WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
- ID
- 24321
- Status
- summarized
- Published
- 15 Sep 2026, 12:00 AM
- Fetched
- 15 Sep 2026, 2:40 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/wordpress-adds-automated-plugin-reviews.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 15 Sep 2026, 2:41 AM
- Tags
- Audience
- developerssaas_founders
What happened
WordPress now runs automated AI-based security reviews (via WordPress.org AI models and Jetpack Scan) on every plugin and theme release during a cooldown period before distribution, blocking high-risk updates automatically. Since June 5, 2026, the 'Protect The Shire' initiative enforces a 6-hour cooldown (down from 24) on all auto-updates; on July 28, 2026, this system caught a backdoor in a plugin with ~20,000 active installations before it reached users.
Why it matters
If you ship WordPress plugins or themes, your next update may be blocked or delayed if the automated review flags it—test your release process against this new friction and expect potential distribution holds. For agencies and builders running WordPress sites in Malaysia's large SME market, auto-updates now have a built-in safety net but also a delay window, so plan patching timelines accordingly.
Discussion angle
How does AI-based code review for blocking plugin releases compare to manual review trade-offs—and could this model apply to other package ecosystems like npm or Composer that Malaysian builders rely on?