Security

Detect every unauthorized
file change.

When an attacker compromises a WordPress site, the first thing they do is modify files — injecting backdoors, adding malicious scripts, or altering core files. BlockForge monitors every file across all your installations, creating baselines and alerting you instantly when something changes that shouldn't.

How file-level attacks go unnoticed.

WordPress file systems are complex — thousands of files across core, plugins, themes, and uploads. Attackers exploit this complexity to hide in plain sight, making changes that blend in with legitimate files.

Hidden Backdoors

Attackers inject PHP backdoors in obscure directories that survive plugin updates. Files named wp-cache.php or tucked inside /uploads/ can persist for months without detection.

Core File Tampering

Modified wp-login.php or wp-config.php can silently harvest credentials. These files look normal on the surface but contain injected code that sends login data to external servers.

No Baseline

Without knowing what "normal" looks like, you can't detect what's abnormal. If you've never fingerprinted your file system, any modification — legitimate or malicious — is invisible to you.

Baseline, monitor, alert — automatically.

BlockForge creates a cryptographic fingerprint of every file in your WordPress installations. On each subsequent scan, files are compared against this baseline. New files, modified files, and deleted files are flagged immediately. Core files are also verified against official WordPress.org checksums, ensuring they haven't been tampered with — even if the modification predates your monitoring setup.

  • Baseline snapshot creation
  • Automatic change detection
  • Core file verification against WordPress.org checksums
  • Whitelist rules for legitimate changes
  • Alert on suspicious patterns
  • Full audit trail of every change

File Change Report

7 CHANGES
Modified

/wp-includes/class-wp-query.php

Core mismatch
Added

/wp-content/uploads/2026/wp-cache.php

Suspicious
Modified

/wp-content/plugins/contact-form/readme.txt

Plugin update
Added

/wp-content/uploads/2026/03/header.jpg

Whitelisted
Deleted

/wp-content/plugins/old-plugin/init.php

Plugin removed
Scan completed: 4 min ago 2 alerts · 5 expected changes

Key capabilities.

Complete file system visibility across all your WordPress sites — from baseline creation to real-time change detection and forensic audit trails.

Baseline Snapshots

Create a cryptographic fingerprint of every file in your installation. SHA-256 hashes ensure that even a single byte change is detected. Baselines update automatically after verified legitimate changes.

Change Detection

Automatically detect added, modified, and deleted files between scans. Each change is classified by type and flagged based on risk level — from routine plugin updates to suspicious core modifications.

Core Verification

WordPress core files are verified against official WordPress.org checksums. Any deviation from the official release — even a single injected line — is immediately flagged as a core integrity violation.

Whitelist Rules

Not every change is suspicious. Define whitelist rules for directories, file patterns, and expected changes. Upload directories, cache files, and known modification patterns are filtered to reduce noise.

Pattern Alerts

Intelligent alerting based on suspicious patterns — PHP files in upload directories, modified core files, new executable files in unexpected locations. Get notified about what matters, not routine changes.

Audit Trail

Every detected change is recorded with timestamps, file hashes, and classification. Build a complete forensic timeline for incident investigation or compliance reporting — searchable and exportable.

Related security features.

File integrity monitoring works best alongside vulnerability scanning, malware detection, and configuration snapshots for layered WordPress security.

Monitor every file. Detect every change.

Start monitoring your WordPress file systems today. Free plan includes 3 sites.