WordPress.org has begun automatically reviewing every plugin and theme release before it is distributed through the WordPress.org update API, blocking releases that exceed its security-risk threshold. The system combines multiple AI models with Jetpack Scan to assess code changes during a mandatory six-hour cooldown period and cross-check findings into a consolidated risk score.
The controls prevented a backdoored update for a plugin with roughly 20,000 active installations from reaching users after the malicious commit was detected on July 28. Developers of blocked releases receive findings by email and must publish a remediated version or request Plugins Team review if they believe the detection was a false positive.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
A malicious commit added a backdoor to a release for a plugin with about 20,000 active installations. The automated review assigned it a high-risk score during the cooldown, preventing distribution through the WordPress.org update API; the Plugins Team removed the plugin from the directory 26 minutes after a Wordfence alert.
WordPress.org instituted a mandatory six-hour cooldown for every plugin and theme release, withholding releases from the update API while they undergo security assessment.
WordPress.org began applying automated AI-model and Jetpack Scan review to plugin and theme releases before update-API distribution. Releases exceeding its risk threshold are automatically blocked, and committers receive findings to remediate or contest through manual review.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
5 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcehelpnetsecurity.com
Open sourcemake.wordpress.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.