↑ ↓ select, Enter open, Esc close

Check WordPress core files for tampering

Adjust the values, the command updates live
user@server
wp core verify-checksums --path=/var/www/vhosts/example.com/httpdocs

Downloads the checksums for the installed WordPress version from wordpress.org and compares them with the files in wp-admin, wp-includes and the root directory. Modified or additional files are reported as warnings. Useful when you suspect malicious code or after a failed update.

Note: wp-content is not checked. Plugins can be verified separately with wp plugin verify-checksums --all.

Also searched as

  • check if wordpress is hacked
  • find modified wordpress core files
  • verify wordpress core integrity

Related one-liners

All in WP-CLI

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.