WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites
ID: 45dd31ff-049c-5195-b878-217bf947cd13
STIX ID: report--45dd31ff-049c-5195-b878-217bf947cd13
Feed Name: cybersecurityNews.com
WordPress implemented an automated, AI-driven security review and mandatory six-hour cooldown for every plugin/theme release after a malicious backdoor commit was pushed to a plugin with ~20,000 active installs; the AI review flagged the update with a high security score and the update was not distributed. The change embeds multiple AI models alongside Jetpack Scan to compute a security score and automatically block high-risk releases, notifying committers and encouraging fixes or appeals to the Plugins Team to reduce supply-chain exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
