It seems a lot of defacement/spam attacks are based on base64 and/or eval'd javascript/css in tpl.php or index.php

We could add a check that looks for a few telltale signs.

Comments

smustgrave’s picture

Issue summary: View changes
Status: Active » Closed (outdated)

Closing out as outdated. There hasn't been a follow up in 11 years and D7 (hopefully) is nearing it's EOL.

If still a valid feature request for D7 please reopen with an updated issue summary.