Title: text javascript unknown inserted into my header.php
Last modified: August 20, 2016

---

# text javascript unknown inserted into my header.php

 *  [edyzen](https://wordpress.org/support/users/edyzen/)
 * (@edyzen)
 * [13 years, 3 months ago](https://wordpress.org/support/topic/text-javascript-unknown-inserted-into-my-headerphp/)
 * Hello world
    My site is [http://www.propertypilihan.com](http://www.propertypilihan.com)
   I found text javascript unknown inserted into my header.php such as below :
 * <script type=’text/javascript’>if(document.getElementById(‘hideMe’) … _[hacked
   code deleted – please don’t post here ]_
 * y.</p></div>
 * My question is :
    1 .From where hacker can access header.php ? 2. How to protect
   my site ?

Viewing 11 replies - 1 through 11 (of 11 total)

 *  [beyerste](https://wordpress.org/support/users/beyerste/)
 * (@beyerste)
 * [13 years, 3 months ago](https://wordpress.org/support/topic/text-javascript-unknown-inserted-into-my-headerphp/#post-3483912)
 * Hi,
    there are many blogs infected with this code. If you serach on Google for“
   1301851861911781711021861911821711311041861711901861171”. You can find some pages.
   These code hides this Element (<div class=slider_wrapper_en>”). It will extract
   following text:
 * `<styletype="text/css">.slider_wrapper_en{position:absolute;clip:rect(480px,auto,
   auto,480px);}</style>
 * My problem is that my header.php is not changed if I have a look to the file,
   but if I open my page the script was inserted. So, where is it stored?
    Is “slider_wrapper_en”
   a hint? Because I have installed Sliding Door theme.
 * Stefan
 *  [esmi](https://wordpress.org/support/users/esmi/)
 * (@esmi)
 * [13 years, 3 months ago](https://wordpress.org/support/topic/text-javascript-unknown-inserted-into-my-headerphp/#post-3483913)
 * **[@beyerste](https://wordpress.org/support/users/beyerste/)**: As per the [Forum Welcome](http://codex.wordpress.org/Forum_Welcome#Where_To_Post),
   please [post your own topic](http://wordpress.org/support/forum/how-to-and-troubleshooting#postform).
   Posting in an existing topic prevents us from being able to track issues by topic.
   Added to which, your problem – despite any similarity in symptoms – is likely
   to be completely different.
 *  [WPyogi](https://wordpress.org/support/users/wpyogi/)
 * (@wpyogi)
 * [13 years, 3 months ago](https://wordpress.org/support/topic/text-javascript-unknown-inserted-into-my-headerphp/#post-3483914)
 * **[@edyzen](https://wordpress.org/support/users/edyzen/)** – please see:
 * [http://codex.wordpress.org/FAQ_My_site_was_hacked](http://codex.wordpress.org/FAQ_My_site_was_hacked)
   
   [http://wordpress.org/support/topic/268083#post-1065779](http://wordpress.org/support/topic/268083#post-1065779)
   [http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/](http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/)
   [http://ottopress.com/2009/hacked-wordpress-backdoors/](http://ottopress.com/2009/hacked-wordpress-backdoors/)
 * Additional Resources:
    [http://sitecheck.sucuri.net/scanner/](http://sitecheck.sucuri.net/scanner/)
   [http://www.unmaskparasites.com/](http://www.unmaskparasites.com/) [http://blog.sucuri.net/2012/03/wordpress-understanding-its-true-vulnerability.html](http://blog.sucuri.net/2012/03/wordpress-understanding-its-true-vulnerability.html)
 *  [switch2mac](https://wordpress.org/support/users/switch2mac/)
 * (@switch2mac)
 * [13 years, 3 months ago](https://wordpress.org/support/topic/text-javascript-unknown-inserted-into-my-headerphp/#post-3483924)
 * Did somebody checked that issue?
    Looks like malware, but no entry in mysql or
   php files. Any idea ?
 * Regards
    David
 *  [WPyogi](https://wordpress.org/support/users/wpyogi/)
 * (@wpyogi)
 * [13 years, 3 months ago](https://wordpress.org/support/topic/text-javascript-unknown-inserted-into-my-headerphp/#post-3483925)
 * What do you mean “somebody”? The recommended resources for hacked sites are posted
   right above your post.
 *  [switch2mac](https://wordpress.org/support/users/switch2mac/)
 * (@switch2mac)
 * [13 years, 3 months ago](https://wordpress.org/support/topic/text-javascript-unknown-inserted-into-my-headerphp/#post-3483926)
 * @ WPyogi thanx for the great help…
    For all others, this code is added by plugin
   Facebook / quiknotes, the directory name of the plugin is quiknotes. The plugin
   is not available anymore on wordpress.org.
 * So delete/deactivate the plugin and check your system as WPyogi mentioned before.
 *  Thread Starter [edyzen](https://wordpress.org/support/users/edyzen/)
 * (@edyzen)
 * [13 years, 3 months ago](https://wordpress.org/support/topic/text-javascript-unknown-inserted-into-my-headerphp/#post-3483932)
 * WPyogi
    Thanks for your suggestion, that is very useful
 *  [Derek Rippe](https://wordpress.org/support/users/dwrippe/)
 * (@dwrippe)
 * [13 years, 3 months ago](https://wordpress.org/support/topic/text-javascript-unknown-inserted-into-my-headerphp/#post-3483935)
 * For the record, the plugin mentioned by switch2mac, Facebook/quiknotes, is most
   likely not the culprit here. I just came across this hack on another site not
   utilizing that plugin.
 * As advised by the links provided by WPyogi, it’s probably best to do a clean 
   install. No telling how or where that malicious code has been inserted, and odds
   are it’ll be faster for you to re-install WordPress and your site files than 
   it will be to manually check _every file in your WordPress directory_ only to
   miss something and have the malware show up again.
 *  [Rian Rietveld](https://wordpress.org/support/users/rianrietveld/)
 * (@rianrietveld)
 * [13 years, 1 month ago](https://wordpress.org/support/topic/text-javascript-unknown-inserted-into-my-headerphp/#post-3483941)
 * Thanks for this discussion, removing Facebook/quiknotes solved the javascript
   injection in one of my sites.
 *  [Andrew Nevins](https://wordpress.org/support/users/anevins/)
 * (@anevins)
 * WCLDN 2018 Contributor | Volunteer support
 * [13 years, 1 month ago](https://wordpress.org/support/topic/text-javascript-unknown-inserted-into-my-headerphp/#post-3483942)
 * Removing the malicious code may resolve the symptom of the hack, but it does 
   not resolve the hacker’s ability to inject malicious code to your website.
 *  [Rian Rietveld](https://wordpress.org/support/users/rianrietveld/)
 * (@rianrietveld)
 * [13 years, 1 month ago](https://wordpress.org/support/topic/text-javascript-unknown-inserted-into-my-headerphp/#post-3483943)
 * [@andrew](https://wordpress.org/support/users/andrew/), it solved the problem
   for now. I checked the complete code/database, the rest is clean.
    I will move
   to site to a different provider with a clean WP and plugin install soon.

Viewing 11 replies - 1 through 11 (of 11 total)

The topic ‘text javascript unknown inserted into my header.php’ is closed to new
replies.

 * In: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
 * 11 replies
 * 8 participants
 * Last reply from: [Rian Rietveld](https://wordpress.org/support/users/rianrietveld/)
 * Last activity: [13 years, 1 month ago](https://wordpress.org/support/topic/text-javascript-unknown-inserted-into-my-headerphp/#post-3483943)
 * Status: not resolved

## Topics

### Topics with no replies

### Non-support topics

### Resolved topics

### Unresolved topics

### All topics
