Using nulled wordpress themes and plugins is always risky, without going through full code and looking for any additionaly added malicious code which can include backdoors and access to your backend. In case of wordpress themes, which are composed by a big number of PHP files, it can be quite hard and time consuming to find the malicious code. Additionally, most of known hosting providers do not allow the use of nulled themes/plugins and will delete them if they are detected.