Plugin Checksums

Published by WPManageNinja

Every file of every published release, fingerprinted with MD5 and SHA-256. Check whether the plugin files on a site are the files we shipped — no account, no license key, no request that identifies the site being checked.

Coverage starts 14 Aug 2026. We publish checksums from the current release of each product forward, not for versions released before this service existed. If a version is not listed, we have no manifest for it — that is a gap in our coverage, not a finding about the files.

14Products
45Versions
3,817Files fingerprinted
30 Sep 2026Last updated

The register

AzonPress azonpress
2.3.1169 filesadded 14 Aug 2026
Zip SHA-256 · 2.3.1 b4649f1ec4371baadf9a63dac25c03a616d846e4945769e97c1b42cbf9613020
Fluent Boards Pro fluent-boards-pro
2.1.0116 filesadded 17 Sep 20264 versions
Zip SHA-256 · 2.1.0 2853ef8d56b57df20a80b0faa1781a5e50da6a07e2c25351edb04da3942cd280
FluentBooking Pro fluent-booking-pro
2.5.0189 filesadded 24 Sep 20265 versions
Zip SHA-256 · 2.5.0 5740acb126046603cfb60a6b36d4f5c2f2308b4bf05cc032fa447d063c96f65f
FluentPlayer Pro fluent-player-pro
1.4.0171 filesadded 26 Aug 20262 versions
Zip SHA-256 · 1.4.0 ba8f73981cea15c0f2bdde1bda6932f1d3e18794a11e73cfc5dd2eb828643530
FluentHub fluent-toolkit
2.1.1360 filesadded 31 Aug 20262 versions
Zip SHA-256 · 2.1.1 3f6c40d0fb4c7fc769ec09881d9d0880cfddb526bc7160e9b5b4fa6712984dcd
FluentCRM Pro fluentcampaign-pro
3.2.5400 filesadded 30 Sep 20264 versions
Zip SHA-256 · 3.2.5 d58b6e84cf4f5412c26e405a1f5e4b246617bb0e98d6040965852452d1cb72d6
Ninja Tables Pro ninja-tables-pro
5.2.171,114 filesadded 15 Sep 20264 versions
Zip SHA-256 · 5.2.17 2faf9bb98157f54b88f91b5bf3c7d6fb2fb198f1c60b3d8279e7a654b0af92ad
Paymattic Pro wp-payment-form-pro
4.6.26242 filesadded 22 Sep 20263 versions
Zip SHA-256 · 4.6.26 adc7d023e3eb90e6a0cac32af565a0ec22a48784668fc9c9eb4c43134f60e61c

Check a download

Hash the zip you received and compare it to the digest listed above. This tells you the archive is ours before you unpack anything.

$ shasum -a 256 azonpress.zip
b4649f1ec4371baadf9a63dac25c03a616d846e4945769e97c1b42cbf9613020  azonpress.zip

Compare the whole string. A matching prefix means nothing on its own.

Check an installed plugin

Fetch the manifest for the version on the site and compare every file. The manifest lists paths relative to the plugin directory, so demo-pro.php means wp-content/plugins/demo-pro/demo-pro.php.

# every file in one released version
curl https://checksums.wpmanageninja.com/plugin-checksums/{slug}/{version}.json

# which versions exist
curl https://checksums.wpmanageninja.com/plugin-checksums/{slug}/index.json

# everything we publish
curl https://checksums.wpmanageninja.com/plugins.json

Endpoints

PathReturns
/plugin-checksums/{slug}/{version}.jsonChecksums for one release
/plugin-checksums/1.0/?slug=…&version=…The same, query-string form
/plugin-checksums/{slug}/index.jsonEvery published version of one plugin
/plugins.jsonEvery plugin listed above

GET and HEAD only, CORS open, ETag honoured. A published version never changes, so it is served immutable and can be cached forever.

Format

The plugin, version and files keys are byte-compatible with the WordPress.org checksum API, so anything that already reads downloads.wordpress.org/plugin-checksums/ reads this too. Our additions live under _meta, where strict consumers can ignore them.

{
  "plugin": "example-pro",
  "version": "1.4.2",
  "files": {
    "example-pro.php": { "md5": "…", "sha256": "…" }
  },
  "_meta": {
    "zipSha256": "…",       // the digest listed above
    "fileCount": 412,
    "softChange": [ … ],    // may differ without meaning tampering
    "ignore": [ … ]         // written after install; skip these
  }
}

What this does and does not tell you

A mismatch means a file differs from what we published. That is worth investigating, but it is not proof of compromise on its own: FTP transfers in text mode rewrite line endings, and site owners sometimes patch plugins deliberately.

A clean result is narrower than it looks. It says the plugin directory matches our release. It says nothing about the rest of the site, and nothing about whether the release itself was safe. These manifests are served over TLS but are not yet signed, so they carry the same trust model as the WordPress.org checksum API.