Recently I had a client who had downloaded a free WordPress theme for their website. It was not a good situation, but more on that later. The site they downloaded it from was not the WordPress.org theme catalog. It was just a site they found in Googling that offered free themes. The theme contained malware and spam links that caused the site to become blocked by protected browsers. It seems that free WordPress themes from sources other thanWordPress.org often contain malware. A recent post by Siobhan Ambrose carefully reviews the first ten Google “free wordpress themes” search results and their themes for malware and other problems. The take away lesson is that 90 percent out of the first ten sites were providing dodgy themes, with 8 sites (that’s 80%) having themes with actual malware. The only search result without malware or other problems in free themes? WordPress.org!
As Lorelle writes, free themes that come with malware have the ability to “integrate into your site, even down to the server level, through a twisting path of imaginative code. … This code has the ability to activate, create trouble, then erase its path, making it tough to detect, test, and eliminate.”
Why are WordPress.org free themes safe? Because WordPress uses malware detection programs for the initial review. Then if it passes that, but before a theme is presented for download, it is carefully reviewed with the code inspected by hand by a team including leading website and WordPress security specialists. If you want to learn more about WordPress malware, read this post titled Anatomy of a Theme Malware by Otto.
In the case of my client it even infected his other themes. No part of his site was really left untouched. It took over 10 hours (it is a very large site) of time to find, scrub and restore his site. Just from simply downloading and installing a free theme from a source other than WordPress.org. So if you want a new blog/site look, I suggest you contact a good WordPress site creator (like me). We often can point you to a free theme that is “clean”, or even provide it for you. Or is you want something that is unique we can often redesign your blog/site theme in less time than it would take to “disinfect”. It is also why I offer my clients free built-in automatic usability and security upgrades that assure their blog/site will always work with the latest, most powerful and secure versions of WordPress.












