b4649f1ec4371baadf9a63dac25c03a616d846e4945769e97c1b42cbf9613020
Plugin Checksums
Every file of every published release, fingerprinted with MD5 and SHA-256. Check whether the plugin files on a site are the files we shipped — no account, no license key, no request that identifies the site being checked.
Coverage starts 14 Aug 2026. We publish checksums from the current release of each product forward, not for versions released before this service existed. If a version is not listed, we have no manifest for it — that is a gap in our coverage, not a finding about the files.
The register
ec6f8890954c5f0ca2ad13bcb4fd91e53b79f0af7d2ff07f8edc17fea3c446d4
2853ef8d56b57df20a80b0faa1781a5e50da6a07e2c25351edb04da3942cd280
5740acb126046603cfb60a6b36d4f5c2f2308b4bf05cc032fa447d063c96f65f
108ac0911e9e01455ee2a32407956aa7f5aeb627920b63a75a91e49f41e0769d
ba8f73981cea15c0f2bdde1bda6932f1d3e18794a11e73cfc5dd2eb828643530
980808c57d80f6f39d8d72bc2939a73f97083a23d0a21ca55727ce3c27ffd747
3f6c40d0fb4c7fc769ec09881d9d0880cfddb526bc7160e9b5b4fa6712984dcd
d58b6e84cf4f5412c26e405a1f5e4b246617bb0e98d6040965852452d1cb72d6
3f7ca9730e1fff1ee56f45dd0342101136a3e2d0ab1b390e945b126f34e0c461
20074cff095a24bffffa370b79be360a1f26fdaf26dce67e13338072c48e5c90
2faf9bb98157f54b88f91b5bf3c7d6fb2fb198f1c60b3d8279e7a654b0af92ad
adc7d023e3eb90e6a0cac32af565a0ec22a48784668fc9c9eb4c43134f60e61c
bb274a22671a6aaed0824d323d3e36bf8b429a87c2934ac1c7f7e8e7ccc76a82
No product matches that.
Check a download
Hash the zip you received and compare it to the digest listed above. This tells you the archive is ours before you unpack anything.
$ shasum -a 256 azonpress.zip
b4649f1ec4371baadf9a63dac25c03a616d846e4945769e97c1b42cbf9613020 azonpress.zip
Compare the whole string. A matching prefix means nothing on its own.
Check an installed plugin
Fetch the manifest for the version on the site and compare every file. The manifest lists
paths relative to the plugin directory, so demo-pro.php means
wp-content/plugins/demo-pro/demo-pro.php.
# every file in one released version
curl https://checksums.wpmanageninja.com/plugin-checksums/{slug}/{version}.json
# which versions exist
curl https://checksums.wpmanageninja.com/plugin-checksums/{slug}/index.json
# everything we publish
curl https://checksums.wpmanageninja.com/plugins.json
Endpoints
| Path | Returns |
|---|---|
/plugin-checksums/{slug}/{version}.json | Checksums for one release |
/plugin-checksums/1.0/?slug=…&version=… | The same, query-string form |
/plugin-checksums/{slug}/index.json | Every published version of one plugin |
/plugins.json | Every plugin listed above |
GET and HEAD only, CORS open, ETag honoured. A published
version never changes, so it is served immutable and can be cached forever.
Format
The plugin, version and files keys are byte-compatible
with the WordPress.org checksum API, so anything that already reads
downloads.wordpress.org/plugin-checksums/ reads this too. Our additions live
under _meta, where strict consumers can ignore them.
{
"plugin": "example-pro",
"version": "1.4.2",
"files": {
"example-pro.php": { "md5": "…", "sha256": "…" }
},
"_meta": {
"zipSha256": "…", // the digest listed above
"fileCount": 412,
"softChange": [ … ], // may differ without meaning tampering
"ignore": [ … ] // written after install; skip these
}
}
What this does and does not tell you
A mismatch means a file differs from what we published. That is worth investigating, but it is not proof of compromise on its own: FTP transfers in text mode rewrite line endings, and site owners sometimes patch plugins deliberately.
A clean result is narrower than it looks. It says the plugin directory matches our release. It says nothing about the rest of the site, and nothing about whether the release itself was safe. These manifests are served over TLS but are not yet signed, so they carry the same trust model as the WordPress.org checksum API.