Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Automates Plugin Security Reviews to Prevent Risks

WordPress Automates Plugin Security Reviews to Prevent Risks

Posted on September 14, 2026 By CWS

WordPress has introduced an automated security review system for plugins to assess potential vulnerabilities prior to distribution through its update API. This initiative aims to ensure plugins are free from security risks before being made available to users.

Enhancing Plugin Security

David Perez, co-lead of the WordPress Official Plugin Repository Team, emphasized the importance of this development. While new plugins undergo initial scrutiny, updates are frequently released without a corresponding review process, potentially introducing vulnerabilities or malicious code.

The absence of consistent post-commit reviews has been a concern, as it could leave room for security breaches. Recently, the automated system detected a backdoor in a plugin with 20,000 active installations before its distribution, thanks to the cooldown period introduced in the Protect The Shire initiative.

Protect The Shire Initiative

Since June 2026, WordPress has implemented a cooldown phase for plugins and themes, aimed at preventing immediate distribution of potentially harmful updates. Initially set at 24 hours, this period is now six hours, allowing time for thorough security checks.

The latest security measure automatically halts distribution of any plugin or theme with a high-risk security score, minimizing the need for intervention by the Plugins Team. The review process involves AI models and Jetpack Scan, which analyze changes and calculate a security score.

Addressing Security Vulnerabilities

Developers are notified via email if a plugin is blocked due to a high-risk score. Perez clarified that the scoring system flags both intentional and inadvertent security issues. Developers are encouraged to adhere to WordPress Coding Standards and utilize tools like PHP_CodeSniffer and Quality Insights Toolkit for code validation.

Some factors contributing to a high-risk score include insecure endpoints, unprepared database queries, and unsafely handled request data. Developers must address these issues and release an updated version to lift any restrictions.

In conclusion, the introduction of automated security reviews by WordPress significantly enhances plugin safety. By preventing the distribution of high-risk updates, this initiative protects users and encourages developers to maintain high coding standards.

The Hacker News Tags:AI models, automated reviews, cooldown period, Jetpack Scan, plugin security, Protect The Shire, security score, Vulnerability, web security, WordPress

Post navigation

Previous Post: AWS Agent Flaw Allows Bypass of Port-Forwarding Restrictions
Next Post: Critical Vulnerabilities in JFrog Artifactory Exploited

Related Posts

JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple Stealers JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple Stealers The Hacker News
FBI Takes Down Chinese Hacking Platforms Targeting U.S. FBI Takes Down Chinese Hacking Platforms Targeting U.S. The Hacker News
TrojPix Exploits Pixel Modulation to Leak Data TrojPix Exploits Pixel Modulation to Leak Data The Hacker News
Fragnesia Linux Kernel Vulnerability Allows Root Access Fragnesia Linux Kernel Vulnerability Allows Root Access The Hacker News
Critical SAP Flaws Pose Severe Security Risks Critical SAP Flaws Pose Severe Security Risks The Hacker News
Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & More The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack
  • New DDRop Attack Targets Intel and AMD Confidential Computing
  • Twitch Extension JeetBot Risks User Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack
  • New DDRop Attack Targets Intel and AMD Confidential Computing
  • Twitch Extension JeetBot Risks User Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark