Hello,
The code you exemplified does not come from the theme. Please check the files with winmerge and compare the default theme files to yours to see any at all code changes from the original files. Maybe your site got infected with mallware. If you identified the file in question, it’s easy to check it with winmerge and compare it to the main file from the package you download from envato.
Let us know how it goes.
Thank you!
Hello,
The code does not come gfrom our theme nor is the code mallicious in any way. Wordfence detects it that way but these tools are not always right. Please check this topic: http://codecanyon.net/item/visual-composer-page-builder-for-wordpress/242431/comments?utf8=%E2%9C%93&term=+base64_decode&from_buyers_and_authors_only=0
This is the official response from the plugin author:
Hello, this is basically problem with Wordfence – the code used there has no harm and it can stay this way.
Thank you!
These are the following path which are consisting of eval and base64_decode.Let me also inform you that it is a fresh install with wordpress.After i install the visual composer , again many path will have files under it containing eval and base64_decode.
wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/td_view_import_export_settings.php:33
wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/td_view_update_newspaper_6.php:347
wp-content/themes/Newspaper/includes/wp_booster/wp-admin/external/ace/worker-css.js:1
wp-content/themes/Newspaper/includes/wp_booster/wp-admin/external/ace/worker-javascript.js:1
wp-content/themes/Newspaper/includes/wp_booster/td_block.php:556
Please help
After installing the Visual Composer the following paths are showing files having eval and bas64_decode
wp-content/plugins/js_composer/assets/js/dist/frontend-editor.min.js:3
wp-content/plugins/js_composer/assets/js/dist/backend.min.js:5
wp-content/plugins/js_composer/assets/lib/php.default/php.default.min.js:310
wp-content/plugins/js_composer/assets/lib/php.default/php.default.min.js:314
wp-content/plugins/js_composer/include/classes/shortcodes/vc-raw-js.php:22
wp-content/plugins/js_composer/assets/lib/php.default/php.default.min.js:625
Hi,
Well not all tools that say you have malicious code or other anomalies are correct. Visual composer states the same about wordfence:
Hi, we always test Visual Composer to be 100% safe – also our 3rd party developers check it and Envato as well. So if you purchase Visual Composer directly from WPBakery you can be 100% sure there are no malicious files in there. As for Wordfence – we personally doubt this plugin, because of the several cases in the past when it acted on such things like shortened URLs and so on.
To follow along with the plugin authors, we at TagDiv assure you there is no exploit or malicious code in our themes or the version of visual composer we provide and these tools are highly doubtful. In order to make a correct assesment, you neet to use more tools, not a single opinion from an untested plugin. We cannot say for sure what the plugin detects as I have checked all of the lines fo code mentioned in the errors you received but there is nothing potentially harmful there. You can rest assured there is no threat. A premium theme is built with custom code and plugins cannot detect this. WordPress plugins are created on the standard wordpress code and cannot recognize custom functions that we use. That is why it detects threats as the code is not in the standard wordpress codex. This is the case with all premium themes.
Thank you!
Hello,
Ive purchased the Newspaper 8.8 theme a few minutes ago at Envato Market, downloaded it directly from Envato to my copmuter and checked it for malicious code before uploading to my webserver. It says that it contains the following issues:
Security breaches : Use of base64_decode()
Security breaches : Use of base64_encode()
Presence of iframes : iframes are sometimes used to load unwanted adverts and malicious code on another site
Malware : Operations on file system
Malware : Network operations
Admin menu : Themes should use add_theme_page() for adding admin pages.
Is it safe to install your theme on my new Webserver? Can this code be used to hack my WordPress site or anything like this?
Thanks in advance!
Greetings
Hi,
The base64 encoding is used in many available themes and plugins
– https://developer.mozilla.org/en-US/docs/Web/API/WindowBase64/Base64_encoding_and_decoding
Our theme also uses it but there will be no security concerns in this matter. Also those detected issues like “iframes are sometimes used…” or “themes should use…” are in general, not applicable here.
I would like to state that the theme is perfectly safe to use as long as downloaded from themeforest. The present theme is the result of years of development and improvements, also it is constantly updated.
However if you deduce that our theme presents a risk for your website, we will be able to provide a full refund if requested.
Thanks