MB Bluejuice
Security

eval, base64_decode and other traces of hidden code

How to recognise obfuscated code in WordPress files, and why looking only in the theme is not enough.

· updated 2026-10-07

Malicious PHP is almost never readable. It is obfuscated so that it is not obvious when reading a file and not caught by a simple keyword search.

Typical patterns

  • eval(base64_decode('...')) — the classic, still around;
  • gzinflate(str_rot13(...)) — multi-layer decoding;
  • $GLOBALS['...'] with random variable names;
  • one extremely long line at the start or end of a file;
  • a file that begins with blank lines before <?php;
  • file_get_contents or curl pointing at an unfamiliar domain.

Where to look, besides the theme

Usually only the active theme gets checked. In practice we also find code here:

  • wp-content/uploads — PHP files have no business being there;
  • inactive themes and plugins — unused but still reachable;
  • wp-includes — one foreign file among hundreds is hard to spot;
  • in the database, in wp_posts and wp_options.

The reliable method

Compare core and plugin files against the official archives by hash. Anything that does not match is either your own modification or a problem. That is faster and more reliable than pattern matching — obfuscated code can look like anything, but it cannot hide a mismatch.

Next

Related articles

Need help with your website?

We will review your situation and tell you what to do first.