A premium WordPress theme that normally costs a few thousand rupees is offered free on a download site. It looks identical and installs fine. The catch is what you cannot see: who changed the code, and what it will do on your server. This guide explains what pirated themes and plugins really do to a website, how to check the ones you already use, and what to do if you have installed one.
A pirated ("nulled") theme or plugin is a paid product with its licence check removed and shared for free, often with hidden code added by whoever shared it. That code can open a backdoor, add spam links, redirect your visitors or steal logins, and because the copy can never be updated, every security hole found later stays open. Use free themes from the WordPress.org directory or buy from the original developer. If you already use a nulled copy, replace it with a genuine one and check the whole site for anything it left behind.
1. What "nulled" and "pirated" actually mean
A nulled theme or plugin is a commercial product whose licence check has been removed or bypassed ("nulled out"), so it runs without a purchase. Download sites, Telegram channels, YouTube descriptions and some "free premium theme" blogs share them. The same thing happens with Joomla templates, Drupal modules, OpenCart and PrestaShop extensions, and ready-made PHP scripts.
Removing a licence check means editing the files, and once a stranger has edited them you cannot know what else was changed. The download site also has to earn money somehow; often the payment is your website's search ranking, visitors or server.
"GPL clubs" that resell premium themes cheaply are a grey area. Much WordPress theme code is GPL licensed, so these copies are not always illegal, but you get no support or official updates from the developer and must trust the reseller not to have altered the files.
2. What hidden code in a nulled theme does
Security researchers have repeatedly found malware bundled into nulled WordPress themes and plugins. One long-running family, known as WP-VCD, spread almost entirely through nulled themes: it created a hidden administrator account, injected spam and ads, and copied itself into every other theme in the same hosting account.
The code is usually disguised: scrambled with functions such as base64_decode, gzinflate or eval, hidden in a harmlessly named file, or set to activate after a few days, so the theme seems fine when you test it.
All websites inside one hosting account run as the same user and share the same files. Malware from a nulled theme on a test site can spread to your main business site in that account. Server isolation protects you from other customers, not from your own files.
3. No updates means known holes stay open
Genuine themes and plugins receive updates for security fixes, new WordPress versions and PHP changes. A nulled copy cannot receive them: the update check needs a valid licence, and applying an official update would remove the "free" unlock anyway.
Once a fix is public, bots scan the web for sites still on the old version. A nulled copy stays on it for ever, so a hole that genuine customers patched months ago is still open on your site. It also breaks sooner or later after a WordPress or PHP update, and you cannot ask the developer for help.

For how attackers exploit outdated plugins and themes in general, read Why and how your WordPress website gets hacked.
4. Legal, licence and hosting risk
Using pirated software is copyright infringement. In India, the Copyright Act, 1957 treats knowingly using an infringing copy of a computer program as an offence, and developers can also send takedown notices or make civil claims. The practical risks for a business:
- Hosting action. Domain India's Acceptable Use Policy prohibits hosting malware and distributing pirated software, and violations can lead to suspension of the account.
- Agency-built sites. If a designer built your site with nulled products, your business is still the one running them. Ask for the licence keys to be registered to you.
- Customer data. If a backdoor leaks customer data, you are responsible for it, whatever the cause.
5. Pirated vs genuine: the real comparison
| What you get | Nulled or pirated copy | Free theme from WordPress.org | Paid theme from the developer |
|---|---|---|---|
| Upfront cost | Nothing | Nothing | One-time or yearly licence |
| Code you can trust | No, altered by an unknown person | Reviewed before listing in the directory | Yes, from the author |
| Security updates | Never | Yes, through your dashboard | Yes, while the licence is active |
| Developer support | None | Community support forum | Yes |
| Hidden malware risk | High | Low | Low |
| Legal and hosting risk | Yes | None, GPL licensed | None |
| Cleanup cost if it goes wrong | Often far more than the licence | Rare | Rare |
The "saving" from a nulled theme is the price of one licence. The cost of a hacked site is lost sales, a Google warning, cleanup time, and sometimes a blacklisted email domain that takes weeks to recover.
6. How to check a theme or plugin you already use
If someone else built your site, or you are not sure where a theme came from, check it.
- Find the source.A genuine premium product has a purchase receipt and a licence key registered on the developer's site.
- Check updates.A licensed theme gets updates in Dashboard > Updates. One that has never updated is a red flag.
- Look for obvious signs.Unknown administrators, pages you did not create, strange footer links, or files with random names in the theme folder.
- Scan the account.Use your control panel's security tool and a security plugin such as Wordfence or Sucuri Security. Scanners can miss new or custom backdoors, so a clean scan is not proof.
- Compare with the official version.Download a fresh copy from the developer or WordPress.org and compare the files. Any extra or changed file needs explaining.
With SSH access, run these in your WordPress folder (replace your-theme with the theme's folder name):
# Obfuscated code often uses these functions (some legitimate code does too)
grep -rnE "eval\(|base64_decode\(|gzinflate\(|str_rot13\(|create_function" wp-content/themes/your-theme
# PHP files do not belong in the uploads folder
find wp-content/uploads -name "*.php"
# Every administrator account on the site
wp user list --role=administrator
# Core files and WordPress.org plugins that differ from the official release
wp core verify-checksums
wp plugin verify-checksums --allwp plugin verify-checksums only covers plugins from WordPress.org. Also look in wp-content/mu-plugins, a folder that loads code automatically and is a favourite hiding place.
7. Safe alternatives that cost little or nothing
- Free themes from the WordPress.org directory. They are reviewed before listing and update through your dashboard. Many popular themes have a free version with a paid upgrade; start free and upgrade when you need it.
- Buy from the original developer or an established marketplace such as ThemeForest. Download only from your own account there and register the licence key so you get updates. Many licences renew yearly for updates; budget for that.
- Use the block editor. Modern block themes and WordPress's site editor cover many layouts that once needed a premium page builder.
- Skip themes entirely. For a simple business site without managing themes and plugins, the AI Website Builder builds and hosts the site for you.
For theme ideas, see Popular WordPress themes.
8. What to do if you already installed a nulled theme or plugin
Do not just switch themes. Deactivating leaves the files on the server, and any backdoor planted elsewhere keeps working.
- Take a full backup first.Files and database: your evidence and safety net.
- Replace it with a genuine copy.Buy a licence or pick a free alternative, then delete the nulled folder completely.
- Check what it left behind.Remove unknown administrators. Look for PHP files in
uploads, unknown files inmu-plugins, and recently changed files in other themes and plugins. - Change every password.WordPress, control panel, FTP, database and email. Also generate new security keys (salts) in
wp-config.phpto sign out every session. - Scan again and watchfor new users and file changes over the next few weeks.
- If you see signs of a hack, such as redirects, spam pages, unknown admins or a browser warning, follow the full security checklist for a hacked or defaced website. If Google shows a warning, also read How to handle the Google "Dangerous site" warning.
Restoring a backup taken before the nulled theme was installed can be quicker and cleaner than hunting through files. Then reapply genuine content changes and install the licensed theme.
9. Where Domain India hosting fits
Domain India's cPanel and DirectAdmin shared hosting plans include server-side security: CloudLinux account isolation, Imunify360 security with malware scanning, a web application firewall, DDoS protection and free SSL; Webuzo plans have Imunify malware scanning and free SSL. Jailed SSH access for the checks in section 6 is available on every plan on request (it is off by default), and every plan includes backups (weekly on cPanel and DirectAdmin, nightly on Webuzo). See how to use Imunify360 and how to restore a backup with JetBackup.
Hosting cannot make a nulled theme safe: a backdoor you install runs with your account's own permissions, and a scanner may not recognise new code. The only real fix is not to install it.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
On Domain India list prices on 19 September 2026, excluding 18% GST, cPanel Starter is ₹125 a month and DirectAdmin Starter is ₹100 a month. Compare every plan on cPanel hosting and DirectAdmin hosting.
What is a nulled WordPress theme?
A paid WordPress theme whose licence check has been removed so it can be used without buying it. It is shared free on download sites, often with hidden malicious code added, and cannot receive the developer's updates.
Are all free WordPress themes dangerous?
No. Free themes from the official WordPress.org theme directory are reviewed before they are listed and receive updates through your dashboard. The danger is "free" copies of paid themes downloaded from unofficial sites.
Can a security plugin make a nulled theme safe?
No. Scanners detect known malware, but a new or disguised backdoor can be missed, and a nulled theme never receives security updates. Replace it with a genuine copy.
Is it enough to deactivate a nulled theme?
No. Deactivating leaves the files on the server, and any backdoor the theme created elsewhere keeps working. Delete the theme folder, remove unknown administrators and files, and change all your passwords.
Are GPL themes sold by third-party sites legal?
Much WordPress theme code is GPL licensed, which allows redistribution, so these copies are not always illegal. But you get no support or official updates from the developer and must trust the reseller not to have altered the files. Buying from the developer is safer.
Will my hosting account be suspended for using a pirated theme?
It can be. Domain India's Acceptable Use Policy prohibits hosting malware and distributing pirated software, and violations can lead to suspension.
Ready to replace a pirated theme with a safe one? Check your site with the steps in section 6, read Why and how your WordPress website gets hacked to close the other common routes in, and if you need help with your hosting account, use live chat or open a support ticket.
Every Domain India shared hosting plan includes CloudLinux account isolation, Imunify360 security, a web application firewall and free SSL.
See cPanel hosting plans