Checksum
A checksum is a short string worked out from a file's contents. If the file changes, so does the string. WordPress.org publishes one for every file in WordPress and in its plugins, so a site's files can be compared with the originals.
- By
- WP Ministry
- Published
In short
- A checksum shows whether a file still matches the original. It cannot say who changed a file, or why.
- WP-CLI checks WordPress's own files and plugins from WordPress.org. Themes, other plugins, uploads, must-use plugins and the database are not checked.
- A clean run prints the Success line and nothing else. A file added to WordPress's folders shows as a warning above a Success line.
A checksum is a short string worked out from the contents of a file. The working out is done by a hash function, which takes input of any length and gives back output of a fixed length. An MD5 checksum is always 32 characters. The same contents always give the same string, and different contents should, as far as possible, give different ones.
That makes a checksum a quick answer to one question: is this file the one its publisher released? Compare the file's checksum with the one the publisher lists, and you know without reading the file.
Where you meet it
- Beside every download of WordPress. The release archive on WordPress.org has an
md5and asha1link next to each file. Each holds the checksum of that download. - Inside WordPress's updater. WordPress.org also publishes a checksum for every single file in a release. WordPress fetches that list itself when it updates.
- In WP-CLI.
wp core verify-checksumsdownloads the list for your version and compares the installed files with it, without loading WordPress.wp plugin verify-checksumsdoes the same for plugins, using the checksums WordPress.org holds for each plugin and version.
What goes wrong
- "It ended in Success" is read as clean. If a file has been added to WordPress's folders and no original was changed, the core command prints
Warning: File should not exist:with the file's name, and its last line still says Success. Read every line. - It is taken to cover the whole site. WP-CLI has no checksum command for themes. A plugin that did not come from WordPress.org is skipped with a warning. Nothing in
wp-content/uploadsorwp-content/mu-pluginsis looked at, nor a drop-in,wp-config.php,.htaccessor the database. Those are places a planted redirect lives, and WordPress site redirecting to another site goes through each one. - A failed checksum is read as proof of a hack. It is proof that the file differs from the original. Someone on your side may have edited it. Compare it with the same version downloaded again. How to check whether your WordPress site has been hacked puts checksums beside the other checks.
- A mismatch is fixed one file at a time. Replacing the files that failed leaves whatever the commands never looked at. Why your WordPress site keeps getting hacked rebuilds from clean downloads and then uses checksums to confirm the result.
How to look at yours
Run these from the site's main folder. They need SSH access and WP-CLI.
wp core verify-checksums --include-root
wp plugin verify-checksums --all --skip-plugins --skip-themesA clean run prints one line for each command and nothing else. The count is the number of plugins you have.
Success: WordPress installation verifies against checksums.
Success: Verified 2 of 2 plugins.Anything else on the screen is a finding. --include-root also warns about files in the main folder that are not part of WordPress, and some of those will be yours. A plugin count followed by "(1 skipped)" means one plugin was not checked. The client site takeover checklist has a table of what each line of output means.
Common questions
Why can't my theme or a paid plugin be checked?
The checksums come from WordPress.org. A plugin bought elsewhere has none there, so WP-CLI warns that it could not retrieve the checksums and skips it. For themes WP-CLI has no checksum command at all. To check either, download the same version from its author and compare the folders.
What are the md5 and sha1 links beside a WordPress download for?
They let you confirm that a download arrived whole and unaltered. Work out the checksum of the file you downloaded, with a tool such as sha1sum, and compare it with the published string. If the two match, you have the file WordPress.org released.

