Theme integrity monitoring
WordPress core and wp.org plugins have official checksums — your theme doesn't, and a dropped malware file is in no checksum manifest at all. Relvato closes both gaps: it self-baselines your active theme's code and watches the places attackers drop executables, so a tampered checkout template or a planted webshell is caught even when signature scanners miss it.
- ✓Active theme PHP & JS files match your approved baseline
- ✓A modified WooCommerce checkout-template override (woocommerce/**) is flagged as high-risk
- ✓A newly dropped executable .php in uploads, mu-plugins or wp-content is flagged
- ✓Added or removed theme files surfaced to review
- ✓Approve an intentional edit to re-baseline — no repeat noise
In real WooCommerce skimmer attacks, two steps leave no trace a checksum scan can see: the attacker modifies a checkout-template override (e.g. woocommerce/checkout/form-billing.php) to harvest card data, and drops a malware file that belongs to no plugin or core. Theme integrity is the tripwire for exactly those moves — a change since your approved baseline, flagged in minutes.
Works on any WordPress or WooCommerce site.
- On the first scan, the Relvato plugin hashes your active theme's PHP & JS files plus any stray .php in mu-plugins, uploads and wp-content — and you approve that as the baseline.
- Every later run re-hashes and diffs against the baseline, so a modified, added, removed or newly-dropped file stands out immediately.
- You get the exact file paths — approve an intentional edit to re-baseline, or investigate a change you didn't make.
How is this different from the file-integrity scan?
File integrity compares WordPress core and wp.org plugin files against their OFFICIAL published checksums — it can only see files a manifest already lists. Theme integrity uses a baseline you approve, so it also covers your theme (which has no official checksums) AND detects ADDED files that are in no manifest, like a dropped webshell.
Won't legitimate theme edits keep flagging?
No — when you make an intentional change you approve it and Relvato re-baselines, so it won't flag again. Routine theme edits show as a review (a warning); only a dropped executable or a modified checkout template hard-fails the run.
What if my site is already compromised at the first scan?
A self-captured baseline can only detect changes AFTER it's approved, so a first scan on an already-hacked site would baseline the bad file as expected — the same limit as any baseline. To mitigate, Relvato surfaces any .php sitting in your uploads folder even at baseline time, since code doesn't belong there.
Does it need the plugin?
Yes — theme integrity reads the file hashes through the Relvato plugin (1.4.0+), so it's WordPress-only.
Put this check on autopilot.
Free while you set it up — 100 checks or 30 days. No card, no sales call.