WP-VCD, how pirated plugins infect the whole site
A paid plugin for free, downloaded "from a certain source"? Very often it is not a gift but a Trojan horse. The malware family called WP-VCD was for years one of the most common WordPress infections, and it spread exactly this way.
How it works
Pirated (so-called nulled) plugins and themes are modified by someone before being shared: hidden code is added. After installation WP-VCD:
- spreads to all themes on the site, to survive cleaning,
- creates a hidden administrator account and back doors,
- injects spam and hidden links (often to pharma or gambling sites), destroying your Google ranking,
- can infect other sites on the same server.
Why "free" ends up costing the most
You save a few hundred zloty on a licence, and you pay with site recovery, lost search rankings and lost customer trust. And because the malware multiplies files and accounts, simply removing the plugin does not cure it, the infection stays.
What to do
- Never install plugins and themes from "pirated" sources. Even if they work, you do not know what else they do in the background.
- If the budget is tight, look for a free, legitimate alternative in the official directory.
- Suspect something is already there? Look for foreign administrator accounts and unknown files in the themes.
A legitimate plugin is not a cost, it is insurance. And if the site is already showing symptoms, get in touch, we will check it and clean it thoroughly.