WordPress.org Now Auto-Blocks High-Risk Plugin and Theme Updates With AI-Powered Security Review
Since June 5, 2026, every WordPress.org plugin and theme release undergoes a mandatory six-hour cooldown during which multiple AI models and Jetpack Scan score it for risk; releases above the threshold are automatically blocked from the update API. The change…
WordPress.org has added an automated, AI-driven security gate to its plugin and theme update pipeline. Per Cyber Security News, since June 5, 2026, every plugin and theme release must pass a six-hour cooldown in which multiple AI models and Jetpack Scan analyze code changes and produce a consolidated security score; releases scoring above the risk threshold are automatically blocked from the WordPress.org update API until issues are resolved. The policy followed a July 28, 2026 incident in which a backdoor was pushed into a plugin with about 20,000 active installations: Wordfence flagged it, and the Plugins Team removed it 26 minutes after notification, before distribution, so it was never delivered to sites (GBHackers likewise reports it was detected during cooldown and never delivered). Blocked authors receive an email detailing the findings and can publish corrected releases; the sources differ slightly on the appeals path — Cyber Security News says authors can appeal false positives to the Plugins Team, while GBHackers says authors are advised to publish a corrected version rather than await a manual appeal. Cyber Security News also notes the scores measure risk exposure rather than developer intent, and false-positive reports are requested.
- Effective since June 5, 2026, all WordPress.org plugin and theme releases pass a mandatory six-hour cooldown with automated security review (Cyber Security News).
- Each release is analyzed by multiple AI models plus Jetpack Scan, which produce a consolidated security score.
- Releases above the risk threshold are automatically blocked from the WordPress.org update API until issues are resolved.
- The policy followed a July 28, 2026 backdoor incident affecting a plugin with roughly 20,000 active installations.
- Wordfence flagged the backdoor; the Plugins Team removed the plugin 26 minutes after notification, before distribution, so it was never delivered to sites.
- Blocked authors are notified by email with the findings and can publish corrected releases.
- Scores measure risk exposure, not developer intent; authors may report false positives (Cyber Security News), though GBHackers says authors are advised to republish corrected versions rather than await a manual appeal.
- The gate covers the WordPress.org update pipeline used by millions of sites.
Coverage timelineoldest first · each row is one article
- · 6d agoWordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites
Cyber Security News· 52
WordPress.org now auto-blocks plugin updates flagged by AI review after a backdoor incident, adding a supply-chain gate for millions of sites.
- · 6d agoWordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review
GBHackers· 58
WordPress.org now runs AI-powered automated security reviews on every plugin release, automatically blocking high-risk updates before distribution to millions of sites.