WordPress Site Health "Should Be Improved": Critical Issues Explained
Your WordPress dashboard says Site Health status "Should be improved" and lists critical issues. Some of those items genuinely matter; others are advice you can safely ignore on a small business site.
Common signs of this issue
- The Site Health widget on your WordPress dashboard shows "Should be improved" with an orange or red indicator.
- Tools, then Site Health lists one or more "critical issues" and several "recommended improvements".
- Items like "Your site could not complete a loopback request" or "The REST API encountered an error" appear, and you are not sure what they mean.
- You see "You should use a persistent object cache" or "Page cache is not detected" and wonder whether your site is slow.
- It says your site is running an outdated version of PHP, or that inactive plugins and themes should be removed.
- The status keeps changing from week to week without you touching anything.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Open Tools, then Site Health and wait for the tests to finish. Click each item to expand it — every entry includes a short explanation and often a link to the setting it refers to. Read the critical section first; recommended improvements can wait.
- Outdated PHP: Site Health tells you which PHP version you are on. Ask your host (or look in your hosting panel) how to switch to a current supported version, and check that your plugins and theme support it first. This one is worth acting on — old PHP is slower and no longer gets security fixes.
- Inactive plugins and themes: go to Plugins and Appearance, Themes. Delete plugins you have deactivated and no longer need, and delete unused themes — but keep your active theme, its parent if it is a child theme, and one recent default WordPress theme as a fallback.
- Loopback request failed or REST API error: expand the item and note the error code. These are commonly caused by a security plugin, a host firewall, Cloudflare, or password protection on the site, and they can break scheduled posts, plugin and theme editing, and the block editor.
- A scheduled event is late or has failed: note the event name (it usually hints at which plugin owns it). One late event after a quiet week is normal on a low-traffic site; the same event late every time means WordPress's scheduler is not running reliably.
- Persistent object cache and page cache not detected: check whether your host already provides caching. If the item says server response time is fine, you can generally ignore it. If it says the response time is slow, that is worth following up.
- Background updates and HTTPS items: if Site Health says automatic updates are not working or the site is not fully on HTTPS, those are real issues worth fixing, though usually not urgent in the next hour.
- Open the Info tab and click Copy site info to clipboard. Paste it into a document. It lists your PHP version, plugins, theme, and server details — exactly what a host or developer will ask for, and it contains no passwords.
- Reload Site Health a day after any change. Some results are cached and the dashboard widget updates on a schedule, so a fix does not always show up immediately.
What this usually means
Site Health is a built-in checklist, not an alarm. It runs a set of tests against your server and settings and sorts the results into critical issues and recommended improvements. A status of "Should be improved" simply means at least one test did not pass. Plenty of perfectly healthy small business sites sit on "Should be improved" forever because of one item that does not apply to them. The useful skill is telling the two kinds apart.
The items that genuinely matter are the ones that affect security or break features. Outdated PHP means your server runs a language version that may no longer get security patches. Loopback and REST API failures mean WordPress cannot talk to itself, which quietly breaks scheduled posts, some backups, the block editor, and plugin updates — see not a valid JSON response and missed schedule for what that looks like. Failed background updates, errors displayed to visitors, and no HTTPS also deserve attention.
The items that usually do not matter much are the performance recommendations aimed at larger sites. Persistent object cache is a server feature (such as Redis or Memcached) that helps busy or database-heavy sites; a five-page brochure site gains little. Page cache not detected is worth a look only if it also reports slow server response. Optional PHP modules missing, like imagick, rarely cause visible problems. And inactive plugins and themes are good housekeeping rather than an emergency — though old, unused code is still a security liability worth removing.
What not to do
- Don't chase a perfect "Good" status for its own sake. Fix what affects security and features, and ignore recommendations that do not fit your site.
- Don't switch PHP versions in your hosting panel without a backup and without checking that your plugins and theme support the new version.
- Don't install an object-caching plugin just to clear the warning. On hosting without Redis or Memcached it does nothing useful, and a misconfigured one can break the site.
- Don't delete your only default WordPress theme. Site Health itself recommends keeping one as a fallback if your main theme ever fails.
- Don't disable your security plugin or firewall to make a loopback or REST API warning go away. Whitelist the specific requests instead.
- Don't post the Site Health Info text publicly on forums without reading it first. It contains no passwords, but it does list server paths and software versions.
When to get help
It is worth bringing someone in when a critical issue involves the server rather than a setting you can click: an outdated PHP version your plugins may not survive, loopback or REST API failures that return server errors, or scheduled events that fail repeatedly. Those are the items where a wrong move can take the site offline, and where the fix usually means reading logs, testing a PHP upgrade on a staging copy, or adjusting firewall rules. A person who does this routinely can also tell you, item by item, which warnings are safe to leave alone — which saves you paying for fixes you do not need. See PHP version compatibility problems and how to update WordPress safely for the groundwork.
Glenn runs WebsiteSelfHelp and reviews Site Health reports for small business owners. Send him your Site Health results (the copied Info text is ideal) and he will tell you plainly which items need fixing, which can be ignored, and what the fixes would involve. You do not need to share a login to get that first answer.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
What does WordPress Site Health "Should be improved" mean?
It means at least one of WordPress's built-in tests did not pass. It is not an emergency on its own. Open Tools, then Site Health, and read the critical issues first — those tell you whether anything important is actually wrong.
Which Site Health critical issues actually matter?
Outdated PHP, loopback request failures, REST API errors, failed background updates, errors shown to visitors, and a site not fully on HTTPS. These affect security or break features. Most performance recommendations are optional on small sites.
What does "Your site could not complete a loopback request" mean?
WordPress tried to contact itself over the web and failed. That self-check is used for scheduled tasks and for safely editing plugins and themes. It is usually caused by a firewall, security plugin, Cloudflare setting, or password protection on the site.
Do I need a persistent object cache?
Most small business sites do not. It helps busy or database-heavy sites, such as large shops or membership sites. If Site Health reports your server response time as fine, you can usually leave this recommendation alone.
Is it safe to remove inactive plugins and themes?
Generally yes, after a backup — deactivated plugins are not doing anything, and unused code is a security risk. Keep your active theme, its parent theme if you use a child theme, and one default WordPress theme as a fallback.
Does Site Health affect my Google rankings?
No. Google never sees your Site Health status. Some of the underlying issues, such as a slow server or no HTTPS, can affect visitors and search performance, but the score itself does not.
How much does it cost to fix Site Health issues?
Many items cost nothing but a few minutes. Server-side fixes like a PHP upgrade with compatibility testing, or tracking down a loopback failure, are typically a small, fixed-scope job. Prices vary, so ask for the specific items to be quoted.