How to know if Wordfence scan issues are legitimate?

Hello,

Wordfence has been finding some issues on some of my sites, but how do I know they aren’t part of the theme or something? Is there a resource for that? I tried having Wordfence remove the files on one of my sites, but it broke the site. For example,

Filename: wp-includes/post.php
File Type: Core
Details: This file appears to be installed or modified by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The text we found in this file that matches a known malicious file is: include_once(dirname(FILE) . ‘/wp-vcd.php’). The infection type is: A backdoor known as WP-VCD.

That’s just one of 8 or so. Any direction is much appreciated!

Hi There,

Thank you for writing in, you can manually check the said malicious files and compare it to that same file in a fresh copy of WordPress.

To play on the safe side, you can replace those said malicious files with the fresh copy from WordPress, and don’t download WordPress and Themes from third-party sites.

Please contact the Wordfence support as well, they might have a better solution regarding this.

Cheers!

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.