WordPress core integrity
WordPress core file integrity checks
Malware loves hiding where nobody looks: in WordPress core files. Comparing them with the official release brings it into the open.
The problem
One line in wp-includes is enough for a backdoor.
Attackers often leave a way back in by editing a WordPress core file, because popular security plugins look elsewhere and an update may not overwrite it.
Checking thousands of files by hand is impossible. Comparing them with official checksums takes a second.
How it works
Compared with the official release, file by file.
- 1
Official checksums
We use the checksums published by WordPress.org for the version and language of the package that was installed.
- 2
Comparison on the site
The agent fingerprints every core file and flags modified ones and ones that shouldn’t be there.
- 3
Diff and decision
For each flagged file you see the changed lines against the official package, with typical backdoor functions highlighted.
In detail
Accuracy first.
- Checksums for the installation language, not the current one: no false positives on translated sites
- Modified files and unexpected files in core folders
- Line-by-line diff against the official package
- Whitespace and line-ending differences recognised as harmless
- Intentional changes can be approved: they stop counting until they change again
- In our tests: zero false positives across 3,336 files of a clean install
FAQ
Frequently asked questions
Where do the checksums come from?
From the official WordPress.org API, for the version and language of the package the site was installed from.
What if I changed a core file on purpose?
You can approve the change: the file is no longer flagged until it changes again.
Does the check slow the site down?
No, the agent works in short steps of a few seconds, sized for shared hosting.
Related features
Goes well with
Try it on your clients’ sites.
During the beta we welcome agencies in small groups and set up the first sites together.