WordPress File Integrity Monitoring: Know Which Changes Are Expected—and Which Need Investigation
Aegisify Shield combines broad integrity scanning, lightweight file-change monitoring, and a focused Critical Files workflow so WordPress administrators can detect unexpected changes, compare them with trusted baselines, and investigate high-value files without automatically rewriting production code.
Move From Change Detection to Evidence-Based Review
The current Shield implementation uses separate layers because a full-site scan and a high-frequency watchlist solve different operational problems.
Click a stage
01EstablishReview a trusted state
02ScanLight, Hybrid, Full
03WatchRecent file changes
04PrioritizeCritical Files
05VerifyDiff + correlate
File Integrity Is Now a Three-Layer Security Workflow
The current page is significantly deeper than basic checksum monitoring.
Light, Hybrid, and Full Scan Modes
Use Light for faster high-value review, Hybrid for routine balanced coverage, or Full for broader baselining and incident work. Automatic frequency options support recurring daily, weekly, or monthly checks, with severity-aware findings and configurable history retention.
Four Integrity Dashboards
Threat Trend tracks High and High+Medium findings across recent scans. Latest Severity Breakdown shows issue distribution. Latest Scan Findings summarizes modified, new, and error counts. File Changes visualizes new, modified, and deleted activity across the last seven days.
Critical Files Watchlist
Critical Files concentrates on sensitive WordPress configuration, core bootstrap files, auto-loaded execution surfaces, and executable-like files found in writable site locations. Because the watchlist is intentionally smaller, it can run at shorter intervals such as 5, 10, or 15 minutes.
Protected Snapshots and On-Demand Diffs
Critical Files can maintain protected baseline snapshots and compare them with current live files. The workflow includes baseline status, checksum state, severity, approval state, investigation state, change timestamps, and on-demand line-level differences.
wp-config.php, supported secret values are redacted from the diff view. The goal is to provide useful evidence without unnecessarily exposing sensitive configuration values to the administrator interface.Prioritize the Files That Can Change WordPress Behavior Fast
Not every file has the same operational impact. Critical Files reduces the search space when high-value execution or configuration surfaces change.
High-Value WordPress Files
The watchlist can include files such as wp-config.php, parent-location configuration, .htaccess, web.config, and core bootstrap locations where an unexpected change can alter execution, routing, credentials, or application behavior.
Executable-Like Files Where They Should Not Be
Aegisify can surface executable-like files discovered in writable directories as investigation findings. This is useful because writable content locations can become persistence or payload locations after a compromise.
WordPress Core Checksum Context
Where applicable, Critical Files can include official WordPress core checksum context. A checksum mismatch does not explain intent by itself, but it provides another signal when validating whether a core file matches the expected distribution.
Approve or Mark for Investigation
After review, administrators can approve verified changes, refresh the baseline, or mark an unexplained file for investigation. CSV export and Activity Log correlation help preserve evidence when the review must continue outside the immediate screen.
Reduce Time Between Unauthorized Change and Human Review
Traditional periodic scans can leave a long gap between the moment a file changes and the moment an administrator notices it. Aegisify closes that gap by combining scheduled integrity scans, a more frequent File Change Monitor, and an even more focused Critical Files watchlist.
The improvement is operational: teams can see a burst of changes after a deployment, verify whether those files match the approved release, and investigate anything outside the expected scope. If a sensitive configuration file changes at an unusual time, the difference and surrounding Activity Log events provide a stronger starting point than a generic “file changed” alert.
File Change Monitor adds another useful layer for active sites. Supported intervals include 5, 10, 15, 30, and 60 minutes, while subscription controls can add custom paths, directory exclusions, email recipients, and alert conditions. This lets teams watch important application paths more frequently without forcing a broad full-site scan every few minutes. The security gain comes from shortening detection time while keeping high-churn directories from overwhelming the evidence.
Baseline Quality Matters More Than Baseline Speed
Start From a State You Trust
Apply approved updates, validate the application, and resolve known compromise indicators before creating a baseline. Baseline data created on a compromised site can make malicious files appear normal later.
Exclude High-Churn Noise Deliberately
Cache, session, temporary, backup, and generated-asset locations can change constantly. Monitor them only when there is a clear security reason so meaningful changes remain visible.
Correlate Before You Approve
Match the timestamp with an update, deployment, restore, administrator action, login event, malware finding, or maintenance window. Do not refresh a baseline simply to make an alert disappear.
Escalate Unexplained Changes
Preserve evidence, restrict privileged access when necessary, review malware and login activity, and use a tested recovery process if the change cannot be tied to legitimate work.
Start Monitoring the Files That Define Your WordPress Site
Configure a broad integrity baseline, then use File Change Monitor and Critical Files to shorten the time between change and review.
Common Questions
Does Aegisify automatically repair changed files?
No. File Integrity is designed for detection and investigation. It does not automatically rewrite production files simply because a change was detected.
What is the difference between File Change Monitor and Critical Files?
File Change Monitor provides broader recurring change visibility. Critical Files uses a smaller, higher-value watchlist with protected baselines, checksum context, diffs, severity, and investigation actions.
Should I approve every change after a plugin update?
No. First confirm the timing, expected file scope, application behavior, and related events. Approve or refresh the baseline only after the change is understood.
How can Aegisify AI help?
Ask about Aegisify or WordPress: errors, plugins, security, SEO, compatibility, troubleshooting, comparisons, or launch a free website scan.
