It’s script you can just read it guys, everyone fights so hard for open source and no one bothers reading anything.
It’s script you can just read it guys, everyone fights so hard for open source and no one bothers reading anything.
It took me all of 15 minutes to find code injections appended to the bottom of the code files.
...but that wasn't the interesting part. Since it was a very popular SEO plugin, I actually took the extra time and reported the attack code wordpress security scanners and the torrent site.
A month later I checked back and the plugin had been re-uploaded, but this time with the attack code heavily obfuscated and much more subtely hidden within the plugin.
...and this time when I reported it to the torrent site, the site admins banned me and actually IP blocked me.
tldr; The only open source code getting reviewed is heavily used stuff.
Pirated closed-source themes and plug-ins for WordPress is a very common source of malware on WP sites.