WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
High · The Hacker News ·
WordPress
What happened
WordPress.org will automatically security-review every plugin update before release via its update API, aiming to block risky updates. Site admins and plugin developers are affected.
What to do now
No emergency action. Inventory WordPress plugins, remove unused ones, enable auto-updates for trusted plugins, test updates in staging, and monitor WordPress.org and vendor advisories for blocked or delayed releases.
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.