← Back to blog

File Integrity: How SeenSecure Detects Even the Smallest Line of Code Changed in Your WordPress

Header: how SeenSecure watches every file in your WordPress

Most security plugins only alert you if they detect a known malware signature. SeenSecure goes one step further: it watches every file in your WordPress and alerts you the moment even one of them changes, whether it’s recognized as a threat or not.

Why Detecting Known Malware Isn’t Enough

An attacker who already knows how to evade a malware scanner’s signatures can modify a legitimate file so subtly that no known pattern catches it. The only real way to catch it is to know that file, whatever its content, is no longer the same as it was yesterday.

How SeenSecure’s FIM Works

A baseline of thousands of files

On first activation, SeenSecure calculates the fingerprint (hash) of every WordPress core file, every installed plugin, and every installed theme — thousands of files in total — and stores it as a reference baseline.

Continuous, real-time comparison

From there, it compares that fingerprint continuously. The moment a file changes, it shows up in the dashboard with the exact name, date, and time — no need to wait for a scheduled scan.

You approve or investigate every change

Not every change is an attack. A plugin update also changes files. That’s why every detected change stays pending for review until you decide: approve it (you know it was you, or a legitimate update) or flag it for investigation.

A whitelist for what changes by design

Files that constantly change by their own nature — caches, logs, temporary data — can be fully excluded from monitoring, so real alerts don’t get lost among ones that don’t matter.

SeenSecure real-time log showing a detected and approved file change with its exact timestamp
The FIM real-time log: every change, with its file, timestamp, and who approved it.

A Real Example

In the FIM real-time log, every change is logged with its exact timestamp and who approved it — so there’s a record of whether a change to one of the plugin’s own files was a legitimate update approved on the spot, or something that deserves more attention, instead of getting lost among alerts nobody reviews.

Frequently Asked Questions

How many files does SeenSecure watch?

The entire WordPress core, plus every plugin and theme you have installed — on a mid-sized site, that’s several thousand files watched at once.

What happens if I approve a change by mistake?

Approving a change updates the baseline permanently and can’t be undone from the dashboard — the pending record disappears the moment you approve it. So if you have any doubt about whether a change is legitimate, it’s safer to investigate first than to approve it and ask questions later.

Does it work alongside the malware scanner?

Yes — they’re two independent layers within the same Security Scanner. FIM detects any change; the malware scanner analyzes content for known malicious patterns. Together they cover far more than either one alone.

Want to really protect your WordPress?

Protect your WordPress with 70+ protections: firewall, 6-layer anti-bot, malware scanner, IP management, hardening and automatic backups. FREE plan, free forever.

Create free account →