Remove delete readme.html option
Removal of the readme.html file causes the site to be fail WP CLI checksum tests. Potentially making the site less secure as it is it won't be suitable for file integrity checks. It is also incompatible with some hosts (see WP Engine workaround in child plugin).I assume this feature was originally added as a way to hide the WP version. However the WP version hasn't been shown in this file for some years, the WP version can be found in many other locations and deleting an HTML file offers no security benefit.As the feature doesn't improve security, and affects the ability to use file integrity checks I recommend removing it from future releases.
Log in to comment and vote
Comments1
Dennis Dornon
Dec 13, 2024
Removing the entire Delete readme.html feature is not an option at this time.
Please note there is a hook that allows you to disable specific security checks: https://managers.mainwp.com/t/can-you-disable-certain-security-checks/6774/10