Key details

  1. The Plugins Team announced automated release blocking on September 9, 2026.
  2. Every plugin and theme release has gone through a cooldown since June 5; the current cooldown is six hours.
  3. The review combines several AI models with Jetpack Scan.
  4. High-risk releases are automatically blocked from the WordPress.org update API.
  5. All plugin committers receive an email when a release is blocked.
  6. Authors can publish a corrected release or contact the Plugins Team about a suspected false positive.
  7. WordPress.org says the system prevented a July 28 backdoored release for a plugin with around 20,000 active installs from being distributed.

What builders should take away

  1. Plugin maintainers should treat the six-hour cooldown as part of the normal release pipeline rather than expecting committed updates to propagate immediately.
  2. For urgent security fixes, plan around the cooldown and monitor committer email so a false positive does not silently delay remediation.
  3. Review the automated findings before appealing; publishing a corrected release is expected to be faster than waiting for manual review in many cases.
  4. Teams operating WordPress fleets gain another supply-chain control at the directory level, but should not treat it as a replacement for their own vulnerability monitoring and staged updates.
  5. Plugin businesses should test release automation and customer communication against a world where WordPress.org can intentionally hold or block an update.

What changed

The WordPress.org Plugins Team has launched an automated security gate for every plugin release. Since June 5, plugin and theme releases have passed through a cooldown before distribution through the WordPress.org update API; the cooldown is currently six hours. During that window, WordPress.org analyzes release changes using several AI models together with Jetpack Scan, cross-checks the results and produces a security score. The new enforcement step automatically blocks releases with a high-risk score from the update API and emails all plugin committers with the findings. The release stays blocked until a corrected version scores below the threshold or the Plugins Team resolves a false positive.

Why it matters

WordPress plugin supply-chain risk often appears after a plugin has already passed its initial directory review. Until this system, there was no consistent security-review gate between a maintainer committing an update and that update reaching potentially millions of sites through one-click updates. Automatic blocking changes that distribution boundary. The Plugins Team says the underlying review already caught a July 28 backdoor in a plugin with around 20,000 active installations; because the compromised version was still inside the cooldown, it never reached users through the update API. That gives the new gate more operational weight than a policy-only announcement.

Every release now has a security window before distribution

WordPress.org says every plugin and theme release has gone through a cooldown since June 5, currently set to six hours. Plugin ZIPs can be committed during that period, but the release is held back from the update API, including the one-click update path in WordPress dashboards.

Multiple scanners feed one blocking decision

During the cooldown, WordPress.org runs several AI models plus Jetpack Scan against the changes. Findings are cross-checked and combined into a security score. The Plugins Team says this reduces false positives but does not eliminate them, and a high score reflects risk rather than proof of malicious intent.

High-risk results now stop distribution automatically

The new enforcement layer blocks a high-risk release as soon as the review finishes instead of depending on a human reviewer being available. Committers receive the findings by email. A fixed release goes through the cooldown again, while authors can contact the Plugins Team if they believe the block is incorrect.

A real backdoor was already caught before it reached users

WordPress.org says a backdoor was committed on July 28 to a plugin with about 20,000 active installations. The automated review gave the release a high security score while it was still in cooldown, so the compromised version was never distributed through the update API. Wordfence separately notified the Plugins Team, and the plugin was closed for downloads 26 minutes later.

The trade-off is slower release propagation and possible false positives

The security benefit comes with a deliberate delay: routine releases wait through the cooldown, and legitimate code can still trigger a high score. Plugin authors therefore need to account for the review window in urgent release planning and keep an eye on committer email when an update does not propagate as expected.

What to watch next

  • False-positive rates and whether WordPress.org changes the blocking threshold or cooldown duration.
  • Whether the same automatic blocking policy is expanded or clarified for theme releases.
  • More disclosure about the AI models, scan coverage and classes of findings used in the security score.
  • How emergency security releases are handled when the normal cooldown would delay a critical patch.
  • Whether plugin authors receive machine-readable findings that can be integrated into CI before committing a release.

Still unclear

  • WordPress.org does not publish the exact scoring formula or blocking threshold.
  • The Plugins Team explicitly says false positives are possible.
  • The announcement describes several AI models plus Jetpack Scan but does not identify every model or scanner configuration.
  • A directory-level block reduces one distribution risk but cannot detect every malicious or vulnerable update.

Sources

Direct reading behind this dossier.

1 sources
Automated security review for plugin releases
WordPress.org Plugins Team primary

Official description of the cooldown, multi-tool security scoring, automatic blocking behavior and the July backdoor caught before distribution.

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment