Nulled WordPress themes and plugins: why they're the most common way in for hackers
This guide covers nulled wordpress themes plugins from confirmation through cleanup and prevention.
A premium WordPress theme costs a few dozen euros, and a plugin for forms, caching or SEO about the same per year. On the other side, a few clicks away, the same products can be downloaded for free, "activated", with all features. For a small business or a freelancer building a site on a tight budget, the choice seems obvious.
When we clean hacked sites and look for how the attacker got in, a pirated theme or plugin is among the most common answers. Not because someone targeted your site in particular, but because the malicious code was in the files from day one, before the site was even published.
The problem is made worse by the fact that many owners don't know their site uses pirated software at all. The site was ordered from an agency or freelancer, handed over "turnkey", and nobody asked where the theme and plugins came from.
In this article we explain what nulled themes and plugins are, why they're so risky, how to check whether your site uses them (even if you didn't build it yourself) and how to replace them safely.
What "nulled" means

When dealing with nulled wordpress themes plugins, order matters more than speed.
A nulled theme or plugin is premium software from which someone has removed the licence check and then shared it for free or for a token price. Such files are found on "free premium theme download" sites, forums, Telegram channels and various file-sharing services.
What about the GPL licence?
WordPress and most WordPress themes and plugins are released under the GPL licence, which allows the PHP code to be redistributed. That's why you sometimes hear the argument that nulled software is "legal". It's more complicated than that. Images, design and some other parts often aren't under the same licence, and access to updates and support is tied to a purchased licence. Far more important than the legal question, though, is the security one: you don't know who modified the files before they reached you, or what they added.
GPL "clubs" and resellers
There are also sites selling access to hundreds of premium plugins for a few euros a month, arguing that everything is GPL. Some of them don't inject malicious code, but you still depend on a third party that isn't the product's author. Updates arrive late or not at all, and you can't verify that a file is identical to the original. For a site your business depends on, that's a risk that doesn't pay off.
Why nulled themes and plugins are so dangerous

Code injected before you install it
People who share nulled software rarely do it out of kindness. They make money by adding their own code to the files. Most often that's:
- a backdoor, a hidden entry point that lets them access every site the theme is installed on later,
- code that creates an administrator account when certain conditions are met, or on command from an external server,
- hidden spam links in the footer or page code that visitors don't see but Google does,
- redirect code that sends some visitors to ads, scams or malicious sites,
- code that "phones home" to an external server with the address of the site it's installed on, giving the attacker a list of targets.
This code is usually obfuscated and doesn't have to activate straight away. A site can run normally for months, and then one day spam appears in Google, a suspicious administrator shows up or visitors get redirected.
No updates
This risk exists even when a nulled file has no injected code. Serious authors release regular updates that close security holes. With a nulled version you don't get those updates through WordPress, so the site stays on a version with a known, publicly disclosed vulnerability. Attackers' automated tools look for exactly such vulnerabilities. When a hole in a popular plugin is announced, mass attacks on sites that haven't updated start within days.
No support, and you don't know what you have
If something stops working, there's no one to ask. If the author publishes a warning about a critical vulnerability, you don't receive it. And since you don't know who modified the files, even a specialist reviewing the site can't easily tell what's original and what was added.
It spreads across the whole server
A backdoor in a theme doesn't stay in the theme. Once the attacker uses it, they can write files anywhere in the account: into WordPress core, other plugins, the uploads folder and, on shared hosting, sometimes into other sites on the same account. That's why simply deleting the nulled theme after an infection isn't enough.
What a typical scenario looks like
Most of the cases we see follow a similar pattern:
- Building the site. To fit the budget, the site is built on a premium theme with a few premium plugins downloaded from a "free download" site.
- The quiet period. The site works normally for weeks or months. The injected code is there, but it's waiting or only activates for search engine crawlers.
- The first signal. Something odd appears: spam results in Google, an unknown administrator, the host reports the site is sending spam email, or visitors report being redirected.
- A quick "fix". Someone deletes the suspicious pages or user, and everything seems fine for a few days.
- The return. Because the source is still in the theme or plugin, the infection comes back, often on a larger scale. Only then does a proper cleanup begin.
The pattern is the same regardless of the business, from local services to online shops. Why such infections come back is explained in detail in Infection returns after cleanup.
Shared hosting with several sites

If you keep several sites in the same hosting account, for example the company site, an old site and a test version, a nulled theme on one of them puts all of them at risk. The backdoor usually has access to the entire account, so the attacker can infect sites that never had pirated software. During a cleanup, every site in the account should be reviewed, not just the one where the problem was noticed. Old and abandoned installations are best removed completely.
How to tell whether your site uses nulled software
Many owners don't know they have it, because they didn't build the site themselves. Here are the signs to look out for.
No licence and no updates
A premium theme or plugin should come with an invoice or an account with the vendor and a licence key. If none of that exists but the theme is "activated", it's probably nulled. Another signal: the admin area never shows a new-version notice for that theme or plugin, even though the author releases updates regularly.
Odd licence messages
Some nulled packages display messages like "Licence activated by…" with the name of some website, or have the licence field filled with a random string of characters.
Files that aren't in the original
If you have access to the original version of the same theme or plugin, compare the file lists. Extra PHP files, especially with names that look like system files, or changes in main files such as functions.php, are a clear sign the package was modified. Security scanners that compare files with the originals (they do it automatically for plugins from WordPress.org) can help too.
Suspicious code
Searching theme and plugin files for functions often used to obfuscate code (eval, base64_decode, gzinflate, str_rot13, assert) and for unknown external addresses often reveals injected code. On their own these functions aren't proof, because legitimate code sometimes uses them too, but long obfuscated strings in a theme that shouldn't have them are a serious warning sign.
Ask whoever built the site
If an agency or freelancer built the site, ask for a list of the premium themes and plugins and their licences. A serious agency will have it. If the answer is vague, assume there are no licences.
What to do if your site uses a nulled theme or plugin

Use this checklist whenever nulled wordpress themes plugins shows up again after a partial cleanup.
1. Don't try to "clean" the nulled file
The instinct is to find and remove the injected code and keep the rest. That's a bad idea. You can never be sure you've found everything, and you're still left without updates. The only right path is replacement.
2. Get the original version or an alternative
- Buy a licence for the same theme or plugin from the author or the official marketplace, and download the original files. With themes, settings are usually stored in the database, so replacing the files doesn't change how the site looks. Still, make a backup before replacing anything.
- If a licence isn't an option, look for a free alternative in the official WordPress.org repository. For most needs (forms, caching, SEO, galleries) there are good free plugins that are updated regularly.
- If the theme is fully customised and no original exists, the site needs a file-by-file review, or you should consider a new, clean theme. That's more work, but it's a one-off.
3. Assume the site is already infected
If the nulled software has been on the site for a while, assume the backdoor has already been used. Do a full review: replace core and all plugins with clean copies, review the uploads folder and the database, and check the users. How to look for a backdoor is described in How to find a WordPress backdoor.
4. Change all access credentials
Change the passwords for hosting, FTP, the database and all administrators, and the security keys in wp-config.php. Review the administrator list, because nulled code often creates hidden accounts. More in Unknown admin account in WordPress.
5. Check Google
Search site:yoursite.com together with words like casino, viagra or bonus to see whether the nulled code has already been injecting spam. If it has, see Spam links in my site's Google results.
Legal and business risks
Security is the main problem, but not the only one.
Copyright on design and content. Even though the PHP code of themes and plugins is usually GPL, the photos, icons, fonts and demo content that come with a premium theme often have their own licences. Using them without a licence can lead to takedown or compensation claims.
Obligations towards customers. If the site collects customer data, for example through an online shop or a form, you're responsible for protecting it. Knowingly running software of unknown origin is hard to justify if there's a data leak.
Partners' trust. More and more companies, especially larger ones and public institutions, require basic security standards from their suppliers. Pirated software on your site is a poor start to that conversation.
What a "free" theme actually costs

Owners often underestimate nulled wordpress themes plugins until Search Console or clients raise the alarm.
Compare two situations.
Original theme and plugins: a few dozen euros for the theme, and usually a few dozen euros a year per premium plugin. For that you get updates, support and files you know the origin of.
Nulled theme and plugins: zero euros up front. Then, when the infection activates:
- cleaning the hacked site, which starts at €100 with us and costs more for large infections,
- days or weeks of a Google warning or spam results,
- lost enquiries and sales while the site isn't working properly,
- possible problems with your host suspending the account for abuse,
- the time you and your team spend on all of it,
- and finally, buying the original licence anyway, because without it the problem repeats.
The "saving" usually comes back many times more expensive, and the biggest part of the cost isn't even the cleanup invoice but lost client trust and the time the site isn't working as it should. More on what affects the cleanup price in How much does cleaning a hacked site cost.
If you're commissioning a site: what to ask the developer for
If an agency or freelancer is building your site, a few simple requirements protect you from this problem:
- A list of all premium themes and plugins that will be used.
- Licences in your name or your company's, or at least a clear agreement on who pays renewals and where the licences are held.
- Access to the vendor accounts, or transfer of the licences to you at the end of the project.
- A written guarantee that there's no pirated software on the site.
- An agreement on updates after handover: who does them and how often.
A low price for building a site is sometimes possible precisely because the developer saved on licences. That's not always the case, but it's worth asking up front.
How to choose themes and plugins safely

Avoiding pirated versions isn't enough on its own. Even an original plugin can be risky if its author no longer maintains it. Before installing, check:
- The source. The WordPress.org repository, the author's official site or a well-known marketplace. Not links from forums and social media.
- The last update. A plugin that hasn't been updated for a year or more is probably abandoned.
- Compatibility with your WordPress and PHP versions.
- Active installations and ratings. Not a guarantee, but a plugin used by many sites gets fixes faster when a problem is found.
- Its vulnerability history. A quick search for the plugin name with the word "vulnerability" shows whether it has had serious problems and how quickly the author fixed them.
- Whether you really need it. Every plugin adds attack surface. Fewer plugins means less risk.
How to reduce the risk after the replacement
Replacing nulled software removes one source of problems, but the site still needs maintenance. The basic rules:
- download themes and plugins only from official sources (WordPress.org, the author's site, an official marketplace),
- update regularly, ideally once a week,
- remove themes and plugins you don't use,
- use strong passwords and two-factor authentication for administrators,
- make regular backups stored off the server.
The full list of measures is in the guide Protect a WordPress site from hacking.
Next step

If you suspect your site uses a nulled theme or plugin, or it was built by someone who didn't give you the licences, run a free website check to see whether signs of infection are already visible from the internet. For a full review of files and database, replacement of pirated software and a cleanup, get in touch or call +381 65 402 5000. If you want the site to stay updated and monitored afterwards, our maintenance plan starts at €30 a month.