Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you’re updating WordPress, replace its old core files with the official files for the new release; don’t delete the whole installation or remove an unexplained file just because it looks old. Back up and verify the database and site files first, preserve wp-config.php and wp-content, and identify any specific leftover by its full path and WordPress version before considering removal.

First, decide what “old WordPress core files” means

There are two different tasks that are easy to confuse:

  • Updating WordPress: replace the old core directories and files with those from the intended official release. This is a core update, not a command to wipe the WordPress directory.
  • Removing one leftover: investigate a particular file that remains after an update. A file is not safe to delete just because it appears old or was not included in the new release.

For a routine update, use the WordPress dashboard updater if it is available, or follow WordPress’s manual update instructions. If you have a specific leftover, establish what it is before deleting anything.

What to keep when replacing core files

  • wp-config.php, which contains site configuration.
  • The existing wp-content directory, which contains site content such as plugins, themes, and uploads. WordPress explicitly says: “Do NOT delete your existing wp-content folder.”
  • Site-specific files and settings, including custom .htaccess rules and a site-created root robots.txt, where applicable.

WordPress’s shorter update guide describes replacing wp-admin and wp-includes, uploading the new root-level core files, and preserving the existing wp-content directory. The Advanced Administration Handbook’s manual upgrade guidance also identifies files and folders to retain. Follow the instructions that match your installation and release; broad wording about deleting old files is not permission to delete every item in the site directory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Safely replace core files during a manual update

  1. Back up the database and all WordPress files. Include files such as .htaccess. Verify that the backups exist and can be restored before proceeding. WordPress’s manual upgrade guidance recommends backing up both.
  2. Deactivate plugins as directed in WordPress’s manual upgrade procedure. Download and extract the official WordPress package for the release you intend to install.
  3. Replace the core directories and files. Remove the old wp-admin and wp-includes directories, then upload their new versions. Overwrite applicable root-level core files with the package’s files. Where package files inside wp-content apply, upload those into the existing wp-content directory; do not replace or delete that directory.
  4. Preserve configuration and site-specific files. Do not delete wp-config.php. Keep custom .htaccess rules and a site-created root robots.txt where relevant, and apply the official procedure’s specific exceptions rather than a blanket deletion.
  5. Run the upgrade program if prompted, then check the site. Review the site, permalinks, themes, plugins, and any changes relevant to the update.

For a routine update, the built-in WordPress updater is generally the simpler route: WordPress handles replacement and its defined cleanup. Manual replacement is for situations where you are following the manual procedure and have file access, verified backups, and a clear understanding of which files must remain.

What to do if an old file remains after updating

WordPress’s automatic updater processes a defined list of old files. Its upgrade FAQ says files outside that list and absent from the release distribution remain in place. The update_core() reference describes copying new files, upgrading the database, and then removing old files; it also documents interrupted cleanup as a possible failure case.

That means a leftover may be an orphan, a site-specific file, or evidence of an incomplete update. The updater’s behavior does not establish that an arbitrary file is safe to remove. Before deleting a named file:

  1. Record its full path, including its directory.
  2. Identify the installed WordPress version and determine whether the update completed successfully.
  3. Compare the file with the official files for that specific release and determine whether it belongs to your site or another component.
  4. Keep a verified backup before removing it. If you cannot establish that the file is obsolete, leave it in place and get version-specific help.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use WP-CLI if you already administer the site from the command line

WP-CLI documents wp core update and wp core verify-checksums. The first is a command-line route for updating WordPress core; the second checks core files against WordPress.org checksums. Check the installed WP-CLI command documentation for the options and requirements that apply to your setup.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before running either command on a live site, confirm that you are in the correct WordPress installation and that you have appropriate access, a verified backup, and a clear update state. Checksum verification can help assess core files, but it does not by itself prove that a separate, unexplained file is safe to delete.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.