When WordPress core files are damaged, deleted or changed by malware, you can replace them all with a clean copy without touching your posts, pages, themes, plugins or uploads. Your content lives in the database and in wp-content; the core files in wp-admin, wp-includes and the root folder can be swapped freely. This guide shows four safe ways to do it and what to check afterwards.
Take a backup first. Then reinstall core from Dashboard › Updates › Re-install, or upload fresh wp-admin and wp-includes folders and root files from wordpress.org, never its wp-content folder, and never overwrite your wp-config.php. If jailed SSH is enabled, wp core download --skip-content --force does the same in one command. Afterwards, save your permalinks and check the site; if the files were hacked, replacing core is only the first step.
If the problem is just the root index.php (a 403 on the home page, a blank page or a defaced front page), follow How to restore or reset the WordPress index.php file. It includes the standard file contents.
1. What is core, and what is yours
| Part of the site | Safe to replace with a fresh copy? | Why |
|---|---|---|
| wp-admin/ and wp-includes/ | Yes | Pure WordPress code, identical on every site of the same version |
| Root files such as index.php, wp-login.php, wp-settings.php, wp-load.php | Yes | Also WordPress code |
| wp-config.php | No | Holds your database details and security keys |
| .htaccess | Keep yours | Holds your permalink and any custom rules |
| wp-content/ | No | Your themes, plugins and uploads |
| The database | Not touched | Your posts, pages, users and settings |
Old guides printed the "default" contents of files such as wp-settings.php and wp-login.php for you to paste. Don't do that: those files are long, change with every release, and a pasted copy from an article can be outdated or wrong. Always take core files from an official WordPress download of the same version.
2. Back up first
Before replacing anything, keep a copy you can go back to:
- download the whole WordPress folder with the File Manager or SFTP, and export the database from phpMyAdmin; or
- make sure a recent JetBackup backup exists. Domain India cPanel and DirectAdmin hosting runs weekly JetBackup 5 backups, keeping five copies, and you can restore files or a single database from your panel. See how to restore a backup with JetBackup.
If the site was hacked, the current files are evidence. Keep the copy, but don't restore from it.
3. Four ways to reinstall core
From the WordPress dashboard
If you can still log in, go to Dashboard › Updates and click Re-install version …. WordPress downloads the current release and replaces the core files, leaving wp-content and wp-config.php alone. This is the easiest route.
With WP Toolkit (cPanel)
WP Toolkit is installed on our cPanel servers; in cPanel it is the WordPress Management page (type "WordPress" in cPanel's search box to find it). It can check your WordPress installation's integrity against the official release; if it offers to reinstall the core files it finds changed, that does the same job without the dashboard.
By uploading a fresh copy
Use this when you can't log in to WordPress.
- Find your version.Open
wp-includes/version.phpin the File Manager and read$wp_version. Use the same version, or the latest if you plan to update anyway. - Download WordPressfrom wordpress.org and unzip it on your computer.
- Delete the old core folders.In your WordPress folder on the server, delete
wp-adminandwp-includes. Deleting rather than overwriting removes any extra file an attacker added there. - Upload the new ones.Upload the fresh
wp-adminandwp-includes, then the root files from the download, replacing the old ones. Do not upload the downloadedwp-contentfolder. - Keep your config.The download contains only
wp-config-sample.php, so your ownwp-config.phpis not overwritten. Leave it in place. - Set permissions.Files 644, folders 755. Never 777.
Uploading a zip and using Extract in the File Manager is much faster than uploading thousands of small files. See how to use the File Manager.
With WP-CLI over SSH
Jailed SSH is available on every Domain India shared hosting plan. It is off by default, so ask support to enable it, and log in with a key; see enabling and using jailed SSH. WP-CLI is available inside the jail on our cPanel and DirectAdmin servers. From your WordPress folder:
# See which core files differ from the official release
wp core verify-checksums
# Replace core with the same version, leaving wp-content alone
wp core download --version="$(wp core version)" --skip-content --force
# Check again
wp core verify-checksums--skip-content stops WP-CLI from writing the default themes and plugins over yours.
4. If wp-config.php is damaged
wp-config.php is yours, not core, so it can't be replaced from a download. Restore it from a backup. If there is none, rebuild it from wp-config-sample.php: fill in DB_NAME, DB_USER, DB_PASSWORD and DB_HOST (normally localhost) from your control panel's database section, set $table_prefix to the prefix your tables use in phpMyAdmin, and generate fresh keys and salts at https://api.wordpress.org/secret-key/1.1/salt/. New salts log everyone out, which is what you want after a hack.
5. After the reinstall
- Pages other than the home page give 404: open Settings › Permalinks and click Save Changes.
- Blank page or 500 error: read the error log; see how to enable debugging in WordPress. If a plugin is to blame, rename
wp-content/pluginstoplugins-offto disable them all, then turn them back on one by one. - Database connection error: check the details in
wp-config.php; see troubleshooting "Error establishing a database connection". - You still see the old page: on our cPanel servers a proxy cache can serve a stored copy for a while. Add
?t=1to the address to see the live version.
Clean core files don't remove a backdoor in wp-content/uploads, a hidden administrator account, or code in your theme or wp-config.php. After reinstalling core, follow the security checklist for hacked websites, change every password and update all plugins and themes.
6. Where Domain India hosting fits
Domain India cPanel hosting gives you the File Manager, WP Toolkit and JetBackup 5 in one panel, so you can back up, reinstall and restore WordPress yourself. The card shows the live price, excluding 18% GST.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
Will reinstalling WordPress core delete my posts or plugins?
No. Reinstalling core replaces wp-admin, wp-includes and the root WordPress files. Your posts and settings are in the database, and your themes, plugins and uploads are in wp-content, which a correct reinstall does not touch.
How do I reinstall WordPress core from the dashboard?
Log in, go to Dashboard, Updates, and click the Re-install version button. WordPress downloads the current release and replaces the core files, leaving wp-content and wp-config.php alone.
How do I reinstall WordPress core if I can't log in?
Download WordPress from wordpress.org, delete the wp-admin and wp-includes folders on your server, upload the fresh ones and the root files, and do not upload the downloaded wp-content folder. Your wp-config.php stays in place.
Can I restore wp-config.php from a WordPress download?
No. The download contains only wp-config-sample.php. Restore wp-config.php from a backup, or rebuild it from the sample with your database details and freshly generated keys and salts.
Is WP-CLI available on Domain India shared hosting?
WP-CLI is available inside the jailed SSH shell on our cPanel and DirectAdmin servers. Jailed SSH is off by default; ask support to enable it for your account, and log in with an SSH key.
Does reinstalling core clean a hacked WordPress site?
Only partly. It replaces damaged core files, but backdoors in wp-content, hidden admin users and changed theme files remain. Follow a full hacked-site cleanup after the reinstall.
Ready to fix your site? Back up first, then use the method above that fits, or open a support ticket if the site still does not load.
Send us the site address, what you see and which method you used, and we will check the server side of your hosting account with you.
Open a support ticket