Hello,
Wordfence has been finding some issues on some of my sites, but how do I know they aren’t part of the theme or something? Is there a resource for that? I tried having Wordfence remove the files on one of my sites, but it broke the site. For example,
Filename: wp-includes/post.php
File Type: Core
Details: This file appears to be installed or modified by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The text we found in this file that matches a known malicious file is: include_once(dirname(FILE) . ‘/wp-vcd.php’). The infection type is: A backdoor known as WP-VCD.
That’s just one of 8 or so. Any direction is much appreciated!