How can I be sure it is safe to delete these files?

I was having a look at some "urgent" issues you've had for my site using WPDefender. I'm not sure what to do. There are 12 pages listed, but they are things like "error_log" and "wp-rss" and they seem like they could be legit and important files. WPDefender says they are not "core" files. I'm not sure what the "core" files actually are. I'm scared to delete the files because they don't look like a mistake. And I am running All in one WP Security as well and it hasn't indicated an issue. Are you SURE these are bad files I should delete? How can I go about finding our for certain?

PS: I have turned on the 5 day access for support for this site.

  • Vaughan

    Hi Dandelion,

    Hope you're well?

    Core files are files included with wordpress & the plugins. Non-core files are files that are present but not originally part of the wordpress package or plugin package.

    error_log files you should just ignore these, you can delete them if you want, but they come from the server so will keep being regenerated when errors occur. Nothing to worry about with those, best ignore them in Defender.

    How old is your site?

    All the files it's listing belong to a really old version of Wordpress.

    /wp-rss2.php
    /wp-rss.php
    /wp-register.php
    /wp-rdf.php
    /wp-atom.php
    /wp-commentsrss2.php
    /wp-feed.php
    /wp-pass.php
    /500.php

    If you click on the file name, it should show you the code in the file. I would use FTP to download these files to your desktop for backup (just in case), then delete them as they're all deprecated and old files that are no longer used in WP, you shouldn't have any issues. But in case you do, you have the files backed up, so can easily re-upload them, but unless your site was built pre-2013 then they shouldn't be there anyway.

    Hope this helps

  • Dandelion

    Thank you, that is very helpful! I don't completely understand, but I understand a lot more and a have an action plan for moving forward. My site was built probably in early to mid 2013. So right on the borderline.

    Are these old Wordpress files, or old Wordpress theme files? Because I do have some older Wordpress.com themes like Twenty-Eleven and Twenty-Thirteen in there but not being used. If I delete those will the issue go away?

    If not I'll download the files then delete as you suggest.

  • Vaughan

    Hi,

    They are old Wordpress core files, could have been left there after a manual update at 1 time, or the wpupdater is not able to unlink() or delete them automatically.

    You should be safe to remove them.

    Twenty-eleven and thirteen themes are ok to be left as long as you keep them updated, but if you are never likely to use them again, it's always best to delete what is not being used or not going to be used.

    Hope this helps

Thank NAME, for their help.

Let NAME know exactly why they deserved these points.

Gift a custom amount of points.