Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Automates Plugin Security Reviews to Prevent Risks

WordPress Automates Plugin Security Reviews to Prevent Risks

Posted on September 14, 2026 By CWS

WordPress has introduced an automated security review system for plugins to assess potential vulnerabilities prior to distribution through its update API. This initiative aims to ensure plugins are free from security risks before being made available to users.

Enhancing Plugin Security

David Perez, co-lead of the WordPress Official Plugin Repository Team, emphasized the importance of this development. While new plugins undergo initial scrutiny, updates are frequently released without a corresponding review process, potentially introducing vulnerabilities or malicious code.

The absence of consistent post-commit reviews has been a concern, as it could leave room for security breaches. Recently, the automated system detected a backdoor in a plugin with 20,000 active installations before its distribution, thanks to the cooldown period introduced in the Protect The Shire initiative.

Protect The Shire Initiative

Since June 2026, WordPress has implemented a cooldown phase for plugins and themes, aimed at preventing immediate distribution of potentially harmful updates. Initially set at 24 hours, this period is now six hours, allowing time for thorough security checks.

The latest security measure automatically halts distribution of any plugin or theme with a high-risk security score, minimizing the need for intervention by the Plugins Team. The review process involves AI models and Jetpack Scan, which analyze changes and calculate a security score.

Addressing Security Vulnerabilities

Developers are notified via email if a plugin is blocked due to a high-risk score. Perez clarified that the scoring system flags both intentional and inadvertent security issues. Developers are encouraged to adhere to WordPress Coding Standards and utilize tools like PHP_CodeSniffer and Quality Insights Toolkit for code validation.

Some factors contributing to a high-risk score include insecure endpoints, unprepared database queries, and unsafely handled request data. Developers must address these issues and release an updated version to lift any restrictions.

In conclusion, the introduction of automated security reviews by WordPress significantly enhances plugin safety. By preventing the distribution of high-risk updates, this initiative protects users and encourages developers to maintain high coding standards.

The Hacker News Tags:AI models, automated reviews, cooldown period, Jetpack Scan, plugin security, Protect The Shire, security score, Vulnerability, web security, WordPress

Post navigation

Previous Post: AWS Agent Flaw Allows Bypass of Port-Forwarding Restrictions
Next Post: Critical Vulnerabilities in JFrog Artifactory Exploited

Related Posts

North Korean Hackers Exploit AI for Enhanced Cyber Attacks North Korean Hackers Exploit AI for Enhanced Cyber Attacks The Hacker News
Critical PAN-OS Flaw Exploited for Root Access Critical PAN-OS Flaw Exploited for Root Access The Hacker News
Cybercriminals Target AI Users with Malware-Loaded Installers Posing as Popular Tools Cybercriminals Target AI Users with Malware-Loaded Installers Posing as Popular Tools The Hacker News
WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More The Hacker News
New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login The Hacker News
Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack
  • New DDRop Attack Targets Intel and AMD Confidential Computing
  • Twitch Extension JeetBot Risks User Security
  • Critical Vulnerabilities in JFrog Artifactory Exploited
  • WordPress Automates Plugin Security Reviews to Prevent Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack
  • New DDRop Attack Targets Intel and AMD Confidential Computing
  • Twitch Extension JeetBot Risks User Security
  • Critical Vulnerabilities in JFrog Artifactory Exploited
  • WordPress Automates Plugin Security Reviews to Prevent Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark