https://wordpress.org/plugins/about/guidelines/
And for stuff like phoning home without informed consent. Presumably the WordPress team has to check every line of code to do that, so they catch out any of said attacks during that check.
https://wordpress.org/plugins/about/guidelines/
And for stuff like phoning home without informed consent. Presumably the WordPress team has to check every line of code to do that, so they catch out any of said attacks during that check.
It's not a total ban, either: "However, note that some systems, like Paypal donation buttons, use encoded code as part of their normal operating mechanism. This is not considered to be 'obfuscated' as this is simply how these types of systems operate and it is not a choice by the plugin author."
That seems like a reasonably-sized loophole.
http://premium.wpmudev.org/blog/free-wordpress-themes-ultima...
The part about searching for themes in Google says that you get better results now than you used to.
As for what stops third party sites doing this? Well for paid ones, reputation. You allow through themes with lots of security issues and backdoors, and customers start getting hacked and well... people might start steering clear of you in future. So the marketplaces and theme shops have an incentive not to act like scumbags.
For free sites? Guess reputation there too. You're right that we could see this happen in some cases, but not doing the proper review process is a losing proposition for the site as well as the users.
The "Paypal" loophole is specifically because the first version of the guidelines had people constantly emailing us asking if this Paypal code snippet was okay. All the Paypal code snippet does (or used to do) is to include the relevant form data for "who to pay" in a base64 encoded mechanism instead of including the email address directly in the HTML code snippet. People didn't know what the code was, or if it was okay, and I wanted them to stop asking.
We still look for suspect code, and obfuscation that makes no sense is right out. We even reject minified JS, unless the minified JS is distributed from upstream code and can be verified to be unmodified from the original upstream source.