Aegisify company logo
File Integrity2026-08-12T13:26:01+00:00
Aegisify Shield — File Integrity

WordPress File Integrity Monitoring: Know Which Changes Are Expected—and Which Need Investigation

Aegisify Shield combines broad integrity scanning, lightweight file-change monitoring, and a focused Critical Files workflow so WordPress administrators can detect unexpected changes, compare them with trusted baselines, and investigate high-value files without automatically rewriting production code.

A changed file is not automatically malicious. An unexplained change is still a security question.Updates, deployments, cache generation, backup restores, and attackers can all modify files. Aegisify helps separate normal operational change from activity that deserves verification.
1BaselineKnown-good state
2DetectNew + modified files
3VerifyDiff + investigate
Integrity Workflow

Move From Change Detection to Evidence-Based Review

The current Shield implementation uses separate layers because a full-site scan and a high-frequency watchlist solve different operational problems.

Click a stage

01EstablishReview a trusted state
Update through an approved maintenance process, confirm the site is behaving normally, run the selected scan, and create baselines only after the result is understood.
02ScanLight, Hybrid, Full
Choose a performance-aware scan mode appropriate to routine review, balanced coverage, or broader investigation.
03WatchRecent file changes
File Change Monitor tracks new, modified, and deleted files between broader integrity scans and can use shorter recurring intervals.
04PrioritizeCritical Files
High-value configuration, bootstrap, core, and writable execution surfaces receive a dedicated watchlist, severity, checksum context, and investigation workflow.
05VerifyDiff + correlate
Compare the protected baseline snapshot with the live file, review Activity Log context, and approve only changes that are understood and authorized.
What Changed in Shield 7.4.5

File Integrity Is Now a Three-Layer Security Workflow

The current page is significantly deeper than basic checksum monitoring.

Broad Integrity

Light, Hybrid, and Full Scan Modes

Use Light for faster high-value review, Hybrid for routine balanced coverage, or Full for broader baselining and incident work. Automatic frequency options support recurring daily, weekly, or monthly checks, with severity-aware findings and configurable history retention.

Visual Intelligence

Four Integrity Dashboards

Threat Trend tracks High and High+Medium findings across recent scans. Latest Severity Breakdown shows issue distribution. Latest Scan Findings summarizes modified, new, and error counts. File Changes visualizes new, modified, and deleted activity across the last seven days.

Focused Protection

Critical Files Watchlist

Critical Files concentrates on sensitive WordPress configuration, core bootstrap files, auto-loaded execution surfaces, and executable-like files found in writable site locations. Because the watchlist is intentionally smaller, it can run at shorter intervals such as 5, 10, or 15 minutes.

Evidence Review

Protected Snapshots and On-Demand Diffs

Critical Files can maintain protected baseline snapshots and compare them with current live files. The workflow includes baseline status, checksum state, severity, approval state, investigation state, change timestamps, and on-demand line-level differences.

Security-minded detail: when Aegisify displays a Critical Files difference for wp-config.php, supported secret values are redacted from the diff view. The goal is to provide useful evidence without unnecessarily exposing sensitive configuration values to the administrator interface.
Critical Files

Prioritize the Files That Can Change WordPress Behavior Fast

Not every file has the same operational impact. Critical Files reduces the search space when high-value execution or configuration surfaces change.

Configuration

High-Value WordPress Files

The watchlist can include files such as wp-config.php, parent-location configuration, .htaccess, web.config, and core bootstrap locations where an unexpected change can alter execution, routing, credentials, or application behavior.

Writable Surfaces

Executable-Like Files Where They Should Not Be

Aegisify can surface executable-like files discovered in writable directories as investigation findings. This is useful because writable content locations can become persistence or payload locations after a compromise.

Validation

WordPress Core Checksum Context

Where applicable, Critical Files can include official WordPress core checksum context. A checksum mismatch does not explain intent by itself, but it provides another signal when validating whether a core file matches the expected distribution.

Workflow

Approve or Mark for Investigation

After review, administrators can approve verified changes, refresh the baseline, or mark an unexplained file for investigation. CSV export and Activity Log correlation help preserve evidence when the review must continue outside the immediate screen.

Customer Security Posture

Reduce Time Between Unauthorized Change and Human Review

Traditional periodic scans can leave a long gap between the moment a file changes and the moment an administrator notices it. Aegisify closes that gap by combining scheduled integrity scans, a more frequent File Change Monitor, and an even more focused Critical Files watchlist.

The improvement is operational: teams can see a burst of changes after a deployment, verify whether those files match the approved release, and investigate anything outside the expected scope. If a sensitive configuration file changes at an unusual time, the difference and surrounding Activity Log events provide a stronger starting point than a generic “file changed” alert.

File Change Monitor adds another useful layer for active sites. Supported intervals include 5, 10, 15, 30, and 60 minutes, while subscription controls can add custom paths, directory exclusions, email recipients, and alert conditions. This lets teams watch important application paths more frequently without forcing a broad full-site scan every few minutes. The security gain comes from shortening detection time while keeping high-churn directories from overwhelming the evidence.

Practical result: more focused change detection, clearer baselines, faster investigation, and less risk of normal WordPress churn obscuring a high-impact modification. Teams also gain a repeatable record of what was reviewed, accepted, or escalated.
How to Operate File Integrity Safely

Baseline Quality Matters More Than Baseline Speed

01

Start From a State You Trust

Apply approved updates, validate the application, and resolve known compromise indicators before creating a baseline. Baseline data created on a compromised site can make malicious files appear normal later.

02

Exclude High-Churn Noise Deliberately

Cache, session, temporary, backup, and generated-asset locations can change constantly. Monitor them only when there is a clear security reason so meaningful changes remain visible.

03

Correlate Before You Approve

Match the timestamp with an update, deployment, restore, administrator action, login event, malware finding, or maintenance window. Do not refresh a baseline simply to make an alert disappear.

04

Escalate Unexplained Changes

Preserve evidence, restrict privileged access when necessary, review malware and login activity, and use a tested recovery process if the change cannot be tied to legitimate work.

Build a Trusted Baseline

Start Monitoring the Files That Define Your WordPress Site

Configure a broad integrity baseline, then use File Change Monitor and Critical Files to shorten the time between change and review.

File Integrity FAQ

Common Questions

Does Aegisify automatically repair changed files?

No. File Integrity is designed for detection and investigation. It does not automatically rewrite production files simply because a change was detected.

What is the difference between File Change Monitor and Critical Files?

File Change Monitor provides broader recurring change visibility. Critical Files uses a smaller, higher-value watchlist with protected baselines, checksum context, diffs, severity, and investigation actions.

Should I approve every change after a plugin update?

No. First confirm the timing, expected file scope, application behavior, and related events. Approve or refresh the baseline only after the change is understood.

Detect Change. Verify Intent.

Make File Integrity Part of Daily WordPress Security

Aegisify Shield gives administrators multiple layers of file-change evidence so unexpected modifications can be investigated before they become forgotten history.