• Resolved Vunderbar

    (@vunderbar)


    Hi WF Team,

    Working on a site that has been updated to 7.0.1. A current Scan has been showing 21 Results, all with the following same message which appear to be related to a previous version. Thought these would have cleared after the update, but nope, they’re still there.

    With options of Ignore, Delete File or Mark as Fixed … what to do? Are these harmless leftovers that can be deleted? Any insight, suggestions?

    Items

    Unknown file in WordPress core: wp-includes/php-ai-client/third-party/Http/Discovery/Strategy/CommonPsr17ClassesStrategy.p

    Unknown file in WordPress core: wp-includes/php-ai-client/third-party/Http/Discovery/Exception/StrategyUnavailableExceptio

    Unknown file in WordPress core: wp-includes/php-ai-client/third-party/Http/Discovery/Exception/PuliUnavailableException.ph

    Unknown file in WordPress core: wp-includes/php-ai-client/third-party/Http/Discovery/Exception/NoCandidateFoundException.p

    Unknown file in WordPress core: wp-includes/php-ai-client/third-party/Http/Discovery/Exception/DiscoveryFailedException.ph

    Unknown file in WordPress core: wp-includes/php-ai-client/third-party/Http/Discovery/Exception/ClassInstantiationFailedExc

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/OpenAiCompatibleImplementation/AbstractOpenAiCompa

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/VideoGenerationOp

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/Models/VideoGeneration/Contracts/VideoGenerationMo

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/Models/TextToSpeechConversion/Contracts/TextToSpee

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/TextGenerationOper

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/Models/TextGeneration/Contracts/TextGenerationMode

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/Models/SpeechGeneration/Contracts/SpeechGeneration

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/ImageGenerationOp

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/Models/ImageGeneration/Contracts/ImageGenerationMo

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/Http/Contracts/WithRequestAuthenticationInterface.

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/Contracts/ProviderWithOperationsHandlerInterface.p

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/AbstractApiBasedModelMetada

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/Contracts/ApiBasedModelInte

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/ListModelsApiBasedProviderA

    Unknown file in WordPress core: wp-includes/php-ai-client/src/Providers/ApiBasedImplementation/GenerateTextApiBasedProvide

    Type: File
    Issue Found Jul 15, 2026 1:17 AM
    High
    File Type: Core
    ◇ Details: This file is in a WordPress core location but is not distributed with this version of WordPress. This scan often includes files left over from a previous WordPress version, but it may also find files added by another plugin, files added by your host, or malicious files added by an attacker. Learn More

    PS – already checked with the host provider, and they recommended contacting the plugin provider.

Viewing 9 replies - 1 through 9 (of 9 total)
  • Plugin Support wfpeter

    (@wfpeter)

    Hi @vunderbar, thanks for getting in touch!

    It’s my understanding that these are new WordPress core files rather than leftovers from a previous version. Having said that, I’d not expect them to be unknown during your scan unless your Wordfence plugin is either having trouble communicating to our servers to update, or the scan took place before they were cached in our copy of the repository.

    I’d ensure Wordfence is on the latest version, then go to Wordfence > All Options > Advanced Firewall Options > Manually Refresh Rules and run a fresh scan. If the results still appear after that, use Ignore (until file changes).

    Let us know how you get on,
    Peter.

    Thread Starter Vunderbar

    (@vunderbar)

    Hey Peter,

    Thanks for the quick reply. WF is up to date (8.2.2), and WP was also just updated again this morning to 7.0.2. Ran a scan this morning after the update … same 21 results / files still showing.

    Just did the “Manual Refresh Rules”, ran the scan again and … they’re still there. Go figure.

    Guess I’ll just have to put them on Ignore for now.

    Plugin Support wfpeter

    (@wfpeter)

    Hi @vunderbar, thanks for letting me know.

    I’ve just realized that the filenames mentioned are cut off in your original post. At first look, I thought it might be a copy/paste or forum formatting issue rather than the cause of the scan result.

    I’ve seen this once before where a migration or backup/restore plugin caused some of the filenames to be truncated in longer paths. These php-ai-client paths are some of the longest in WordPress core and it looks like that may have happened here.

    Reverting to the original filenames would likely cause this scan result to be resolved.

    Thanks again,
    Peter.

    Thread Starter Vunderbar

    (@vunderbar)

    Hi Peter,

    Bingo – that’s got it!

    Good on you for remembering the previous case and catching that.

    As these were all files under an “AI” folder, I’m going to score one for the humans. (Hey, gotta do it while we still can, hah!)

    Funny thing, I also found duplicates in those folders of previous versions of those files from Feb. 20 and March 11. So deleted the renamed truncated new versions and restored the old ones (which I had originally deleted in the first go-round, which didn’t work) and … all cleared up now.

    Thanks – have a great day. 🙂

    Plugin Support wfpeter

    (@wfpeter)

    Absolutely, we’ll take this one for the humans. It’s great news that’s resolved it, as Wordfence would let you know if the contents of the files looked altered once the filenames were back to the defaults.

    I’ll mark this as resolved, but feel free to start a new topic any time if you have further questions about Wordfence in the future.

    Thanks again,
    Peter.

    same issue here, on two separate sites. What is the solution? Delete the files?

    Thread Starter Vunderbar

    (@vunderbar)

    Hey Accuran,

    1 – check the path of each item in your WF Scan results (cPanel > File Manager) . Probably easier to copy / paste them (depending on how many) into a document, one to a line, for easier readability

    2 – use the link Peter provided (original filenames) to search through the folders and subfolers for the original source files and compare the end of each filename

    3 – if there are duplicates in your folders (like I had), decide which to delete

    (I deleted the newer ones, which may or may not matter. I also added an “N-” to the front of the filename before deleting to distingush them from the older ones for an easier Restore from the Trash just in case. Depends on how full your trash is.)

    4 – rename the files in your list by adding back the end portions that were truncated (double & triple check spelling and capitilization, that one caught me on a few with the “i”s)

    5 – run a WF Scan again – issues should go away

    Thanks @vunderbar for the suggestion. Seems like a lot of effort so I just hit the Delete All Deletable files button (as I had done on the previous site where I encountered this issue. Since that php-ai-client folder is new, I assume there’s noting essential in there anyway unless one is using the new AI features.

    Thread Starter Vunderbar

    (@vunderbar)

    Hah! I like that solution, esp. considering it’s a bunch of AI nonsense. I thought of that as well … after I’d already gone through the process. They’ll probably all be replaced with the next update anyway. Maybe.

    You’re right though, it was a tedious process. So if nothing “borked” … good call. And another option for anyone else that has to deal with it.

Viewing 9 replies - 1 through 9 (of 9 total)

You must be logged in to reply to this topic.