{"id":18987663,"date":"2026-08-07T21:47:31","date_gmt":"2026-08-07T21:47:31","guid":{"rendered":"https:\/\/wordpress.org\/support\/?post_type=topic&#038;p=18987663"},"modified":"2026-08-07T22:03:50","modified_gmt":"2026-08-07T22:03:50","slug":"this-plugin-fits-the-definition-of-malware-and-should-be-blacklisted","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/this-plugin-fits-the-definition-of-malware-and-should-be-blacklisted\/","title":{"rendered":"This plugin fits the definition of Malware and should be blacklisted."},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">This plugin was randomly installed <em>and<\/em> <em>activated<\/em> on every single WordPress site hosted at Siteground. Siteground customers did not consent to the installation of this plugin, nor was the action disclosed by Siteground. The software was added automatically \u2013 with AI connectivity \u2013 which means it has the ability to perform a stunning amount of damage to individual sites, shared servers, and the Siteground ecosystem as a whole.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Considering AI was not invented by Siteground, that also means it has the ability to contact remote servers controlled by third-parties. The plugin obnoxiously inserts itself into every page on the frontend AND admin panel of every site for administrators \u2013 breaking layouts, accessibility, and causing undue hardship to every customer who has to manually purge this MALWARE.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">All of this information is factual. Now, read how Cisco \u2013 an enterprise leader in IT \u2013 says the following classes of malware are DEFINED:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Viruses<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A computer virus is a type of malware that propagates by <strong>inserting a copy of itself<\/strong> into and becoming part of another program. It spreads from one computer to another, leaving infections as it travels. Viruses can range in severity from causing <strong>mildly annoying effects<\/strong> to <strong>damaging data or software<\/strong> and causing denial-of-service (DoS) conditions. [&#8230;] Normally, the host program <em>keeps functioning<\/em> after it is infected by the virus. However, some viruses overwrite other programs with copies of themselves, which destroys the host program altogether. Viruses spread when the software or document they are attached to is transferred from one computer to another <strong>using the network<\/strong>, a disk, file sharing, or infected email attachments.<\/p>\n<cite><strong>Cisco<\/strong><\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Let&#8217;s see if any of that applies to this plugin, shall we? Here we go:<\/p>\n\n\n\n<ul>\n<li>Propagates by inserting a copy of itself and becoming part of another program? \u2705 Yes.<\/li>\n\n\n\n<li>Did it spread from one computer\/server to another, leaving infections as it went? \u2705 Yes.<\/li>\n\n\n\n<li>Did it cause mildly annoying effects, damage data, or cause a denial-of-service? \u2705 Yes.<\/li>\n\n\n\n<li>Does the AI in this plugin have the ability to overwrite or destroy other programs? \u2705 Yes.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Okay, so the plugin \u2013 at the very least \u2013 loosely fits the definition of a virus. Let&#8217;s move on to the next one:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Worms<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Computer worms are similar to viruses in that they replicate functional copies of themselves and can cause the same type of damage. In contrast to viruses, which require the spreading of an infected host file, worms are standalone software and <strong>do not require a host program or human help to propagate<\/strong>. To spread, worms either <strong>exploit a vulnerability on the target system<\/strong> or use some kind of\u00a0social engineering\u00a0to <strong>trick users into executing them<\/strong>. A worm enters a computer through a vulnerability in the system and takes advantage of file-transport or information-transport features on the system, <strong>allowing it to travel unaided<\/strong>. More advanced worms leverage encryption, wipers, and ransomware technologies to harm their targets.<\/p>\n<cite><strong>Cisco<\/strong><\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Okay, more specific&#8230; but let&#8217;s do the comparison, anyway:<\/p>\n\n\n\n<ul>\n<li>Similar to a virus because it replicated itself and can cause the same type of damage? \u2705 Yes.<\/li>\n\n\n\n<li>Did the plugin run without requiring the host program or human help to propagate? \u2705 Yes.<\/li>\n\n\n\n<li>Did the plugin exploit a Siteground vulnerability or trick users into executing it? \u2705 Yes.<\/li>\n\n\n\n<li>Did the plugin take advantage of the system&#8217;s file-transport features to travel unaided? \u2705 Yes.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Not looking good. That said, we have more definitions to cover because it&#8217;s \u2728Siteground\u2728 who will surely be allowed to continue this behavior:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Trojans<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A Trojan is another type of malware named after the wooden horse that the Greeks used to infiltrate Troy. It is a harmful piece of <em>software that looks legitimate<\/em>. <strong>Users are typically tricked into loading and executing it on their systems.<\/strong> After it is activated, <strong>it can achieve any number of attacks<\/strong> on the host, from <em>irritating the user<\/em> (popping up windows or changing desktops) to damaging the host (deleting files, stealing data, or <strong>activating and spreading<\/strong> other malware, such as viruses). Trojans are also known to create backdoors to <strong>give malicious users access to the system<\/strong>. Unlike viruses and worms, Trojans do not reproduce by infecting other files nor do they self-replicate. Trojans must spread through user interaction such as opening an email attachment or downloading and running a file from the Internet.<\/p>\n<cite><strong>Cisco<\/strong><\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Let&#8217;s see if the good people of Sparta recognize this plugin:<\/p>\n\n\n\n<ul>\n<li>Harmful piece of software that looks legitimate? \u2014 It certainly harmed <em>some<\/em> users. \u2705 Yes.<\/li>\n\n\n\n<li>Did Siteground trick users into loading and executing it on their systems? \u2705 Yes.<\/li>\n\n\n\n<li>Is the plugin&#8217;s AI able to achieve any number of attacks on the host after activating? \u2705 Yes.<\/li>\n\n\n\n<li>Does the plugin have the potential to give malicious users access to the system? \u2705 Yes.<\/li>\n\n\n\n<li>Does the plugin fit the Trojan definition of being unable to self-replicate? \ud83d\udeab No.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Phew&#8230; close one \u2014 the plugin almost fit the definition of a Trojan there. Good thing it has the ability to self-replicate by infecting other files and systems autonomously. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>WORDPRESS \u2014 DO THE RIGHT THING AND REMOVE THIS PLUGIN FROM THE REPOSITORY.<\/strong> It provides NO value-added after Siteground customers run out of their sample credits. It&#8217;s an involuntary cash-grab that doesn&#8217;t benefit any WordPress users outside of Siteground&#8217;s ecosystem \u2014 and even the <em>idea<\/em> of it offering anything beneficial is <em>highly<\/em> <em>questionable<\/em>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Shame on you, <em>Siteground<\/em>.<\/p>\n","protected":false},"template":"","class_list":["post-18987663","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18987663","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":1,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18987663\/revisions"}],"predecessor-version":[{"id":18987669,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18987663\/revisions\/18987669"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=18987663"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}