A premium plugin costs £59 a year. A search turns up the same plugin, same version, free. It installs fine. It works fine. Nothing appears to be wrong.
Then six weeks later the site is serving spam pages and nobody can work out how. Nulled plugins are one of the most consistent causes of compromise we encounter, and the reason is structural rather than accidental.
Ask who is paying for the distribution
This is the question that settles the matter.
Someone is running servers, paying for bandwidth, and maintaining a library of pirated plugins. They are not doing it out of principle. There is no advertising revenue that covers it.
The revenue model is the modified code. That is not a risk of using nulled plugins — it is the business.
Occasionally a file really is a clean copy. Frequently it is not, and you have no way to tell by looking.
What gets added
The modifications follow recognisable patterns.
A backdoor. A small function giving remote access, often disguised inside a legitimate-looking file. It waits, sometimes for months, before anything is done with it — because a dormant backdoor is not noticed.
Hidden link injection. Links to gambling, pharmaceutical or adult sites rendered invisibly on your pages. Human visitors see nothing. Search engines see everything, and your domain becomes part of someone else's link scheme.
An admin account creator. Code that quietly creates a privileged account, or recreates one after you delete it.
Callback code. Your site reports its address to a remote server, adding you to a list of known-vulnerable installations.
Update hijacking. The licence check is replaced so updates come from the pirate's server rather than the developer's. You are now taking code from an unknown party on an ongoing basis.
The problem beyond the malicious code
Even a genuinely clean nulled copy leaves you worse off, because you have cut yourself off from updates.
When a security vulnerability is found in that plugin, the developer releases a patch. You do not get it — you have no licence. Meanwhile the vulnerability is published, and automated scanning for it begins within days.
So you are running known-vulnerable code with no route to fixing it. That is a slow failure rather than a dramatic one, and it is why sites using nulled plugins get compromised repeatedly.
You also have no support, no compatibility fixes for new WordPress versions, and no recourse when something breaks.
How to check what you are running
Not everyone knows what a previous developer installed. Some practical checks:
- Look for premium plugins with no licence key. If a paid plugin shows no active licence and nobody in the business remembers buying it, that is your answer.
- Check for update warnings. Nulled copies often show "unable to check for updates" or nothing at all.
- Compare version numbers against the developer's site. A version that never advances is a strong signal.
- Ask the person who built the site. Directly. Where did each premium plugin come from and where are the licences?
- Search your files for
base64_decode,eval(andgzinflate— common in obfuscated injected code, though legitimate code occasionally uses them too.
If you inherited a site and cannot account for its premium plugins, treat that as a genuine unknown rather than an administrative detail.
What to do if you find one
- Do not simply deactivate it. Deactivated code remains on the server and can often still be executed.
- Delete it completely, files and all.
- Buy the legitimate version and install it fresh from the developer.
- Assume the site may already be compromised. Scan properly — files and database — and look for the backdoor.
- Change every password and check for admin accounts you do not recognise.
Step four is the one people skip. Removing the plugin does not remove what it installed. Our guide to removing malware from WordPress covers what to check.
The arithmetic
Say the licence is £59 a year. Set that against a realistic incident: an emergency clean-up, several days of lost traffic while Google shows a warning, customers who saw a redirect, rankings that take months to recover, and the time you spend on none of your actual work.
People often say they cannot justify the licence. It is worth noticing that the alternative is not free — it is an unpredictable cost, deferred, with interest.
Legitimate ways to spend less
The underlying budget concern is fair. There are honest answers to it.
Plenty of excellent free plugins on WordPress.org do what businesses actually need. Many premium plugins have capable free tiers. Most developers discount heavily in seasonal sales. Some offer lifetime licences that work out cheaper over a few years.
And often the real answer is fewer plugins. Sites accumulate them, and a genuine audit usually finds several doing very little. Removing three unused plugins pays for the one that matters.
If you are not sure what is on your site
Inherited sites are the common case here — a developer built it years ago, nobody knows the provenance of anything, and there is no licence documentation.
Our WordPress security and error fixing service includes a full audit of what is installed, whether anything shows signs of tampering, and whether the site is already compromised.
Once it is clean, our security monitoring service tracks what you run against published vulnerabilities so you are not relying on remembering.
Send us your web address and we will tell you what we can see, usually the same day.
Get Shielded
We build, host, secure and monitor business websites — cleaning up hacks and keeping sites online for clients across the UK, USA, Australia and the UAE.