Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to check WordPress files with WP-CLI checksums

Is one of your WordPress files changed or damaged? A checksum check finds it fast. This guide shows how.

WordPress2 min read3 steps

What is a checksum?

A checksum is like a fingerprint for a file. Every file has its own. If even one letter in the file changes, the fingerprint changes too. WordPress.org publishes the right fingerprints for each official version.

WP-CLI compares the fingerprints of the files on your site with the official ones. If a file does not match, it was edited, damaged, or maybe changed by malware. Malware is harmful software that attackers hide in a site.

What is WP-CLI?

WP-CLI is a tool that manages WordPress by typed commands. You need SSH access. SSH is a safe way to type commands on your server. Ask Hostvento support whether your plan includes SSH and WP-CLI.

Steps

  1. Connect to your server using SSH.
  2. Go to your WordPress folder. For many sites it is public_html.
  3. Run the command below.
cd public_html
wp core verify-checksums

The first line moves into your site folder. The second checks all core files against the official list.

If all is well you see a message like "Success: WordPress installation verifies against checksums."

If you see warnings

You may see lines like "File doesn't verify against checksum" or "File should not exist". Here is what they mean:

  • Doesn't verify means the file was changed.
  • Should not exist means there is an extra file that WordPress does not use. This can be harmless, such as a leftover file. It can also be a sign of a hack.

Open each named file or ask for help before you delete anything.

Warning: Take a backup before you replace or delete files.

Repair the core files

To get fresh copies of the core files, run:

wp core download --force --skip-content

This downloads WordPress again and overwrites the core files. The --skip-content option leaves your wp-content folder alone. It is safe for themes and uploads, but it will also replace any core files you edited on purpose. The wp-config.php file is not replaced.

Check plugins too

wp plugin verify-checksums --all

This checks every plugin that comes from the official WordPress.org plugin directory. Premium plugins from other places cannot be checked this way.

Tip: Run the check every month, or when your site acts strangely. Lots of mismatches may mean your site was hacked, so open a support ticket.

Quick recap

  • A checksum is a file's fingerprint.
  • wp core verify-checksums compares your files with the official ones.
  • Mismatches point to edited or harmful files.
  • Back up before you repair anything.