Check your themes for hidden codes

If you search for ‘FREE WordPress themes’, a Google search will show about 23,400,000 results. That shows how easily you can locate a free WordPress theme of your choice and avoid spending money for buying themes. Quite nice idea, who wants to spend money unnecessarily, if you can get very good themes free? I too use such themes in some of my sites, and recommend them for my friends, especially new bloggers who do not want to spend on each everything required to setup a WordPress site. But, be careful while you select a free theme.

Recently I have read some articles by some renowned theme reviewers that cautioned about malicious hidden codes in themes using Base64 encoding schemes. After that, I have myself checked many themes and found that some of them contained malicious codes. For more insight into the seriousness of the problem, read the article Beware of Free WordPress Themes.

As you know, WordPress themes contain mainly PHP codes and other coding to make the themes functional. Some themes have been reported to contain hidden codes that are used to hide links to several sites that are not related to your blog or site, and they can be potentially harmful. So, any theme has to be evaluated carefully before installing and running on your server. A very popular method that can be used is using the plugin TAC (Theme Authenticity Checker) to check themes, especially free themes downloaded from unknown sites.

For those who do not know what ‘Base64’ is, it is a group of encoding schemes representing binary data of ASCII strings used for encoding binary data for storing and transferring to media which deal with text only. And Base64 codes are used in a lot of apps like ‘email via MIME (Multipurpose Internet Mail Extensions), XML, etc. So, Base64 itself is not harmful, but it becomes harmful or malicious when it is used to hide data, links/URLs that you do not want in your site or blog.

One of the most common misuses of Base64 is by spammers who use it to evade anti-spamming tools. These tools sometimes do not decode Base64, and hence Base64 is often used by the bad guys as their favorite method to harm others using internet in several ways.

So, if you like to use free themes, your first choice should be the collection of free themes available at WordPress. If you do not find any, you can search for free themes, from other sites. Even then it is better to go to a reputed theme site that may have some free themes too.

Also, I must say, I have found several feature-rich WordPress themes and other themes and templates that are as good as premium themes. Check for further posts in this site. I will be posting details, screen shots and site references from where you can download such trusted free themes.