confirm. The finding moves to ignored status and is excluded from the score.

To restore: filter to Ignored, then restore the finding so it can score again on the next evaluation.

Settings shows how many checks are ignored and links back to the Checklist Ignored filter. Clearing history does not clear ignores.

Export CSV

  1. On Checklist, click Export CSV (disabled while a scan is running or before the first scan).
  2. The browser downloads store-maintenance-checklist-findings.csv.

Included: open and ignored findings from the current results (passed checks are omitted).

Columns: check_id, severity, area, title, why, evidence, status (open or ignored), ignore_reason, primary_action_url, further_tools, score_excluded (yes / no), scan_timestamp, environment, provisional (yes / no).

Privacy: Export is ops metadata (finding text and admin URLs), not a full customer data dump. Treat downloads as sensitive if evidence links include order or product admin paths.

Score summary

The metric strip shows an overall score and counts for open Critical / Warning / Info, passed, and ignored.

RuleBehaviour
FormulaStart at 100; subtract penalties (info 3, warning 8, critical 15); floor at 0
IgnoredExcluded from the score
Link-outsSite Health and WooCommerce Status nudges never add penalty
Softened severitiesOn local / development / staging (unless force-production), Critical >Warning and Warning > Info; the score uses softened severities
DisclosureInformational only — not security, PCI, or legal certification

Environment banners explain when severities are relaxed. Force full production scoring in Settings or via STMC_FORCE_PRODUCTION_SEVERITY.

Non-production environments

When WP_ENVIRONMENT_TYPE is local, development, or staging, and force-production is off:

  • Severities are softened (see table above)
  • Some production-only environment checks (for example HTTPS off, debug display) do not raise production Criticals the same way

Use Treat as production for scan severity on Settings when you want staging QA to mirror live risk.

Updated on October 9, 2026