$ techbeacon▋
Threats

WordPress Deploys AI‑Driven Scan to Vet Every Plugin Update for Security Threats

WordPress Deploys AI‑Driven Scan to Vet Every Plugin Update for Security Threats

WordPress announced the rollout of an automated security review system that will examine every plugin release before it reaches the update feed on WordPress.org. The new pipeline combines several artificial‑intelligence models with the existing Jetpack Scan service to flag vulnerable or malicious code before it can be installed on millions of sites.

The move comes after a series of high‑profile incidents in which compromised plugins served as entry points for ransomware, data theft, and defacement. Because WordPress powers roughly 43% of all websites, even a single rogue plugin can affect a vast number of users. Historically, the platform has relied on manual review and community reporting, but the sheer volume of submissions—often tens of thousands per month—has strained those resources.

According to the WordPress security team, the AI‑based engine evaluates new code against known vulnerability patterns, suspicious behavior signatures, and anomalous permission requests. When a potential issue is detected, the plugin is held back from the update API and sent to human analysts for deeper investigation. Only after clearance is the update made publicly available.

Jetpack Scan, a tool already used by many WordPress sites for on‑the‑fly malware detection, forms a core component of the new workflow. By integrating its scanning capabilities with the AI models, WordPress aims to catch both known threats and novel exploits that may not yet have signatures in traditional antivirus databases.

Community reaction has been cautiously optimistic. Plugin developers welcome the added layer of protection but acknowledge that false positives could delay legitimate releases. The WordPress core team has pledged to fine‑tune the system based on feedback and to provide a transparent appeals process for developers whose plugins are temporarily blocked.

While the automated review does not replace the need for best‑practice coding and regular security audits, experts see it as a significant step toward hardening the ecosystem. As AI continues to mature, WordPress plans to expand the model’s scope to include theme reviews and possibly third‑party integrations, signaling a broader commitment to safeguarding the open‑source platform against evolving cyber threats.

Source: GBHackers
Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related