BetterShield

Check your files against the official copies

5 min read

Compare WordPress core and plugin files with the official WordPress.org copies, put a changed file back, mark changes expected and use quarantine.

BetterShield compares your WordPress core and plugin files with the copies WordPress.org publishes, and watches the code nobody publishes for changes. Find it under BetterShield › Activity › File changes (the tab reads Files).

What is compared

WhatCompared withCan be put back
WordPress coreThe checksums WordPress.org publishes for your version and language.Yes
Plugins from the WordPress.org directoryThe checksums for the exact version installed.Yes
Your active theme and its parent, must-use plugins, drop-ins, wp-config.php, .htaccess, .user.ini files, and plugins not in the directoryWhat the file was at the last check. WordPress.org publishes no checksums for themes.No

Core and plugin folders are also searched for files nobody published. In the third row only code files are watched: the first check records them, and later changes are reported, except an update WordPress itself installed. Uploads are never checked.

When the check runs

  • Every hour for WordPress core and directory plugins, in the background. On a large site one full check can take several hours; the screen shows progress.
  • Once a day for watched files: your theme, must-use plugins, drop-ins, wp-config.php, .htaccess and plugins outside the directory (every hour with Ultra).
  • Check now starts a check with freshly fetched checksums, or carries on the one running. On a large site the hourly schedule finishes it.
  • When a plugin is installed or updated, the downloaded copy is compared with the published one before it replaces the old files. This never stops an update.

While changes are open, Findings shows Files no longer match the official copies. If nothing is open and no check has finished for two days, it shows Files have not been checked against the official copies.

Read the report

Files at a glance shows Last check (with the next run), Unresolved changes, Can be put back and In quarantine.

If part of the site could not be compared, a note names each item and why. Nothing on it is counted as clean.

Each file shows its path, when it was Noticed, what it was compared against, and its kind:

KindMeaningSeverity shown
AlteredDiffers from the official copy, or from what it was.Critical
Not publishedNothing published this file.Critical
MissingA file the official copy lists is gone.Medium
Could not be readThe server would not let it be read: a permissions problem, not a change.Low
PackageA plugin update did not match its published copy when it arrived.High

Files are grouped under Can be put back, Plugins that differ from their published release and No official copy to put back, with the reason given once per group. A long group shows ten files, then a button with the full count, such as Show all 24.

Act on a file

ActionWhat it does
Show the differenceFetches the official copy and shows it beside yours, line by line. A long file shows only the part that changed.
Put the official file backFetches the official copy, checks it against the published checksum, writes it, and moves your file to quarantine. Put this file back in quarantine reverses it.
ExpectedStops reporting the file as it is now; a further change is reported again. It moves to Marked expected, where Stop ignoring reports it again.

Only an altered core or directory plugin file gets the first two buttons. Reinstall to replace a missing file. For code nobody publishes, restore from your own backup: earlier contents are not kept. Files over 2 MB cannot be compared or put back here.

By plugin and version

Each plugin or theme with open changes at one recorded version:

  • Check again (plugins only): after an update has finished, compares the open changes with the installed version’s published copy. What matches closes.
  • Mark all 12 changes expected… (the button shows your count) lists the counts and names added files that can run as code, then Mark these 12 changes expected marks them as one decision.
  • Marked expected together lists those decisions; Report them again undoes one.

A Package row lists the files that differ, each with Show the difference. If you built or patched that plugin yourself, press Adopt this copy: that version stays quiet until one of its files changes, and Undo appears in the confirmation line.

Kept in quarantine

When BetterShield replaces a file, for example by putting the official file back, the file that was there is kept, never deleted. Copies go to a sealed bettershield-quarantine folder in your uploads folder, under random names with an extension no server runs.

ActionWhat it does
Download a copySaves it to your computer as a .txt file. Recorded in the activity log.
Put this file backPuts it back byte for byte. The difference is reported again.
Delete, then Yes, remove it for goodRemoves the copy for good. Recorded in the activity log.

Deleting the plugin leaves the copies in place unless you choose, under When this plugin is deleted on Settings › General, to pack them into one archive.

Note: The folder’s deny rule works on Apache. On a server that ignores it, Findings shows Files kept as evidence are not sealed off from the web with the folder to deny in your server configuration.

With Ask for my password before an action that removes a protection on (Settings › General), marking or unmarking expected, adopting a copy, and putting back or deleting a quarantined copy ask for your password first.

What cannot be checked

  • Plugins not on WordPress.org, such as premium or custom ones: named in the note, then watched for changes, with no official copy to put back.
  • A WordPress version without published checksums, such as a release candidate.
  • A plugin that is a single file rather than a folder.
  • Very large folders, beyond what one check walks. The note says so.

What each request to WordPress.org carries is on What BetterShield contacts. From the terminal, wp bettershield integrity does the same jobs: see WP-CLI commands.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield