Sandeep Kumar Mishra
Sandeep Kumar Mishra writes about WordPress and Artificial Intelligence, offering tips and guides to help you master your website and stay updated with the latest tech trends.

WordPress has introduced an automated security review process for every plugin release. Before a new release is distributed through the WordPress.org Update API, it is now analyzed for potential security risks.
If a release is considered to pose a high security risk, whether intentionally or unintentionally, it can be automatically blocked from distribution.
Plugins are reviewed when they are initially submitted to the WordPress.org directory, but updates are released continuously. A plugin that is secure today could potentially introduce a vulnerability or malicious code in a future release.
WordPress.org says some recent incidents highlighted the need for an automated security check before plugin updates reach users.
Since June 5, 2026, every plugin and theme release has gone through a cooldown period before being distributed through the WordPress.org Update API. The current cooldown period is six hours, including for one-click updates from the WordPress dashboard.
During this period, WordPress.org analyzes release changes using several AI models together with Jetpack Scan. The results are cross-checked and combined into findings that receive a security score.
A higher score indicates a higher potential security risk. Releases that reach the blocking threshold are automatically stopped, and plugin committers receive an email containing the findings.
Importantly, WordPress.org notes that a high security score does not necessarily mean malicious intent. An accidentally introduced vulnerability can receive a similarly high score because the system measures risk rather than intent.
A blocked release will not be distributed through the WordPress.org Update API until the identified issues are resolved.
Plugin authors should:
WordPress.org notes that because the Plugins Team handles a high volume of reviews, publishing a corrected release is usually faster than waiting for a manual review of an appeal.
At this time, WordPress.org says emails are sent only when a release is blocked. Plugin authors who have not received a blocking email do not need to take any action.
The new automated review adds another security check before plugin releases are distributed through WordPress.org. For plugin developers, understanding the findings and addressing legitimate security issues will be important whenever a release is blocked by wordpress.org. In our understanding its a huge and amazing step towards a more secure wordpress eco-system.
Keeping your WordPress website secure requires more than just relying on automated reviews. Website owners and developers should also follow basic security practices, keep plugins and themes updated, and regularly review their site’s security. For more practical recommendations, see our guide on how to secure a WordPress website.
You can read the original announcement on WordPress.org News.
Trying to stay on top of it all? Get the best tools, resources and inspiration sent to your inbox every Wednesday.