Topics

On this page

WordPress Core Integrity

From v4.13.1, EasyEngine checks every WordPress core it installs against the official checksums published by WordPress.org. A site goes live only when its core files match.

When EasyEngine checks core

Creating a site

ee site create --type=wp downloads WordPress core in three steps:

  1. It downloads the release package and checks the package’s MD5 checksum.
  2. It unpacks the package with tar or unzip.
  3. It runs wp core verify-checksums on the result.
ee site create example.com --type=wp

This works the same for every locale and WordPress version, including WordPress 7.

If the download or the check fails, EasyEngine stops the create and removes what it made, then shows the error from WP-CLI. It doesn’t retry errors that a retry can’t fix, such as an unknown --version or --locale, or a checksum mismatch.

If WordPress.org’s checksum service can’t be reached, the site is still created and EasyEngine shows this warning:

Could not verify WordPress core checksums

Run the check yourself later (see below).

Restoring a site

ee site restore installs WordPress core the same way. It unpacks the new core into a temporary directory first, and replaces wp-admin and wp-includes only when the unpack succeeds. If the new core can’t be unpacked, the site keeps its existing core.

Upgrading EasyEngine

When you upgrade to v4.13.1 or later with ee cli update, the upgrade verifies WordPress 7 core integrity on existing sites. It runs wp core verify-checksums on each WordPress 7 site and restores any core file that doesn’t match.

Why EasyEngine unpacks core itself

Some WordPress releases, including WordPress 7, contain files with long paths. The stable release of WP-CLI unpacks .tar.gz packages with a PHP function that shortens paths longer than 100 characters. EasyEngine avoids this: WP-CLI downloads and checks the package, EasyEngine unpacks it with the system’s tar or unzip, and the checksum check confirms the result.

Check a site’s core yourself

Run WP-CLI’s checksum check inside the site’s container:

ee shell example.com --command='wp core verify-checksums'

Success: WordPress installation verifies against checksums. means every core file matches the official release.