
Core Checksum Verifier Security & Risk Analysis
wordpress.org/plugins/core-checksum-verifierVerifies the integrity of your WordPress core files with official checksums. Displays modified/missing files.
Is Core Checksum Verifier Safe to Use in 2026?
Generally Safe
Score 100/100Core Checksum Verifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'core-checksum-verifier' plugin v1.0.1 exhibits a mixed security posture. On the positive side, the code demonstrates good practices by exclusively using prepared statements for SQL queries and ensuring all outputs are properly escaped. It also avoids dangerous functions and file operations, and has no recorded vulnerability history, which suggests a history of secure development.
However, a significant concern arises from its attack surface. The plugin exposes one AJAX handler that lacks any authentication or capability checks. This means any unauthenticated user could potentially interact with this endpoint, posing a risk if the functionality it exposes is sensitive or can be misused. While taint analysis shows no vulnerabilities, the absence of checks on the AJAX handler is a known entry point for common web attacks.
In conclusion, while the plugin's core code appears to be written with security in mind regarding data handling, the lack of authentication on its AJAX endpoint is a critical oversight. This single unprotected entry point significantly elevates the risk profile, outweighing the otherwise positive code quality signals. Addressing this unprotected AJAX handler should be the immediate priority.
Key Concerns
- Unprotected AJAX handler
Core Checksum Verifier Security Vulnerabilities
Core Checksum Verifier Code Analysis
Output Escaping
Core Checksum Verifier Attack Surface
AJAX Handlers 1
WordPress Hooks 2
Maintenance & Trust
Core Checksum Verifier Maintenance & Trust
Maintenance Signals
Community Trust
Core Checksum Verifier Alternatives
Files Fence
files-fence
Detect if a wordpress core files are changed and if a unwanted file(s) are uploaded or created in wordpress folders different to wp-content
WP Fingerprint
wp-fingerprint
WP Fingerprint adds an additional layer of security to your WordPress website, working to check your plugins for signs of hack or exploit.
Subresource Integrity (SRI) Manager
wp-sri
Adds Subresource Integrity (SRI) attributes to your page's elements for better protection against JavaScript DDoS attacks.
Auto SRI
auto-sri
Automatically adds Subresource Integrity (SRI) to external scripts/styles and safely excludes Google reCAPTCHA and Google Fonts.
Integrity Checker
integrity-checker
The WordPress Integrity Checker checks your WordPress installation by detecting modified files, permissions issues and other common problems.
Core Checksum Verifier Developer Profile
1 plugin · 0 total installs
How We Detect Core Checksum Verifier
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/core-checksum-verifier/assets/css/admin.css/wp-content/plugins/core-checksum-verifier/assets/js/admin.js/wp-content/plugins/core-checksum-verifier/assets/img/9068699.png/wp-content/plugins/core-checksum-verifier/assets/img/header.png/wp-content/plugins/core-checksum-verifier/assets/js/admin.jscore-checksum-verifier/assets/css/admin.css?ver=core-checksum-verifier/assets/js/admin.js?ver=HTML / DOM Fingerprints
pul-buttonpul-overlay__bodypul-dialog__headerpul-dialog__bannerpul-dialog__banner-innerpul-dialog__header-innerpul-dialog__header-bodypul-dialog__header-content+4 morecorechDatajQuery/wp-json/core-checksum-verifier/v1/settings