· updated 2026-10-07
Malicious PHP is almost never readable. It is obfuscated so that it is not obvious when reading a file and not caught by a simple keyword search.
Typical patterns
eval(base64_decode('...'))— the classic, still around;gzinflate(str_rot13(...))— multi-layer decoding;$GLOBALS['...']with random variable names;- one extremely long line at the start or end of a file;
- a file that begins with blank lines before
<?php; file_get_contentsorcurlpointing at an unfamiliar domain.
Where to look, besides the theme
Usually only the active theme gets checked. In practice we also find code here:
wp-content/uploads— PHP files have no business being there;- inactive themes and plugins — unused but still reachable;
wp-includes— one foreign file among hundreds is hard to spot;- in the database, in
wp_postsandwp_options.
The reliable method
Compare core and plugin files against the official archives by hash. Anything that does not match is either your own modification or a problem. That is faster and more reliable than pattern matching — obfuscated code can look like anything, but it cannot hide a mismatch.