WordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review
WordPress.org now runs AI-powered automated security reviews on every plugin release, automatically blocking high-risk updates before distribution to millions of sites.
WordPress launched an automated security review that combines multiple AI models and Jetpack Scan during a six-hour cooldown to score each plugin release; updates above the blocking threshold are automatically held back from the WordPress.org update API. The change follows a July 28 incident where a backdoor added to a plugin with roughly 20,000 active installations was detected during cooldown and never delivered; the Plugins Team removed it 26 minutes after a Wordfence notification. Blocked developers receive an email with findings and are advised to publish a corrected version rather than await manual appeal.
- Every plugin update is analyzed by multiple AI models plus Jetpack Scan during a six-hour cooldown
- Updates exceeding the risk threshold are automatically blocked from the WordPress.org update API
- Follows a July 28 backdoor in a plugin with ~20,000 active installs, blocked before delivery
- Plugins Team removed the compromised plugin 26 minutes after Wordfence notification
- Blocked authors receive findings emails and can publish corrected releases
Full article521 words · extracted from gbhackers.com · click to collapse
WordPress has launched an automated security review system that uses multiple AI models and Jetpack Scan to analyze every plugin release before distributing it to websites via the WordPress.org update API.
This new control is designed to prevent vulnerable or malicious plugin updates from reaching millions of WordPress installations through dashboard-based, one-click updates.
WordPress Blocks High-Risk Plugin
The system extends WordPress.org’s existing review process, which previously assessed new plugins before their initial listing but did not consistently examine every subsequent version released by plugin developers.
Under the new procedure, plugin releasenter in a six-hour cooldown period before becoming available through the update API. During this time, WordPress.org analyzes the changes included in each release, compares results across various AI systems, and combines these findings into a security risk score.
A higher score indicates a greater potential security risk. However, it does not necessarily mean that the developer intentionally introduced malicious code.
WordPress emphasized that an accidentally introduced vulnerability can receive the same high-risk score as a deliberately implanted backdoor.
If a plugin update exceeds WordPress.org’s blocking threshold, the platform will automatically prevent that release from being distributed. Plugin developers will receive an email detailing the findings that triggered the blocking decision.
Updates that score below the high-risk threshold will continue through the normal cooldown and distribution workflow.
WordPress uses multiple detection tools to improve accuracy and reduce false positives, though it acknowledges it cannot eliminate them. This change follows an incident on July 28 involving a plugin with approximately 20,000 active installations.
A backdoor was added to a new version of the plugin. However, the automated review detected the suspicious update and assigned it a high security score while it was still in the cooldown period.
As a result, the compromised version was never delivered through the WordPress.org update API. The Plugins Team removed the plugin from downloads just 26 minutes after receiving a notification from Wordfence.
This new mechanism addresses a critical supply-chain risk for plugins: a legitimate plugin can become dangerous if a later update introduces insecure functionality, such as credential theft, remote code execution paths, or deliberately malicious code.
Previously, a high-risk result depended on the Plugins Team’s availability before a release could be stopped. The new workflow automates blocking, reducing the time attackers have to push a compromised update to downstream sites.
Plugin authors whose releases are blocked are encouraged to review the findings reported, correct the identified issues, and publish a new version.
If the revised release scores below the blocking threshold, it will go through the standard six-hour cooldown period. Authors can also reach out to the Plugins Team if they believe the findings are incorrect. However, WordPress indicates that publishing a corrected release is typically faster than waiting for a manual appeal review.
This initiative makes WordPress.org’s plugin ecosystem more resilient against malicious updates and unintentional security regressions.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/wordpress-blocks-high-risk-plugin-releases/