How to know if a Wordpress theme/plugin contains some kind of malicious coding?

Dennyy

Regular Member
Joined
May 16, 2013
Messages
341
Reaction score
79
Hey guys,

There are a few Wordpress themes and plugins that I would love to use in the Member's download section (such as this http://www.blackhatworld.com/blackh...ricing-tables-ready-pro-wordpress-plugin.html) but what have prevented me from using any of them is that I don't want my website to get hacked because of malicious coding.

Other than buying it directly from the developer (which I do when I really like the theme/plugin), is there a way to find out if uploaders have injected some kind of funky source coding? I 'do' do "ctrl+f" to find if there are websites in the coding, but I feel that this is not enough.

Any response is appreciated!
 
For theme, I run TAC Plugin and Exploit Scanner.

Exploit Scanner Plugin - It will scan the codes of all of your themes and plugins inside your wordpress that have malicious code.
 
I also use TAC and Exploit Scanner. After that, I use Scrapebox to scan my site for any outbound links that were not made by me.
 
For theme, I run TAC Plugin and Exploit Scanner.

Exploit Scanner Plugin - It will scan the codes of all of your themes and plugins inside your wordpress that have malicious code.

Exploit Scanner will pick up a lot of false positives. The person has to know what they're looking at in order to decipher between the false positives and the actual threats.
 
Yup, Virus Total can only do so much as it is mainly for apps.

Thanks a lot for the quick response guys, I will definitely check out both TAC and Exploit Scanner! (followed by Bupler's idea of scanning OBL)
 
Exploit Scanner will pick up a lot of false positives. The person has to know what they're looking at in order to decipher between the false positives and the actual threats.

Yeah, it will pick up a lot of false positives but at least you have an idea what are those codes and you can easily find callbacks and suspicious codes.
 
Yeah, it will pick up a lot of false positives but at least you have an idea what are those codes and you can easily find callbacks and suspicious codes.

Not if the OP doesn't know what he's looking for.

Heh, for those who don't speak code, it'll look like a bunch of gibberish.
 
i know this is off topic but.. Whats up with one popup saying the fbi has locked my browser.. and my browser is literally locked?? anyone know this or dealt with it before?
 
There was a great thread a couple years back on this. I'll see if I can dig it up.
 
Back
Top