如何移除网站中的AddThis?Magento平台Cpanel无法找到嵌入代码求助
Hey there, sorry to hear your Magento site ended up with unwanted AddThis code embedded—let’s break down the most likely places it could be hiding, since Cpanel’s basic file search might miss some tricky spots in Magento’s structure.
1. Check Magento Theme Files & Layouts
Magento’s frontend templates are a common target for code injection. Start with these key files:
- Template files: Look in
app/design/frontend/<your-theme-package>/<your-theme>/template/page/html/forhead.phtmlorfooter.phtml—these are where global scripts are often added. Use Cpanel’s file manager to open these files and scan for anyaddthis.comscript tags. - Layout XML files: Check
app/design/frontend/<your-theme-package>/<your-theme>/layout/page.xmlor any custom layout files. Look for blocks referencing AddThis, or direct<action method="addItem">calls that inject the script.
Pro tip: Use Cpanel’s Search Content feature (in File Manager) to search for the string addthis across all .phtml, .xml, and .php files in your Magento root—this will catch embedded code even if it’s in an unexpected file.
2. Audit Third-Party Extensions
Malicious or compromised extensions are another common source of injection:
- Go to your Magento admin panel → System → Configuration → Advanced to see a list of enabled modules. Look for any unfamiliar modules, especially ones related to social sharing or analytics that you didn’t install.
- Check the extension directories:
app/code/community/andapp/code/local/—delete any extensions you don’t recognize or trust (make sure to back them up first just in case). - Also, check
app/etc/modules/for XML files that enable unknown modules, as these might be linked to the injected code.
3. Dig Into the Magento Database
Sometimes code gets injected into Magento’s core configuration tables:
- Open phpMyAdmin via Cpanel, select your Magento database, and run a search on the
core_config_datatable for the stringaddthisor<script>. Look for any suspicious entries in thevaluecolumn—these might be injecting the script site-wide. - Also check the
cms_pageandcms_blocktables if you use Magento’s CMS pages/blocks—malicious code could be embedded directly in a footer block or homepage content.
4. Clear All Caches
Magento’s caching system might be serving up cached versions of the injected code even after you remove it:
- In your Magento admin, go to System → Cache Management and click Flush Magento Cache and Flush Cache Storage.
- For good measure, you can also manually delete the contents of
var/cache/andvar/page_cache/folders via Cpanel’s File Manager (don’t delete the folders themselves, just their contents).
5. Check Server-Level Files
Sometimes injection happens at the server level, outside of Magento’s files:
- Inspect your
.htaccessfile in the Magento root directory—look for any unexpectedRewriteRuledirectives that might be injecting code into page responses. - If you have access to PHP settings via Cpanel, check if
auto_prepend_fileorauto_append_fileare set to any unknown scripts—these can inject code into every PHP page on your site.
6. Rule Out CDN or External Service Hijacking
If you use a CDN like Cloudflare or a third-party hosting service, verify:
- No unauthorized page rules or script injection settings are enabled in your CDN dashboard.
- Your domain hasn’t been redirected or hijacked to serve modified content.
Important Note
Before making any changes, back up your Magento files and database via Cpanel—this way you can restore everything if something goes wrong.
内容的提问来源于stack exchange,提问作者Ashley Jia

