Skip to content

Add WordPress core integrity scanning - #7

Merged
matthewdorman merged 1 commit into
mainfrom
feature/core-integrity-scan
Aug 19, 2026
Merged

matthewdorman merged 1 commit into
mainfrom
feature/core-integrity-scan

Conversation

@matthewdorman

Copy link
Copy Markdown
Owner

Summary

  • add a read-only WordPress core integrity report using authoritative checksums for the installed version and package locale
  • distinguish modified, missing, unexpected, and unreadable core files with explicit clean, findings, incomplete, and unsupported states
  • bound unexpected-file enumeration to wp-admin and wp-includes, without following symlinks or inspecting arbitrary root files or wp-content
  • expose relative-path evidence in wp-admin and CSV while preventing spreadsheet formula interpretation
  • add isolated fixture coverage to CI and document privacy, caching, custom-build, and coverage limitations

Deliberate boundaries

  • Development/nightly version strings are unsupported because an authoritative manifest may not exist; the scanner does not compare them with a previous stable release.
  • A localized package uses $wp_local_package and never silently falls back to en_US. Missing version/locale checksums produce an incomplete result.
  • Only successful checksum manifests are cached (12 hours). Local files are hashed fresh for every generated report.
  • Unexpected files are reported only under core-owned wp-admin and wp-includes. Site-root extras and all of wp-content are excluded to avoid treating normal host/application files as core changes.
  • Symlinks, unsafe manifest entries, unreadable paths, and scan/report limits make coverage incomplete instead of clean.
  • The report includes relative paths and MD5 evidence, but never absolute paths or file contents.

Validation

  • php tests/test-core-integrity-auditor.php
  • PHP syntax lint across all PHP files
  • WordPress PHPCS across production PHP sources
  • shellcheck scripts/*.sh
  • ./scripts/build-release.sh
  • ./scripts/validate-release.sh dist/plugin-reviewer.zip
  • live read-only smoke scan against an official WordPress 6.8.1 install: complete/clean, 2,782 core-owned files enumerated, zero findings

Closes #3

@matthewdorman
matthewdorman merged commit bab85e2 into main Aug 19, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add WordPress core integrity and change scanning

1 participant