Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Claude AI Agents Automate Cyberattacks, Develop Zero-Days, Evade Detection
September 11, 2026
WordPress AI Scans Plugin Updates for Malware Before Release
September 11, 2026
Critical Microsoft Teams Flaw Lets Attackers Create In-Browser Phishing Pages
September 11, 2026
Home/CyberSecurity News/WordPress AI Scans Plugin Updates for Malware Before Release
CyberSecurity News

WordPress AI Scans Plugin Updates for Malware Before Release

Key Takeaways WordPress has implemented an automated, AI-driven security review system for all plugin and theme releases. This new system scans for malware and vulnerabilities during a mandatory...

Marcus Rodriguez
Marcus Rodriguez
September 11, 2026 4 Min Read
3 0

Key Takeaways

  • WordPress has implemented an automated, AI-driven security review system for all plugin and theme releases.
  • This new system scans for malware and vulnerabilities during a mandatory six-hour cooldown period before updates are distributed.
  • The initiative was prompted by a real-world incident where a malicious backdoor was nearly pushed to 20,000 active plugin installations.
  • Updates flagged with a high-risk score are automatically blocked from distribution, enhancing supply chain security.
  • Plugin developers whose releases are blocked will receive an email detailing the flagged issues and recommended steps for resolution.

WordPress Bolsters Plugin Security with AI-Powered Pre-Release Scans

In a significant enhancement to its security infrastructure, WordPress has deployed an automated, AI-powered system designed to scrutinize every plugin and theme release before it reaches the WordPress.org update API. This critical new checkpoint aims to prevent malicious or vulnerable code from being distributed to millions of WordPress installations globally, addressing a previously identified gap in the platform’s update pipeline.

Table Of Content

  • Key Takeaways
  • WordPress Bolsters Plugin Security with AI-Powered Pre-Release Scans
  • Automated Blocking Mechanism Activated
  • Resolution Process for Blocked Releases
  • What You Should Do

The introduction of this automated review mechanism follows a concerning incident on July 28, 2026, where a backdoor was stealthily inserted into an update for a plugin actively used by approximately 20,000 sites. While the malicious commit was detected within WordPress.org’s mandatory cooldown window, prompting an immediate alert from security firm Wordfence, the event underscored a critical vulnerability: the reliance on human intervention for blocking distribution. The compromised plugin was removed from the directory just 26 minutes after the alert, but the incident highlighted the need for an autonomous defense system.

Automated Blocking Mechanism Activated

This realization directly spurred the development of an automated blocking mechanism. Since June 5, 2026, every plugin and theme release submitted to WordPress.org has been subject to a mandatory six-hour cooldown period before it becomes available through the update API, including one-click updates directly from the WordPress dashboard. During this crucial window, a sophisticated array of AI models, alongside WordPress’s existing malware and vulnerability scanning engine, Jetpack Scan, now meticulously analyze all code changes.

These diverse scanning tools collaborate to consolidate their findings into a single security score, where a higher score signifies a greater potential for risk. This multi-layered approach, involving several detection systems running in parallel and cross-referencing their outputs, significantly enhances accuracy and helps to minimize false positives, though WordPress.org acknowledges that the system is not infallible.

Any release that surpasses a predefined risk threshold is automatically blocked immediately upon completion of the review. In such cases, every committer associated with the plugin receives an email notification detailing the specific findings that triggered the block. Releases that remain below this threshold proceed through the standard cooldown period and are distributed as usual. WordPress.org has clarified that an elevated score does not inherently imply malicious intent; unintentional coding flaws or vulnerabilities can register the same high-risk score as deliberate malware, as the system assesses risk exposure rather than developer intention.

Resolution Process for Blocked Releases

Currently, notification emails are only dispatched when a release is actively blocked. Plugin authors who do not receive an email can assume their update has successfully passed the review process. When a release is blocked, it will not be pushed through the update API until the identified issues are resolved. WordPress.org advises authors to first review the specific findings outlined in the notification email, as these pinpoint the exact reasons for the flag.

The most expedient path to resolution is to rectify the identified issues and submit a new release. Once the revised version scores below the blocking threshold, it will re-enter the normal cooldown and distribution pipeline. Authors who believe a finding is a false positive can directly contact the Plugins Team; however, the team cautions that publishing a corrected release is almost always faster than awaiting a manual appeal review, given the substantial volume of submissions they manage.

WordPress powers a significant portion of the internet, and its extensive plugin ecosystem has historically represented a persistent attack surface. A single compromised update can silently propagate to every website utilizing that extension. By integrating AI-based scanning directly into the update pipeline, rather than relying solely on post-release detection, WordPress.org is adopting a proactive, supply-chain-style defense model, mirroring strategies increasingly embraced across other major software distribution platforms.

The Plugins Team has indicated that the detection thresholds and underlying models will continue to evolve as more data is gathered. They have specifically encouraged developers to report any false positives to aid in refining the system’s accuracy over time. For an ecosystem where plugin updates often auto-deploy to millions of sites with minimal user interaction, this automated gatekeeping represents one of the most impactful security enhancements to WordPress’s core infrastructure in recent years.

What You Should Do

  • Plugin Developers: Review the specific findings in any blocking notification emails. Prioritize fixing identified issues and publishing a new, corrected release. Report any suspected false positives to the Plugins Team to help refine the system.
  • WordPress Site Administrators: Ensure all plugins and themes are kept up-to-date. While this new system significantly reduces risks, staying current with official updates remains a fundamental security practice.
  • Security Researchers: Continue to monitor and report vulnerabilities or malicious activity within the WordPress ecosystem.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical Microsoft Teams Flaw Lets Attackers Create In-Browser Phishing Pages

Next Post

Claude AI Agents Automate Cyberattacks, Develop Zero-Days, Evade Detection

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Passkey Phishing Attacks Hijack Microsoft 365 Accounts, Steal Cloud Data
September 10, 2026
Critical Check Point VPN Vulnerabilities Allow RCE Attacks
September 10, 2026
New Attack Steals Data via AI Workflows, No Jailbreak Needed
September 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us