WPSecureOps

Glossary · File change

A WordPress core file has been modified

Wordfence type
coreFile
Category
File change
Severity
High

A file that ships with WordPress no longer matches the official copy.

What Wordfence found

Wordfence checksums core files against the official release. A mismatch means the file's contents differ from what WordPress.org distributes for that version.

Why it matters

Core files should never be edited. A modification is either a compromise, a well-meaning but dangerous hand-edit, or a host that patches core for its own reasons. All three are worth knowing about, and the first is the one that matters.

How to fix it

  1. 1View the difference — Wordfence can show what changed, and that usually settles the question immediately.
  2. 2If it is malicious or unexplained, reinstall core from the Updates screen, which replaces every core file.
  3. 3If a developer edited core deliberately, move the change into a plugin or a filter. It will be lost at the next update otherwise.
  4. 4If the host modified it, ask them why before overwriting.

Findings that often appear with this one

How WPSecureOps treats it

The connector reports this as coreFile. WPSecureOps files it under File change and bands it by the numeric severity Wordfence assigns, so findings of this kind from every site you manage arrive in one queue rather than one email per site. Titles and descriptions are stripped of HTML and the site's absolute path is replaced before anything leaves the server.

See this finding in context