ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

WordPress.org Now Auto-Blocks High-Risk Plugin and Theme Updates With AI-Powered Security Review

infoToolsimportance 58
What's new: WordPress.org update distribution now includes a supply-chain gate: every plugin and theme release is held for a six-hour cooldown, scored by multiple AI models plus Jetpack Scan, and high-risk releases are blocked automatically from the update API. Previously there was no such pre-distribution AI gate — as shown by the July 28, 2026 backdoor, which was caught only via a Wordfence report followed…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Since June 5, 2026, every WordPress.org plugin and theme release undergoes a mandatory six-hour cooldown during which multiple AI models and Jetpack Scan score it for risk; releases above the threshold are automatically blocked from the update API. The change…

WordPress.org has added an automated, AI-driven security gate to its plugin and theme update pipeline. Per Cyber Security News, since June 5, 2026, every plugin and theme release must pass a six-hour cooldown in which multiple AI models and Jetpack Scan analyze code changes and produce a consolidated security score; releases scoring above the risk threshold are automatically blocked from the WordPress.org update API until issues are resolved. The policy followed a July 28, 2026 incident in which a backdoor was pushed into a plugin with about 20,000 active installations: Wordfence flagged it, and the Plugins Team removed it 26 minutes after notification, before distribution, so it was never delivered to sites (GBHackers likewise reports it was detected during cooldown and never delivered). Blocked authors receive an email detailing the findings and can publish corrected releases; the sources differ slightly on the appeals path — Cyber Security News says authors can appeal false positives to the Plugins Team, while GBHackers says authors are advised to publish a corrected version rather than await a manual appeal. Cyber Security News also notes the scores measure risk exposure rather than developer intent, and false-positive reports are requested.

  • Effective since June 5, 2026, all WordPress.org plugin and theme releases pass a mandatory six-hour cooldown with automated security review (Cyber Security News).
  • Each release is analyzed by multiple AI models plus Jetpack Scan, which produce a consolidated security score.
  • Releases above the risk threshold are automatically blocked from the WordPress.org update API until issues are resolved.
  • The policy followed a July 28, 2026 backdoor incident affecting a plugin with roughly 20,000 active installations.
  • Wordfence flagged the backdoor; the Plugins Team removed the plugin 26 minutes after notification, before distribution, so it was never delivered to sites.
  • Blocked authors are notified by email with the findings and can publish corrected releases.
  • Scores measure risk exposure, not developer intent; authors may report false positives (Cyber Security News), though GBHackers says authors are advised to republish corrected versions rather than await a manual appeal.
  • The gate covers the WordPress.org update pipeline used by millions of sites.

Coverage timeline

  1. · 6d ago
    Cyber Security News· 52
    WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites

    WordPress.org now auto-blocks plugin updates flagged by AI review after a backdoor incident, adding a supply-chain gate for millions of sites.

  2. · 6d ago
    GBHackers· 58
    WordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review

    WordPress.org now runs AI-powered automated security reviews on every plugin release, automatically blocking high-risk updates before distribution to millions of sites.