IntegriFix – File Integrity Check & Repair

Description

IntegriFix compares each file of WordPress, of your plugins and of your themes with the version published on WordPress.org for the exact version you have installed, and looks at the places that no official copy covers.

What it finds

  • WordPress files that were modified, added or deleted.
  • Plugin and theme files that differ from their official version, including files that should not be there.
  • Code where code never belongs: PHP files in your media library, PHP hidden inside images, translation files that run code, code files in folders next to WordPress (a favourite hiding place for intruders’ tools).
  • Dangerous settings: a wp-config.php that runs code, .htaccess rules that send search engines elsewhere, a PHP setting that loads a file before every page.
  • A security plugin that is still active but whose files have disappeared.

Premium and custom plugins cannot be compared with WordPress.org. IntegriFix takes a snapshot of each plugin and theme when WordPress installs or updates it, and uses it as the reference for later scans.

Repair, one point at a time, and undo

When the official copy is known, IntegriFix can put things right for you, one point at a time and only when you ask:

  • Replace a modified WordPress, plugin or theme file with its official copy from WordPress.org, or put back an official file that was deleted.
  • Set aside (“quarantine”) a code file that has nothing to do where it is, such as PHP in your media library.
  • Reinstall from WordPress.org an active plugin whose files have disappeared.

Before anything is written, the official copy is checked against its published checksum and the current file is copied to the database (kept 30 days). The file is then checked again, and the previous state is put back if it does not match. Each repair can be undone in one click, as long as the file has not changed since. Configuration files (wp-config.php, .htaccess…) are never changed automatically, nothing is written when your site forbids file changes (DISALLOW_FILE_MODS), and a repair is offered only to people allowed to update WordPress, plugins or themes (and to install plugins, for a reinstallation).

Every repair is available in this plugin, without limit. IntegriFix Pro, a separate paid add-on, repairs several points at once.

Automatic scans and e-mail alerts

IntegriFix checks your site on its own every week (or every day), in short steps in the background with the scheduled tasks of WordPress (WP-Cron), and e-mails the administration address when a new problem appears: a point that needs your attention or deserves a look and that the previous scan did not find. One e-mail per scan, in plain words, with a link to the results and without the names or the content of your files. The frequency and the addresses can be changed in the settings, and the automatic scans or the e-mail turned off.

Built to avoid false alarms

  • Always the reference of the installed version, never “the latest”.
  • Localised WordPress builds, bundled themes, translation files and files transferred by FTP in text mode are recognised.
  • Each finding says what happens, why it matters and what to do.

For developers

  • wp integrifix scan and wp integrifix verify core|plugin|theme for WP-CLI.
  • A JSON report for your own tools.

External services

IntegriFix needs the official reference of each file. It connects only to WordPress.org, and only while a scan runs (started by you or automatic), when you open the comparison of a file or when you ask for a repair:

  • api.wordpress.org — checksums of WordPress core. Sent: the WordPress version and the language of your installation.
  • api.wordpress.org — whether WordPress.org hosts an active plugin whose files are missing, so that its reinstallation can be offered. Sent: the folder name of that plugin.
  • downloads.wordpress.org — checksums and packages of plugins and themes, and the package of a plugin you ask to reinstall. Sent: the folder name and version of each installed plugin and theme.
  • core.svn.wordpress.org, plugins.svn.wordpress.org, themes.svn.wordpress.org — the official copy of a single file, to show you what changed or to repair it. Sent: the path of that file and the version of its plugin, theme or WordPress.

No data about your site, your visitors or your content is sent: not even its address, since these requests go through IntegriFix’s own HTTP client, which identifies itself only as IntegriFix and its version. These requests are covered by the WordPress.org privacy policy: https://wordpress.org/about/privacy/

The alert e-mail of the automatic scans is sent by your site itself, with the WordPress mail function (wp_mail), to the addresses set in the IntegriFix settings; nothing is sent to IntegriFix or to any other service.

Screenshots

FAQ

Does “no problem found” mean my site is safe?

It means every file that has an official reference matches it and no known warning sign was found. Software running on a server that has been compromised can be deceived; for a check from outside, use the IntegriFix rescue tool.

Where do I find the rescue tool?

The rescue tool runs the same checks without WordPress, from the command line of your server. Its instructions are at https://integrifix.fr/en/rescue (in French: https://integrifix.fr/secours). It is meant for your provider or developer, when the site is unreachable or its results cannot be trusted.

What is IntegriFix Pro?

A separate plugin, paid once per site, with no subscription. This plugin is complete without it: every scan, finding, comparison and repair is available here, without limit, and nothing is locked.

IntegriFix Pro adds:

  • Grouped repair: every file that can get its official version back is repaired in one action, with the same checks and a single undo.
  • The rescue tool in the browser, which also repairs, for when the administration no longer opens.
  • Updates from the Plugins screen, and support by e-mail.

This plugin never downloads or installs IntegriFix Pro. After buying it at https://integrifix.fr/pro, you download its zip file with your licence key and upload it yourself (Plugins › Add New Plugin › Upload Plugin). IntegriFix Pro contacts IntegriFix’s licence server; this plugin contacts only WordPress.org. The IntegriFix Pro tab and suggestions can be turned off in the IntegriFix settings.

Which languages are available?

English and French.

Does IntegriFix slow down my site?

No. No page of your visitors waits for a scan. A scan runs in short steps: when you start it, from the IntegriFix screen or WP-CLI, and in the background through the scheduled tasks of WordPress (WP-Cron) for the automatic scans, every week by default. You can make them daily or turn them off in the IntegriFix settings. The other background task is a daily cleanup of expired backups and references.

When do I get an e-mail?

When an automatic scan finds a point that needs your attention or deserves a look and that the previous scan did not find, one e-mail per scan, sent to the administration address of the site unless you set other addresses. Points you chose to ignore and points of low importance never send an e-mail, and a scan you start yourself sends none: you see its result on the screen.

Does it work on multisite?

Yes. IntegriFix is activated for the whole network and appears in the network admin, for super admins only: the files of WordPress, plugins and themes are shared by all the sites of the network.

Why doesn’t IntegriFix use the WordPress HTTP functions?

It calls the Requests library bundled with WordPress directly, so that no other plugin can intercept the checksums IntegriFix compares your files with.

What happens to my files?

A scan only reads them. A file changes only when you ask for a repair: IntegriFix then keeps a copy of it in the database for 30 days, so that you can undo the repair.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“IntegriFix – File Integrity Check & Repair” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

0.1.3

  • Automatic scans, every week by default (or every day, or off), run in short steps by WP-Cron with the same checks as the screen; an automatic scan waits for a scan you started, and is given up cleanly after repeated failures, which the dashboard shows.
  • An e-mail when an automatic scan finds a new point that needs your attention or deserves a look: one per scan, in the language of the site, without the names or the content of your files, to the administration address or the addresses you choose. A test e-mail can be sent from the settings.
  • The dashboard, the WordPress dashboard box and the settings show the last and the next automatic scan; the introduction offers the frequency.

0.1.2

  • New “IntegriFix Pro” tab after Settings: what the separate paid plugin adds, what stays free and how to get it. It sends no request to any server and can be turned off in the settings, with the other suggestions.
  • The IntegriFix Pro suggestion above the results says how many files could be repaired at once; the guided mode shows one line with the same conditions. “Hide” hides both for good.
  • Nothing mentions IntegriFix Pro while it is active. Links to integrifix.fr follow your language.

0.1.1

  • Fix: a redirect to the site’s own address in .htaccess (HTTP to HTTPS, adding www) is no longer reported as cloaking; the lines shown include the browser conditions.
  • A scan that stops shows the server’s answer in its technical details (status, error code, message), and the first step says what it does.

0.1.0

  • First version: scan of core, plugins, themes and sensitive files, readable comparison with the official copy, WP-CLI commands.
  • Repair of one point at a time from WordPress.org (official copy, missing file, quarantine, plugin reinstallation), with a 30-day backup and a one-click undo.