=== ABC Integrity ===
Contributors: abcdrew
Tags: security, integrity, checksums, malware, verification
Requires at least: 6.4
Tested up to: 7.1
Requires PHP: 8.1
Stable tag: 1.0.3
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Detect modified, missing, or tampered WordPress core files by comparing them against the official checksums published by WordPress.org.

== Description ==

ABC Integrity checks each WordPress core file against the official checksums published by WordPress.org. After a scan, any file that has been modified, is missing, or cannot be read is flagged in the dashboard — so you can catch tampering, accidental edits, or signs of a compromised site before they become a bigger problem.

**Features**

* One-click scan — no configuration required
* Detects modified, missing, and unreadable core files
* Automatically re-fetches checksums when WordPress is updated
* Lightweight: scans run on demand, not in the background
* Plugin and theme files are not checked (core files only)

== External Services ==

ABC Integrity connects to the WordPress.org Core Checksums API when an administrator runs a core file scan. The request sends the site's WordPress version and locale so WordPress.org can return the matching official checksum manifest.

Service: https://api.wordpress.org/core/checksums/1.0/
Terms: https://wordpress.org/about/terms/
Privacy: https://wordpress.org/about/privacy/

== Installation ==

1. Install and activate the plugin through the WordPress Plugins screen.
2. Navigate to **ABC Integrity** in the admin menu and click **Scan core files**.

== Frequently Asked Questions ==

= Does this plugin check plugin or theme files? =

No. ABC Integrity only checks WordPress core files. Plugin and theme files are not scanned.

= What does it mean if a file is flagged as modified? =

It means the file on your server doesn't match the official WordPress checksum for that file. This could be intentional (a manual edit), accidental, or a sign that your site has been compromised. You should investigate any flagged file and restore it from an official WordPress release if you didn't make the change yourself.

= Does running a scan slow down my site? =

No. Scans run only when you click the button in the dashboard — there is no background processing, scheduled scanning, or impact on front-end page load.

= How does the plugin get the checksums? =

When you run a scan, the plugin fetches the official checksum manifest from the WordPress.org Core Checksums API (`api.wordpress.org`), matching your exact WordPress version and locale. The manifest is cached and automatically refreshed when WordPress is updated.

== Changelog ==

= 1.0.3 =
* Added quick access to core scans from the Plugins screen and reminders to rescan after WordPress core updates.
* Improved scan accessibility and the admin layout on narrow screens.
* Added clearer errors when WordPress.org checksums are unavailable.
* Clarified that file changes are reported after a scan.

= 1.0.2 =
* Explains when a new scan is needed after WordPress core is updated.
* Confirmed compatibility with WordPress 7.1.

= 1.0.1 =
* Improved admin scan button behavior after failed scan attempts.
* Maintenance updates for the WordPress.org package.

= 1.0 =
* Initial release.
