WordPress

How to Detect Missing Critical Files and Obtain a Fresh Copy of WordPress

By the Domain India teamPublished 6 min read
Knowledge base article
Contents (5 sections)

If WordPress shows a blank page, a "failed to open stream" error, or breaks right after an update or a malware cleanup, one or more core files may be missing or changed. You can find out exactly which files differ from the official release in a minute, then replace them with a fresh copy of the same WordPress version without touching your content.

Key takeaways

Check the error log for "No such file or directory" or "Failed opening required", or compare your core files with the official release using WP Toolkit's integrity check (cPanel) or wp core verify-checksums over SSH. Then take a backup and replace wp-admin, wp-includes and the root files with a fresh download of the same version. Never replace wp-content or your wp-config.php.

For the full restore guide

This page covers finding what is missing. For every way to reinstall core safely (dashboard, WP Toolkit, upload, WP-CLI), see Restoring and resetting WordPress core files. If only the home page's index.php is broken, see How to restore or reset the WordPress index.php file.

1. Signs that a core file is missing

  • A blank white page, or a 500 error, on every page.
  • A PHP fatal error naming a file under wp-includes or wp-admin, such as Failed opening required '…/wp-includes/load.php'.
  • The dashboard loads without styles, or some admin screens give 404.
  • Problems that start right after an interrupted update, an antivirus or malware cleanup, or a partial upload.

2. Read the error log

A missing file almost always leaves a clear line in the PHP error log. On our cPanel and DirectAdmin servers PHP logs errors by default, to an error_log file in the folder of the script that failed and, on cPanel, also to logs/yourdomain_com.php.error.log in your home folder. cPanel's Metrics › Errors page shows recent web server errors.

Look for lines like:

text
PHP Warning:  require(/home/user/public_html/wp-includes/formatting.php): Failed to open stream: No such file or directory
PHP Fatal error:  Uncaught Error: Failed opening required '/home/user/public_html/wp-includes/formatting.php'

The path in the message is the file to restore. For where each log lives, see reviewing error logs in cPanel and DirectAdmin.

WordPress's own debug log helps with errors raised inside plugins and themes. Add these lines to wp-config.php, above /* That's all, stop editing! */, and switch them off when you are done:

php
define( 'WP_DEBUG', true );
define( 'WP_DEBUG_LOG', true );
define( 'WP_DEBUG_DISPLAY', false );

See how to enable debugging in WordPress for the details.

3. Compare your files with the official release

The error log shows the first missing file, but there may be more. A checksum comparison lists every core file that is missing or changed.

MethodWhereWhat it does
WP Toolkit integrity checkcPanelCompares core files with the official release and reports what differs
wp core verify-checksumsWP-CLI over jailed SSHLists every missing or modified core file in your WordPress folder
wp plugin verify-checksums --allWP-CLI over jailed SSHDoes the same for plugins from wordpress.org

WP Toolkit is installed on our cPanel servers. WP-CLI is available inside the jailed SSH shell on our cPanel and DirectAdmin servers; jailed SSH is available on every shared plan but is off by default, so ask support to enable it and log in with a key. See enabling and using jailed SSH.

bash
cd ~/public_html
wp core version
wp core verify-checksums

"File doesn't verify against checksum" means the file was changed; "File doesn't exist" means it is missing. A file reported as "should not exist" in wp-admin or wp-includes was added by someone else, which is a strong sign of a hack.

4. Get a fresh copy of the same version

  1. Find your version
    in wp-includes/version.php ($wp_version), or with wp core version.
  2. Take a backup first.
    Download the folder and export the database, or confirm a recent JetBackup backup exists; see how to restore a backup with JetBackup.
  3. Download that version
    from the official WordPress release archive on wordpress.org, or the latest if you plan to update anyway.
  4. Replace the core
    as described in the core files guide: delete and re-upload wp-admin and wp-includes, then the root files. Over SSH, wp core download --version="$(wp core version)" --skip-content --force does it in one command.
  5. Set permissions
    to 644 for files and 755 for folders, then run the checksum check again.
If files were changed by malware

Replacing core does not remove backdoors in wp-content, hidden admin users or changed theme files. Follow the security checklist for hacked websites after you restore core.

Frequently asked questions

How do I know which WordPress core files are missing?

Read the PHP error log for "No such file or directory" or "Failed opening required" lines, which name the file. For a complete list, run WP Toolkit's integrity check on cPanel or wp core verify-checksums over SSH.

Will replacing core files delete my posts or plugins?

No. Posts and settings are in the database, and themes, plugins and uploads are in wp-content. Replacing wp-admin, wp-includes and the root files does not touch them.

Which WordPress version should I download?

The same version your site runs, shown in wp-includes/version.php, or the latest release if you intend to update anyway. Take it from wordpress.org only.

Is WP-CLI available on Domain India shared hosting?

Yes, inside the jailed SSH shell on our cPanel and DirectAdmin servers. Jailed SSH is off by default; ask support to enable it and log in with an SSH key.

What does "should not exist" mean in verify-checksums?

A file is present in wp-admin or wp-includes that is not part of the official release. That usually means someone added it, so treat the site as possibly hacked and follow a full cleanup.

Ready to restore your site? Follow the core files guide, or open a support ticket if WordPress still does not load.

WordPress still broken?

Send us the site address, the error you see and what changed last, and we will check your account's logs with you.

Open a support ticket

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Find Missing WordPress Core Files and Restore Them