Core integrity

Verify WordPress core files against the official release -- and repair only what's actually wrong.

Every WordPress core file is compared against the checksum manifest for the exact official release matching your installed version. A mismatch -- missing, modified, or an unexpected extra file -- is a strong signal of tampering, whether from malware or a bad manual edit. Repair replaces only the affected files from the verified official package, not the whole install.

Official

Checksum manifest

Missing files

Detected

Modified files

Detected

Targeted

Repair

wpfixagent.com/wordpress-core-integrity

Integrity check to verified repair

Fetch the manifestThe checksum manifest for your exact installed WordPress version is used as the comparison baseline.
CompareEvery core file is checked; mismatches are categorized as missing, modified, or unexpected.
ProtectA full restore point is created and verified before any repair action runs.
RepairOnly the files that failed their checksum are replaced, from the verified official package.
VerifyA fresh check confirms the repair actually resolved every flagged file.

Repair playbook

1

Fetch the manifest

The checksum manifest for your exact installed WordPress version is used as the comparison baseline.

2

Compare

Every core file is checked; mismatches are categorized as missing, modified, or unexpected.

3

Protect

A full restore point is created and verified before any repair action runs.

4

Repair

Only the files that failed their checksum are replaced, from the verified official package.

5

Verify

A fresh check confirms the repair actually resolved every flagged file.

Checksum comparison against the official release

Core files are checked against the manifest for the exact WordPress version you have installed -- not a generic or outdated reference set.

Three distinct finding types

Missing core files, modified core files, and unexpected PHP files sitting inside core directories are each reported separately, since they usually mean different things.

Repair replaces only what failed

Core-file repair restores exactly the files that failed their checksum from the exact official release package -- it doesn't touch files that already match.

A restore point first, always

Because a core-file repair is one of the highest-blast-radius actions WPFixAgent can take, it always creates and verifies a full restore point before making any change.

Re-verification after repair

A fresh integrity check confirms every previously-failed file now matches before the repair is marked complete.

Why targeted repair matters

Comparison uses the official manifest for your exact version

Only failed files are touched -- nothing else is overwritten

A full restore point exists before any change is made

Verification re-checks every file the repair claimed to fix

Practical guidance

Go deeper before changing a live site.

Open documentation

Critical errors

How to Fix a WordPress Critical Error Without Making It Worse

Recover from the WordPress critical error screen with a controlled process that protects evidence, creates a restore point, isolates the cause, and verifies the result.

Read guide

Auto repair

WordPress Auto Repair: What Should Be Automated and What Needs Review?

Automation should resolve known, reversible WordPress conditions while risky database, malware, and hosting failures remain review-driven.

Read guide

Backups

Local vs Off-Site WordPress Backups: What a Recovery Plan Needs

Local restore points make repairs fast, while off-site copies protect against hosting and disk failure. A serious recovery plan needs clear roles for both.

Read guide

FAQ

Common questions

What counts as an 'unexpected' core file?

A PHP file present inside a WordPress core directory that isn't part of the official release manifest at all -- often the clearest sign of a planted file, since it has no legitimate reason to be there.

Will core repair overwrite my custom changes?

Only files that fail the checksum comparison are replaced. If you've made direct edits to a core file (not recommended, but possible), that file would show as modified and be flagged for repair -- the same as tampering would be.

Does this check plugin and theme files too?

No -- this page covers WordPress core specifically. Plugin and theme file integrity is covered by the malware scanner and the reinstall-from-official-source workflow.

What if the manifest itself is unavailable?

The scan reports what it could verify; unresolved checks are surfaced rather than silently assumed to be fine.

Free 14-day trial · no card required

Give every WordPress site a safer path from incident to verified recovery.

Install the connector, pair with a one-time token, and start monitoring in minutes -- upgrade whenever you're ready.

Start Free Trial