In short

A nulled plugin is a paid plugin with the licence check stripped out. It works identically on day one. The difference appears the first time it needs a security fix, because the mechanism that would deliver one was removed before it was installed.

For every paid WordPress plugin there is a copy circulating with the licence check cut out, given away free. The polite word is nulled. It is quietly common at the cheaper end of web development, and if one is running on your site, nobody told you it was there.

I have watched this done at close range, by people who did not think they were doing anything wrong, and it is the single practice I have walked away from work over. I want to be precise about why, because the reason is not the one people assume. It is almost never malice. It is margin. And the bill arrives years later, at your address, without ever announcing itself.

The legal risk is real. The practical one is worse

The legal question is real but it is not the one that will hurt you. Using unlicensed software exposes you rather than the developer who installed it, because it is running on your site, under your business name.

The practical risk is worse and much more likely. A nulled plugin cannot update. Whoever modified it removed the connection to the people who publish security fixes, so the day a vulnerability is announced in that plugin, every other site in the world gets a patch and yours does not. Not because anyone forgot. Because the mechanism was removed before it was installed.

So you are running software that is frozen at the moment it was pirated, on a public internet where automated scanning finds known vulnerabilities within hours of disclosure.

Why it happens

Not because developers are villains. I want to be careful here, because the people I have seen do it were not bad people. It is arithmetic.

A build quoted at a competitive fixed price might need six premium plugins. Licences for those run a few hundred euros a year, every year, and the client was quoted once. Somebody has to absorb that, and at thin margins across many projects the temptation is obvious. The nulled copy looks identical, works identically on the day, and in my experience no client has ever asked to see a licence.

The other reason is worse and more common, and it is the one I could not get comfortable with: nobody is thinking about year two at all. If the relationship ends at handover, the fact that a plugin can never be updated is not a problem that belongs to anybody in the room. It belongs to you, later, and you were not told it existed.

Field note

Identical, until it was not

The thing that makes this hard to spot is that on day one there is no difference. The site works. The plugin does what it should. The client is happy, and reasonably so, because what they were shown functions exactly as promised.

The difference only appears the first time that plugin needs a security fix. Then the site with a licence takes an update, and the site without one sits at the version it was pirated at, indefinitely, while the vulnerability details are public and being scanned for.

How to check, without being technical

Four things, in order of how easy they are.

1. Ask for the licences. One email: “Please send me the licence keys and renewal dates for every paid plugin on the site, and confirm which account they are registered to.” A legitimate build produces this in a day. It is also worth having regardless, because licences registered to a departed developer are their own problem.

2. Look for plugins that want to update but cannot. In the WordPress plugins screen, a premium plugin without a valid licence typically shows an update notice that will not complete, or a persistent prompt to enter a key. One or two might be an expired renewal. A pattern of them is a finding.

3. Compare the list to the invoice. Count the paid plugins running on the site, then look at what you were ever billed for, whether in the build cost or since. If the site is running six commercial products and you have never paid for a licence, somebody else did or nobody did.

4. Have someone verify the files. This one needs a developer, and it is definitive. Official plugin releases can be compared against what is installed. Modified files in a plugin nobody has customised is the answer, and it takes an hour.

What to do if you find one

Do not panic, and do not start deleting things.

Buy the licence. In most cases this is the whole fix and it costs less than the conversation about it. Buy it, install the official version over the top, take a backup first.

Then assume it may have been modified. Nulled software is a well-known delivery route for injected code, precisely because it is installed voluntarily by people who then trust it. Replacing the files with official ones removes anything that came with them. After that, rotate the administrator passwords and check the user list for accounts nobody recognises.

Then decide whether the plugin is needed at all. Often the honest answer is no. It was reached for during the build because it was faster than doing the thing properly, and the site has been carrying it since.

The uncomfortable part

If you find one, the question is not really about that plugin. It is about what else was decided the same way.

A build where somebody pirated a licence to protect the margin is a build where other corners were available. Usually nothing dramatic, and usually the same short list: a theme bought from a marketplace, lightly edited, and described as bespoke. Updates never applied, because applying them would overwrite the modifications. A backup configured on day one and never once restored to check it worked.

I have found all three on the same site more than once, and they are not separate failures. They are one decision, made early, about what the price could carry.

So I would not treat a nulled plugin as evidence of bad character. I would treat it as information about how the project was priced, and then go and look at everything else that gets squeezed when a fixed fee meets a thin margin.

Ask for the licence keys

One question, sent in one email, and the answer arrives fast either way.

“Can you send me the licence keys and renewal dates for every paid plugin on the site?”

A legitimate provider replies with a list, possibly slightly annoyed at the admin. There is nothing awkward in the question for them.

If the reply is vague, or explains that licences are handled internally and there is nothing to send, you have your answer without an argument, and you now know to check the rest.

Pro tip

Whoever builds your next site, put licence ownership in writing at the start: every paid plugin licensed in your business name, on your billing, with the keys handed to you at launch. It costs a few hundred euros a year and it removes this entire category of problem permanently.