From v4.13.1, EasyEngine checks every WordPress core it installs against the official checksums published by WordPress.org. A site goes live only when its core files match.
When EasyEngine checks core
Creating a site
ee site create --type=wp downloads WordPress core in three steps:
- It downloads the release package and checks the package’s MD5 checksum.
- It unpacks the package with
tarorunzip. - It runs
wp core verify-checksumson the result.
ee site create example.com --type=wp
This works the same for every locale and WordPress version, including WordPress 7.
If the download or the check fails, EasyEngine stops the create and removes what it made, then shows the error from WP-CLI. It doesn’t retry errors that a retry can’t fix, such as an unknown --version or --locale, or a checksum mismatch.
If WordPress.org’s checksum service can’t be reached, the site is still created and EasyEngine shows this warning:
Could not verify WordPress core checksums
Run the check yourself later (see below).
Restoring a site
ee site restore installs WordPress core the same way. It unpacks the new core into a temporary directory first, and replaces wp-admin and wp-includes only when the unpack succeeds. If the new core can’t be unpacked, the site keeps its existing core.
Upgrading EasyEngine
When you upgrade to v4.13.1 or later with ee cli update, the upgrade verifies WordPress 7 core integrity on existing sites. It runs wp core verify-checksums on each WordPress 7 site and restores any core file that doesn’t match.
- Site content (
wp-content) and the database are not touched. - The check doesn’t load WordPress and can safely run again.
- Disabled sites, stopped sites and sites that can’t be checked are skipped with a warning that shows the command to check them later. The upgrade itself carries on.
Why EasyEngine unpacks core itself
Some WordPress releases, including WordPress 7, contain files with long paths. The stable release of WP-CLI unpacks .tar.gz packages with a PHP function that shortens paths longer than 100 characters. EasyEngine avoids this: WP-CLI downloads and checks the package, EasyEngine unpacks it with the system’s tar or unzip, and the checksum check confirms the result.
Check a site’s core yourself
Run WP-CLI’s checksum check inside the site’s container:
ee shell example.com --command='wp core verify-checksums'
Success: WordPress installation verifies against checksums. means every core file matches the official release.