WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
thehackernews.com Sep 15, 2026

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

AI-summarised brief · reviewed before publication

WordPress announced an automated security review for every plugin release distributed via its update API, aiming to detect vulnerabilities before they reach users. The system, part of the Protect The Shire initiative, introduced a six‑hour cooldown period for updates, down from 24 hours, and automatically blocks high‑risk releases. On July 28, 2026, the review flagged a backdoor in a plugin with roughly 20,000 active installs, preventing its distribution. Developers must address findings to lift the block, while WordPress encourages adherence to coding standards and automated testing tools.

💡 Why It Matters

  • · By inserting a mandatory review step, WordPress reduces the window for attackers to push malicious code, tightening the security of the largest open‑source CMS ecosystem.