WordPress AI Scans Plugin Updates for Malware Before Release
Key Takeaways WordPress has implemented an automated, AI-driven security review system for all plugin and theme releases. This new system scans for malware and vulnerabilities during a mandatory...
Key Takeaways
- WordPress has implemented an automated, AI-driven security review system for all plugin and theme releases.
- This new system scans for malware and vulnerabilities during a mandatory six-hour cooldown period before updates are distributed.
- The initiative was prompted by a real-world incident where a malicious backdoor was nearly pushed to 20,000 active plugin installations.
- Updates flagged with a high-risk score are automatically blocked from distribution, enhancing supply chain security.
- Plugin developers whose releases are blocked will receive an email detailing the flagged issues and recommended steps for resolution.
WordPress Bolsters Plugin Security with AI-Powered Pre-Release Scans
In a significant enhancement to its security infrastructure, WordPress has deployed an automated, AI-powered system designed to scrutinize every plugin and theme release before it reaches the WordPress.org update API. This critical new checkpoint aims to prevent malicious or vulnerable code from being distributed to millions of WordPress installations globally, addressing a previously identified gap in the platform’s update pipeline.
Table Of Content
The introduction of this automated review mechanism follows a concerning incident on July 28, 2026, where a backdoor was stealthily inserted into an update for a plugin actively used by approximately 20,000 sites. While the malicious commit was detected within WordPress.org’s mandatory cooldown window, prompting an immediate alert from security firm Wordfence, the event underscored a critical vulnerability: the reliance on human intervention for blocking distribution. The compromised plugin was removed from the directory just 26 minutes after the alert, but the incident highlighted the need for an autonomous defense system.
Automated Blocking Mechanism Activated
This realization directly spurred the development of an automated blocking mechanism. Since June 5, 2026, every plugin and theme release submitted to WordPress.org has been subject to a mandatory six-hour cooldown period before it becomes available through the update API, including one-click updates directly from the WordPress dashboard. During this crucial window, a sophisticated array of AI models, alongside WordPress’s existing malware and vulnerability scanning engine, Jetpack Scan, now meticulously analyze all code changes.
These diverse scanning tools collaborate to consolidate their findings into a single security score, where a higher score signifies a greater potential for risk. This multi-layered approach, involving several detection systems running in parallel and cross-referencing their outputs, significantly enhances accuracy and helps to minimize false positives, though WordPress.org acknowledges that the system is not infallible.
Any release that surpasses a predefined risk threshold is automatically blocked immediately upon completion of the review. In such cases, every committer associated with the plugin receives an email notification detailing the specific findings that triggered the block. Releases that remain below this threshold proceed through the standard cooldown period and are distributed as usual. WordPress.org has clarified that an elevated score does not inherently imply malicious intent; unintentional coding flaws or vulnerabilities can register the same high-risk score as deliberate malware, as the system assesses risk exposure rather than developer intention.
Resolution Process for Blocked Releases
Currently, notification emails are only dispatched when a release is actively blocked. Plugin authors who do not receive an email can assume their update has successfully passed the review process. When a release is blocked, it will not be pushed through the update API until the identified issues are resolved. WordPress.org advises authors to first review the specific findings outlined in the notification email, as these pinpoint the exact reasons for the flag.
The most expedient path to resolution is to rectify the identified issues and submit a new release. Once the revised version scores below the blocking threshold, it will re-enter the normal cooldown and distribution pipeline. Authors who believe a finding is a false positive can directly contact the Plugins Team; however, the team cautions that publishing a corrected release is almost always faster than awaiting a manual appeal review, given the substantial volume of submissions they manage.
WordPress powers a significant portion of the internet, and its extensive plugin ecosystem has historically represented a persistent attack surface. A single compromised update can silently propagate to every website utilizing that extension. By integrating AI-based scanning directly into the update pipeline, rather than relying solely on post-release detection, WordPress.org is adopting a proactive, supply-chain-style defense model, mirroring strategies increasingly embraced across other major software distribution platforms.
The Plugins Team has indicated that the detection thresholds and underlying models will continue to evolve as more data is gathered. They have specifically encouraged developers to report any false positives to aid in refining the system’s accuracy over time. For an ecosystem where plugin updates often auto-deploy to millions of sites with minimal user interaction, this automated gatekeeping represents one of the most impactful security enhancements to WordPress’s core infrastructure in recent years.
What You Should Do
- Plugin Developers: Review the specific findings in any blocking notification emails. Prioritize fixing identified issues and publishing a new, corrected release. Report any suspected false positives to the Plugins Team to help refine the system.
- WordPress Site Administrators: Ensure all plugins and themes are kept up-to-date. While this new system significantly reduces risks, staying current with official updates remains a fundamental security practice.
- Security Researchers: Continue to monitor and report vulnerabilities or malicious activity within the WordPress ecosystem.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.