Ethical Hacking News
WordPress has introduced an automated plugin review process to block high-risk updates to plugins before they are distributed to users, thereby reducing the risk of malicious attacks on the platform.
WordPress has introduced an automated plugin review process to block high-risk updates and reduce malicious attacks. The process uses AI models to analyze plugin code and identify vulnerabilities, with a security score determining risk level. Releases with high risk scores are blocked, while those below threshold continue normally, with plugin committers notified and given opportunity to review and fix issues. The new feature improves upon the current system, reducing cooldown periods and increasing security. Benefits include reduced risk of malicious attacks, added security for plugin developers, and a culture of security in the plugin development community.
WordPress, a popular content management system (CMS) platform, has taken a significant step towards enhancing its security features by introducing an automated plugin review process. This innovative initiative aims to block high-risk updates to plugins before they are distributed to users, thereby reducing the risk of malicious attacks on the platform. In this article, we will delve into the details of this new feature, its benefits, and the implications it may have on the plugin development community.
According to a recent announcement by WordPress, the new automated review process will analyze every plugin release for potential security issues and ensure that there are no risks involved. This process will be conducted using artificial intelligence (AI) models, which will evaluate the plugin code and identify vulnerabilities. The findings will then be cross-verified and combined into a security score, which will determine the risk level of the plugin update.
Releases with a high risk score will be blocked automatically, while those below the threshold will continue through the normal process. Plugin committers will receive an email with the findings, and they will have the opportunity to review and fix any issues before the plugin is made available to users.
The introduction of this automated review process is a significant improvement over the current system, which relies on manual reviews and cooldown periods to mitigate risks. The cooldown period, which was initially set at 24 hours, has been reduced to six hours, which may not be sufficient to identify all potential security issues.
The benefits of this new feature are numerous. Firstly, it reduces the risk of malicious attacks on the platform, which can have serious consequences for users. Secondly, it provides an added layer of security for plugin developers, who will be notified if their plugin has a high risk score. This will enable them to review and fix any issues before the plugin is made available to users.
The implications of this new feature on the plugin development community are also significant. Plugin developers will need to ensure that their plugins are thoroughly tested and reviewed before they are made available to users. This will require significant investment in terms of time and resources. However, the benefits of this new feature far outweigh the costs, as it will provide an added layer of security for users and reduce the risk of malicious attacks on the platform.
In conclusion, WordPress's introduction of an automated plugin review process is a significant step towards enhancing its security features. This new feature will reduce the risk of malicious attacks on the platform, provide an added layer of security for plugin developers, and promote a culture of security among the plugin development community.
Related Information:
https://www.ethicalhackingnews.com/articles/WordPress-Introduces-Automated-Plugin-Reviews-to-Mitigate-High-Risk-Updates-ehn.shtml
https://thehackernews.com/2026/09/wordpress-adds-automated-plugin-reviews.html
Published: Mon Sep 14 12:50:43 2026 by llama3.2 3B Q4_K_M