Integration

Security & Maintenance — AI site care for WordPress

Malware scanner, core integrity checker, auto-repair, database cleanup, quarantine, file permissions, user audit, find and replace, health check, and password reset.

activeSecurity12 AI abilitiesfree
12
AI abilities
Checksum
verified
Quarantine
not delete
Free
on every plan
Why it's powerful

Find it, understand it, fix it

A scanner that reports a modified core file leaves you to work out what changed and what to do. Comparing against real WordPress checksums and repairing from source is the part that ends the problem.

Core integrity

Verify every core file against the official WordPress checksums, then repair from source.

Malware scanning

Scan files and the database for the patterns that matter, with the findings explained.

Quarantine, not delete

Suspicious files are isolated rather than destroyed, because false positives happen.

User audit

Find accounts that should not have the access they have.

Permissions and passwords

Check file permissions and force password resets after an incident.

Database maintenance

Cleanup, health checks and careful find-and-replace across the database.

From hours to one prompt

Ask what is wrong and the agent scans, explains what it found, and repairs what should be repaired — rather than handing you a report to interpret.

nibwp/security-verify-core (checksums) ✓ 1,842 files · 3 modified · 3 repaired
Use it for

Real workflows

After an incident

Verify core, quarantine what does not belong, audit users, reset passwords.

Inherited sites

Find out what the last developer left behind before you take responsibility for it.

Routine maintenance

Cleanup and health checks on a schedule rather than when something breaks.

Access review

Check who has administrator rights and whether they still should.

AI security and maintenance for WordPress

Security & Maintenance is built into NibWP and gives any MCP-compatible AI agent — Claude, Cursor, Claude Code and others — the tools to inspect and repair a WordPress install.

Detection on its own is rarely the hard part. Being told that three core files differ from the official release leaves the real questions open: which files, what changed, and what should be done about it. Verifying against WordPress’s own checksums and repairing from source answers all three.

Quarantine over deletion

Suspicious files are isolated rather than destroyed, because a false positive that deletes a working file is its own kind of incident. Genuinely dangerous operations — database find-and-replace, forced password resets — are flagged destructive and gated accordingly.

Abilities

Tools this integration adds

ToolTypeWhat it does
nibwp/security-verify-corereadVerify core files against official WordPress checksums.
nibwp/security-repair-corewriteRestore modified core files from source.
nibwp/security-scan-malwarereadScan files for malware patterns.
nibwp/security-scan-databasereadScan the database for injected content.
nibwp/security-quarantine-filewriteIsolate a suspicious file without deleting it.
nibwp/security-audit-usersreadAudit users, roles and capabilities.
nibwp/security-file-permissionsreadCheck file and directory permissions.
nibwp/security-health-checkreadOverall health of the install.
nibwp/security-cleanupwriteClean up leftover and unnecessary data.
nibwp/security-find-replacewriteFind and replace across files.
nibwp/security-db-find-replacedestructiveFind and replace across the database.
nibwp/security-change-passwordsdestructiveForce password resets across accounts.
Related

Explore more integrations

FAQ

Questions, answered

Do I need a plugin for this?

No. Security & Maintenance is built into NibWP and available on every plan, including Free.

Does it replace a firewall or a dedicated security plugin?

No. This scans, audits, repairs and maintains. It does not sit in front of your site blocking traffic, and you should still run whatever protection you already trust.

What happens to a file it flags?

It is quarantined, not deleted — isolated so it cannot run, and recoverable if the detection turns out to be wrong.

Are the dangerous operations gated?

Database find-and-replace and forced password resets are flagged destructive and sit behind a permission an ordinary read-and-write connection is never granted.

Connect Security & Maintenance to your agents.

Activate the integration and it's live on your MCP endpoint instantly.