> However, the only real solution to this problem is to run a limited set of extremely trustworthy plugins and build your own themes.
What on earth? It's pretty simple to check for malicious Javascript or PHP code in a theme.
What on earth? It's pretty simple to check for malicious Javascript or PHP code in a theme.
1) Anything linked outside of the domain. 2) Anything not HTML/CSS/image/Wordpress tag/Javascript libraries 3) Anything encrypted.
Let me know if I missed anything.
Do you scan the CSS for url() references outside of the domain?
Most of the time I use a Wordpress theme as a starting point, rewriting some parts and looking over all of the code.
Also, mentioned above, securing the theme against injections and XSS is important.