A "free" version of a paid plugin? The most expensive mistake on a site
It is tempting. A paid plugin costs a few hundred zloty a year, and somewhere on a forum or in a "bundle" the same plugin sits for free. These are so-called nulled versions, pirated copies of paid plugins and themes with the licence check removed. It looks like a bargain. In practice it is one of the most common ways sites catch an infection, and by their own doing.
Why someone gives away paid plugins for free
That is the first question worth asking. Nobody hosts and promotes someone else's paid software out of kindness. The business model of piracy is your site. The person who "freed" the plugin usually adds something of their own: hidden code that gives them access to your site after installation.
The rule is simple: if you do not pay for the product, you are the product, and in this case your site and its visitors.
What actually sits in such a plugin
The malicious code hidden in a pirated plugin can do very different things, usually quietly:
- create a hidden administrator, so the attacker has permanent access,
- inject spam and links into your pages (which destroys your Google ranking),
- redirect some visitors to foreign, dangerous sites,
- send spam from your server (getting the domain onto blacklists),
- in shops, intercept card data at checkout.
The worst part is that the plugin works normally. It does what it is supposed to, so you have no reason to suspect it is also working against you.
"I will scan it with antivirus": that is not enough
The code in such plugins is often deliberately obfuscated and hidden so it does not stand out, to a person or to simple scanners. Some of it activates only after a while or when a condition is met. Assuming "I will look it over and it will be fine" is risky, even specialists can miss a well-hidden fragment.
What "saving money" really costs
Let us count for real. A plugin licence: say 300-600 zloty a year. The cost of cleaning an infected site, downtime, lost Google rankings and lost customer trust: many times more, and sometimes irrecoverable. On top of that, the pirate will not give you security updates anyway, so over time the plugin becomes vulnerable "officially" too.
How to do it right
- Buy plugins and themes from official sources: from the author, the WordPress repository or trusted stores (e.g. the official CodeCanyon rather than a random bundle from a forum).
- Choose actively developed add-ons: regularly updated, with real support.
- If the budget is tight, look for a free but legitimate alternative instead of a pirated paid version. Very often one exists.
- If you have something from an uncertain source on the site, treat it as a priority to replace.
Not sure what sits on your site?
If the site was built by someone else or "put together from what was available", it is worth checking whether it contains pirated add-ons and hidden code. We run such reviews regularly, we find suspicious elements, point to legitimate replacements and clean up what is needed. Get in touch, we will check your site.