The record
Written from the 1 report below. Nothing here is unsourced.
- WordPress will now run an automated security review on every plugin update before it is distributed through the WordPress.org update API.
- A plugin that passes its initial review can still introduce a vulnerability or malicious code in a later release, which is the gap the new system is meant to close.
- The automated review already caught a backdoor in an update to a plugin with about 20,000 active installations on July 28, 2026, and the compromised version was never distributed to users.
- The review uses AI models along with Jetpack Scan to give each release a security score, and any release with a high risk score is automatically blocked from distribution.
- A blocked developer must fix the flagged issues and publish a new release scoring below the high-risk threshold before the plugin can reach users again.
What to watch next
- Whether WordPress discloses the name of the plugin that contained the backdoor.
- Any changes to the six-hour cooldown period introduced under the Protect The Shire initiative.
- How many plugin updates get blocked by the automated review and whether developers dispute the findings as incorrect.
Coverage1
1 report
English national1
All filed from India
Named United States · WooCommerce · David Perez · Jetpack Scan · Quality Insights Toolkit · Wordfence · Wordpress · WordPress.org
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
