This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

WordPress has introduced an automated security review process for every plugin release. Before a new release is distributed through the WordPress.org Update API, it is now analyzed for potential security risks.
If a release is considered to pose a high security risk, whether intentionally or unintentionally, it can be automatically blocked from distribution.
Why WordPress.org Introduced Automated Security Reviews
Plugins are reviewed when they are initially submitted to the WordPress.org directory, but updates are released continuously. A plugin that is secure today could potentially introduce a vulnerability or malicious code in a future release.
WordPress.org says some recent incidents highlighted the need for an automated security check before plugin updates reach users.
How the Automated Security Review Works
Since June 5, 2026, every plugin and theme release has gone through a cooldown period before being distributed through the WordPress.org Update API. The current cooldown period is six hours, including for one-click updates from the WordPress dashboard.
During this period, WordPress.org analyzes release changes using several AI models together with Jetpack Scan. The results are cross-checked and combined into findings that receive a security score.
A higher score indicates a higher potential security risk. Releases that reach the blocking threshold are automatically stopped, and plugin committers receive an email containing the findings.
Importantly, WordPress.org notes that a high security score does not necessarily mean malicious intent. An accidentally introduced vulnerability can receive a similarly high score because the system measures risk rather than intent.
What Happens If a Release Is Blocked?
A blocked release will not be distributed through the WordPress.org Update API until the identified issues are resolved.
Plugin authors should:
- Review the reported findings to understand what triggered the block.
- Fix the issues and publish a new release. The new version will go through the normal cooldown and security review process.
- Contact the Plugins Team if a finding appears to be incorrect.
WordPress.org notes that because the Plugins Team handles a high volume of reviews, publishing a corrected release is usually faster than waiting for a manual review of an appeal.
What Plugin Authors Need to Know
At this time, WordPress.org says emails are sent only when a release is blocked. Plugin authors who have not received a blocking email do not need to take any action.
The new automated review adds another security check before plugin releases are distributed through WordPress.org. For plugin developers, understanding the findings and addressing legitimate security issues will be important whenever a release is blocked by wordpress.org. In our understanding its a huge and amazing step towards a more secure wordpress eco-system.
Explore the latest in WordPress
Trying to stay on top of it all? Get the best tools, resources and inspiration sent to your inbox every Wednesday.


