I have written quite a number of post warning WordPress users about “dirty themes” which contains malicious codes or hidden links. These codes will not break anything and users, especially those who are using those “free” premium themes like the Thesis, will not notice any difference or find anything funny happening to their blog.
Other than the “free” premium themes, there are also many sites that gives away very well designed WordPress Themes. Most of these are sponsored themes, which means the theme designers makes some money by getting sponsors to pay for his time and effort and in return, the sponsors gets his links inserted in the footer of the Themes. It is a very effective link building method. A popular Theme might get thousands of downloads and even if half of them removes the footer links, the sponsors still gets hundreds of links for a single one time payment.
It is however best that the Themes we are using is free from any unwanted codes or links. Though it might not break the Theme, users might get banned by Google for these links.
To make sure your Theme is clean and safe to use, you can and I highly recommend, install a WordPress plugin called TAC (Theme Authenticity Checker). This plugin scans all of your theme files for potentially malicious or unwanted code and if such code is found, TAC displays the path to the theme file, the line number, and a small snippet of the suspect code. It is up to you then, to decide whether to continue using the Theme or contact the Theme developer for further clarification.
As the plugin is listed in the WordPress Plugin Directory, Installation can be automatically done via your WordPress admin dashboard. Just go to Plugins – Add New and in the Search window type in TAC.





More security consideration you will find on my blog
Don’t you think, that with this tip, you are most likely helping people, using pirated themes that they have downloaded for free because they are too cheap to spend 50$ on a theme?
Well.. not really Mitco, I am just helping them to confirm if their Themes contains malicious codes or not.
The plugin only detects the dirty codes and does not have the ability to get rid of those codes for them. Hopefully, on realizing the that their Themes are not clean, they would opt for he real thing.
I see, but I still think that people will misuse it for just “cleaning” their “dirty” version.