W
Security Free WordPress.org

WP Fingerprint

3.0 (2 reviews)
· 9K+ active installs · By DanFoster
Active Installs
9K+
Rating
3.0 / 5
Version
v2.1.2
Last Updated
Sep 2025
Share

Plugin Review

AI-Researched

What is WP Fingerprint?

WP Fingerprint is a WordPress security plugin focused on file verification. It checks your plugins for signs of a hack or exploit by comparing their checksums against a remote database. The plugin was created by developer DanFoster and has been available for 8 years. It currently holds 9K+ active installs. Its rating stands at 3.0/5 from 2 ratings, with a split of 50% 50% one-star reviews. The latest version is 2.1.2, last updated on Sep 3, 2025.

The plugin transmits SHA-1 checksums of your plugin files to servers hosted in the EU by 34SP.com. It compares these against its own collected checksums to identify abnormalities. This process helps you perform a checksum wordpress verification on your site’s plugins. For premium plugins, WP Fingerprint uses crowdsourced checksums, while plugins from WordPress.org are checked directly against the official repository.

Key Features of WP Fingerprint

  • Automated SHA-1 Checksum Generation: The plugin scans every file inside each plugin folder and creates a SHA-1 checksum for it, then sends this data to remote servers for validation.
  • Remote Checksum Comparison: Collected checksums are compared against a database on WP Fingerprint servers to detect if any plugin file has been altered without authorization.
  • Plugin Version Tracking: Alongside checksums, the plugin captures basic plugin information like version numbers to ensure the checksum matches the correct release.
  • Core File Monitoring: When WordPress core files change, the scanner verifies them to catch exploits that target the core system directly.
  • Premium Plugin Support: For commercial plugins not in the WordPress.org repository, WP Fingerprint relies on a crowdsourced network to provide correct checksums for verification.
  • Admin Menu Indicator: After installation, a dedicated "WP Fingerprint" heading appears in the top admin menu bar, confirming the plugin is active and running scans.
  • EU-Based Data Storage: All checksum data is stored on servers operated by 34SP.com within the European Union, addressing some data residency concerns.

Who Should Use WP Fingerprint?

This tool suits site owners who need a wordpress plugin integrity check without manual file comparisons. It is built for administrators who manage multiple plugins and want an automated way to detect hacked plugin files wordpress. With 9K+ users, it targets a niche audience that values an extra security layer beyond standard firewalls. The plugin is simple enough for beginners, as it runs scans automatically after activation.

If you run a site with many third-party plugins, WP Fingerprint can help you check if wordpress plugin has been modified by an attacker. It is especially useful for sites that cannot use heavy security suites. The 8-year development history suggests a stable, if not frequently updated, codebase. However, the low rating of 3.0/5 indicates mixed user satisfaction with its reliability or performance.

Installation & Setup

You can install WP Fingerprint directly from the WordPress admin plugins menu. It requires WordPress 4.9+ and PHP 5.6 or higher, and has been tested up to WordPress 6.8.5. Setup is straightforward for beginners—once activated, the plugin runs immediately and adds a "WP Fingerprint" link to the top admin bar. No complex configuration is needed to start the initial scan.

Support & Community

Support data reveals a concerning picture. Over the last 2 months, the plugin has recorded 0 open support threads and 0 resolved threads, resulting in a 0% resolution rate. This suggests either very few users are seeking help, or support requests are not being tracked. The rating breakdown—50% 50% one-star—shows a polarized user base. Half of the reviewers found the plugin effective, while the other half experienced significant issues. With only 2 total ratings, the sample size is small, but the split is stark.

The developer, DanFoster, has maintained the plugin for 8 years but last updated it on Sep 3, 2025. The lack of recent support activity may be a concern for users who need assistance with the checksum wordpress process or troubleshooting false positives. Potential users should weigh the automated security benefit against the limited community backing when deciding how to check plugin integrity in wordpress.

Pros & Cons

What's Good
  • With 9K+ active installs, WP Fingerprint provides a dedicated checksum comparison service that alerts you to plugin file changes indicative of hacks or exploits.
  • It stores and compares plugin checksums on EU-hosted servers (by 34SP.com) and WordPress.org, offering an off-site verification layer independent of your own server.
  • The plugin’s 50% five-star rating from its 2 total ratings suggests that half of reviewers found it effective for its stated security purpose.
  • It focuses specifically on plugin integrity, a targeted approach that can catch unauthorized modifications without scanning the entire site.
  • The plugin transmits and stores checksums externally, which can help detect tampering even if your local files have been compromised.
Drawbacks
  • With 50% one-star ratings from only 2 total ratings and 0 resolved support threads out of 0 total, user satisfaction and support availability are highly questionable.
  • The plugin requires transmitting and storing plugin checksums on external servers, which may raise privacy concerns for site owners sensitive to data leaving their infrastructure.
  • Its utility depends entirely on the accuracy and timeliness of the WP Fingerprint checksum database, which may not cover all plugins or update quickly after legitimate plugin updates.

Technical Details

Requires WordPress
4.9+
Requires PHP
5.6+
Tested up to WP
6.8.6
First Released
2018 (8+ years)
Support (last 2 months)
0 threads

Feature Tags

checksums plugins security

Frequently Asked Questions