# Check your files against the official copies

Compare WordPress core and plugin files with the official WordPress.org copies, put a changed file back, mark changes expected and use quarantine.

BetterShield compares your WordPress core and plugin files with the copies WordPress.org publishes, and watches the code nobody publishes for changes. Find it under **BetterShield › Activity › File changes** (the tab reads **Files**).

## What is compared

| What | Compared with | Can be put back |
|---|---|---|
| WordPress core | The checksums WordPress.org publishes for your version and language. | Yes |
| Plugins from the WordPress.org directory | The checksums for the exact version installed. | Yes |
| Your active theme and its parent, must-use plugins, drop-ins, wp-config.php, .htaccess, .user.ini files, and plugins not in the directory | What the file was at the last check. WordPress.org publishes no checksums for themes. | No |

Core and plugin folders are also searched for files nobody published. In the third row only code files are watched: the first check records them, and later changes are reported, except an update WordPress itself installed. Uploads are never checked.

## When the check runs

- **Every hour** for WordPress core and directory plugins, in the background. On a large site one full check can take several hours; the screen shows progress.
- **Once a day** for watched files: your theme, must-use plugins, drop-ins, wp-config.php, .htaccess and plugins outside the directory (every hour with Ultra).
- **Check now** starts a check with freshly fetched checksums, or carries on the one running. On a large site the hourly schedule finishes it.
- **When a plugin is installed or updated**, the downloaded copy is compared with the published one before it replaces the old files. This never stops an update.

While changes are open, Findings shows **Files no longer match the official copies**. If nothing is open and no check has finished for two days, it shows **Files have not been checked against the official copies**.

## Read the report

**Files at a glance** shows **Last check** (with the next run), **Unresolved changes**, **Can be put back** and **In quarantine**.

If part of the site could not be compared, a note names each item and why. Nothing on it is counted as clean.

Each file shows its path, when it was **Noticed**, what it was compared against, and its kind:

| Kind | Meaning | Severity shown |
|---|---|---|
| **Altered** | Differs from the official copy, or from what it was. | Critical |
| **Not published** | Nothing published this file. | Critical |
| **Missing** | A file the official copy lists is gone. | Medium |
| **Could not be read** | The server would not let it be read: a permissions problem, not a change. | Low |
| **Package** | A plugin update did not match its published copy when it arrived. | High |

Files are grouped under **Can be put back**, **Plugins that differ from their published release** and **No official copy to put back**, with the reason given once per group. A long group shows ten files, then a button with the full count, such as **Show all 24**.

## Act on a file

| Action | What it does |
|---|---|
| **Show the difference** | Fetches the official copy and shows it beside yours, line by line. A long file shows only the part that changed. |
| **Put the official file back** | Fetches the official copy, checks it against the published checksum, writes it, and moves your file to quarantine. **Put this file back** in quarantine reverses it. |
| **Expected** | Stops reporting the file as it is now; a further change is reported again. It moves to **Marked expected**, where **Stop ignoring** reports it again. |

Only an altered core or directory plugin file gets the first two buttons. Reinstall to replace a missing file. For code nobody publishes, restore from your own backup: earlier contents are not kept. Files over 2 MB cannot be compared or put back here.

## By plugin and version

Each plugin or theme with open changes at one recorded version:

- **Check again** (plugins only): after an update has finished, compares the open changes with the installed version's published copy. What matches closes.
- **Mark all 12 changes expected…** (the button shows your count) lists the counts and names added files that can run as code, then **Mark these 12 changes expected** marks them as one decision.
- **Marked expected together** lists those decisions; **Report them again** undoes one.

A **Package** row lists the files that differ, each with **Show the difference**. If you built or patched that plugin yourself, press **Adopt this copy**: that version stays quiet until one of its files changes, and **Undo** appears in the confirmation line.

## Kept in quarantine

When BetterShield replaces a file, for example by putting the official file back, the file that was there is kept, never deleted. Copies go to a sealed `bettershield-quarantine` folder in your uploads folder, under random names with an extension no server runs.

| Action | What it does |
|---|---|
| **Download a copy** | Saves it to your computer as a .txt file. Recorded in the activity log. |
| **Put this file back** | Puts it back byte for byte. The difference is reported again. |
| **Delete**, then **Yes, remove it for good** | Removes the copy for good. Recorded in the activity log. |

Deleting the plugin leaves the copies in place unless you choose, under **When this plugin is deleted** on **Settings › General**, to pack them into one archive.

> **Note:** The folder's deny rule works on Apache. On a server that ignores it, Findings shows **Files kept as evidence are not sealed off from the web** with the folder to deny in your server configuration.

With **Ask for my password before an action that removes a protection** on (**Settings › General**), marking or unmarking expected, adopting a copy, and putting back or deleting a quarantined copy ask for your password first.

## What cannot be checked

- **Plugins not on WordPress.org**, such as premium or custom ones: named in the note, then watched for changes, with no official copy to put back.
- **A WordPress version without published checksums**, such as a release candidate.
- **A plugin that is a single file** rather than a folder.
- **Very large folders**, beyond what one check walks. The note says so.

What each request to WordPress.org carries is on [What BetterShield contacts](/docs/what-bettershield-contacts/). From the terminal, `wp bettershield integrity` does the same jobs: see [WP-CLI commands](/docs/wp-cli-commands/).

## Related

- [Score and findings](/docs/score-and-findings/)
- [Incidents](/docs/incidents/)
- [Automatic response](/docs/automatic-response/)
- [General settings](/docs/general-settings/)
