Replacing eval with alert/echo is a nice technique, one I hadn't thought of.<p>Thankfully I haven't had to think of it in years; their conclusions (basically, more logging and keeping up-to-date) would be valid if it weren't Wordpress itself which is usually the attack vector. It's better to use something else entirely.