WordPress Adds Automated Security Scans to Catch Malicious Plugin Updates Before They Go Live
WordPress has introduced automated security reviews for every plugin update before it reaches the WordPress.org update API, aiming to catch vulnerabilities and malicious code that could slip in after a plugin's initial approval. Previously, only new plugins were reviewed before joining the directory; updates shipped without a consistent security check, leaving a gap attackers could exploit.
The system already proved its worth. On 28 July 2026, the automated review flagged a backdoor committed to an update of a plugin with roughly 20,000 active installations. Because the release fell within a mandatory cooldown window, the compromised version never reached users. WordPress security firm Wordfence alerted the Plugins Team, and the plugin was pulled from downloads within 26 minutes.
This builds on WordPress's ongoing 'Protect The Shire' initiative, which since June 2026 has required all plugin and theme updates to pass through a cooldown period (currently six hours, reduced from an initial 24) before auto-updating on end-user sites. The newest change means updates scoring as high-risk can now be automatically halted from distribution without waiting for manual review by the Plugins Team, though WordPress notes a high-risk score can reflect accidental flaws as well as intentional malware.