See all checks
Security & integrity

File integrity monitoring — your supply-chain tripwire.

Relvato compares your WordPress core and wp.org plugin files against their official published checksums, and flags any file that’s been modified, corrupted, or injected — the classic sign of a compromised update or a backdoor.

What it checks
  • Core files match the official WordPress checksums
  • wp.org plugin files match their release checksums
  • No unexpected added or modified files in tracked paths
  • Flags the exact files that differ
Why it matters

A tampered core file is how a backdoor survives — it looks identical in your dashboard. File integrity monitoring compares byte-for-byte against the official release, so an injected file or a corrupted update surfaces immediately instead of after the damage.

Works on any WordPress or WooCommerce site.

How it works
  • Fetches the official checksums for your exact WordPress and plugin versions.
  • The plugin hashes the installed files and reports any mismatch — modified, missing or extra.
  • You get the exact file paths that differ, so a corrupted update or an injected backdoor is obvious.
Questions, answered
Does it read my file contents?

It compares hashes locally via the plugin; only mismatched file paths are reported, not contents.

Which files are covered?

WordPress core and plugins distributed on wp.org, which publish official checksums.

Related checks
File integrity

Put this check on autopilot.

Free while you set it up — 100 checks or 30 days. No card, no sales call.