WordPress
wp-includes
wp-includes is the WordPress core folder that holds the main PHP library: query classes, formatting functions, the block parser, and bundled JavaScript. You should not edit anything in it.
How it is measured
Files such as class-wp-query.php, formatting.php, functions.php, post.php, and version.php (which defines $wp_version) live here, with js/ and blocks/ subfolders. The folder is replaced entirely by each core update, so any change you make is lost.
Verify it with wp core verify-checksums, which hashes core files against the official list for your version and reports a mismatch such as File doesn't verify against checksum: wp-includes/functions.php.
Worked example
A client's site starts redirecting mobile visitors to a pharmacy page. wp core verify-checksums lists one failure: wp-includes/js/jquery/jquery-migrate.min.js, whose size is 14 KB larger than the original. The script has an obfuscated block at the end.
The developer reinstalls core with wp core download --force --skip-content, which restores the file, and then searches wp-content for the backdoor that wrote it.
How it differs
wp-includes is core code that should match the release exactly, while wp-content is where your site's own code lives and is expected to vary. Both sit beside wp-admin. A difference in wp-content is normal; a difference in wp-includes means a modification that did not come from WordPress.
Common errors
Patching a core file to fix a bug and losing the patch on update. Treating a modified timestamp as proof of compromise. Skipping verify-checksums because the site looks fine. Deleting the folder to reinstall and removing a mu-plugin path. Assuming the tool covers plugin and theme files; it does not.
In practice
Run wp core verify-checksums once a month and after any security alert. If a file fails, replace core files from a clean download and then look for the reason in wp-content and the server logs.