Malware or not? | WordPress.org

Moderator
Yui

(@fierevere)

ゆい

Its something that displays ads on your site.

You can get over several thousand good and safe themes here:
https://wordpress.org/themes/

dont use junk you can find all over the internet. Its unsafe approach.

Check this too:
the recommended security measures

thank you Yui , actually, he told me that he bought a premium WordPress theme and added hem as admin to get the ability to install the theme , i discovered that my website is too slow so i started checking in between files and i found that , i really appreciate your help

Moderator
Yui

(@fierevere)

ゆい

If you are a newbie with WordPress, it is best to start with something from official theme repo, https://wordpress.org/themes/
or even a default preinstalled theme. You can learn things and have a (almost*) bug free experience.

Later when you understand what exactly you want to get from your site you can look for other themes, plugins to expand site features.
Maybe a paid theme can be a good choice (most premium themes have their free lite sibling, to try).

In any case, you should get paid theme from verified vendors, who include money-back possibility and technical support for their product.

Some vendors listed here https://wordpress.org/themes/commercial/
ThemeForest seems to be a safe place to buy themes too.

Mmm.
Uninstalling the theme may not actually be enough to get rid of this, unfortunately.
You may want to check your list of active plugins and ensure that you remove anything that is not supposed to be there.
You may also want to deregister all of the options created by the code.

Thank you so much Yui for your help and your time , you were very polite and helpful

Moderator
Jan Dembowski

(@jdembowski)

Forum Moderator and Brute Squad

Malware or not?

Malware. As stated above you need to delouse your site. I have removed the code from your post as these forums are not for trying to fix infected themes. There’s just no point as that theme is loaded with many back doors.

*Drinks coffee*

The person who told you they “bought a premium WordPress theme and added hem as admin to get the ability to install the theme” owes you a massive apology as that’s certainly how your site is now under new management and not yours.

Thank you Carike for your answer , theme is beautiful i like it but unfortunately i doubt that there are malicious codes , is there any way to clean the theme frome malicious codes please

If you have a backup from before you installed the theme, please consider restoring it.
It will likely take you a lot less time to re-create any content than it will to make sure all traces of that thing is gone.

Alternatively, audit every file in your directory, as well as every entry in your MySQL table.

Moderator
Jan Dembowski

(@jdembowski)

Forum Moderator and Brute Squad

is there any way to clean the theme frome malicious codes please

Please stop this.

*More coffee, so good*

You did an amazingly unwise thing. You’re using a theme that you should not be using and aside from helping you delouse your infected site, please do not try and use these forums to support an amazingly unwise thing you did.

As an example: you need a car. Your “friend” gets you one that looks nice, seats many and drives fast. Now you’ve found out that

  1. The car has no brakes
  2. The steering fails every 90 seconds
  3. The owner of the car wants to talk to you and your “friend”
  4. You’ve already been hurt trying to drive the car
  5. People trying to help you says that the car is smoking
  6. The car is in fact on fire and is now igniting your house

and you’re saying “the car is beautiful, can you help me with the driver’s door?”

Please stop. Lose that theme and delouse your site.

Moderator
Yui

(@fierevere)

ゆい

any way to clean the theme frome malicious codes

The best way to clean this theme is to get rid of it. Completely.
And the best way to do so – restore a backup, files and database.

Thank you Yui, I’ll do that, I apologize for wasting your time.

  • This reply was modified 4 days, 18 hours ago by gentle2309.

You did not waste our time.
The only reason why we are being so insistent on you restoring a backup from before you installed the theme is because we have very, very good reason for it after reading the code.
It does some very, very bad things and creates the capability of doing more. Like Jan said, you are no longer in control of your site.



Source link