WordPress Introduces Automated Security Reviews for Every Plugin Release

Sandeep Kumar Mishra
Sandeep Kumar Mishra
in Posts > News
September 14, 2026
5 minutes read
WordPress Introduces Automated Security Reviews for Every Plugin Release

WordPress has introduced an automated security review process for every plugin release. Before a new release is distributed through the WordPress.org Update API, it is now analyzed for potential security risks.

If a release is considered to pose a high security risk, whether intentionally or unintentionally, it can be automatically blocked from distribution.

Why WordPress.org Introduced Automated Security Reviews

Plugins are reviewed when they are initially submitted to the WordPress.org directory, but updates are released continuously. A plugin that is secure today could potentially introduce a vulnerability or malicious code in a future release.

WordPress.org says some recent incidents highlighted the need for an automated security check before plugin updates reach users.

How the Automated Security Review Works

Since June 5, 2026, every plugin and theme release has gone through a cooldown period before being distributed through the WordPress.org Update API. The current cooldown period is six hours, including for one-click updates from the WordPress dashboard.

During this period, WordPress.org analyzes release changes using several AI models together with Jetpack Scan. The results are cross-checked and combined into findings that receive a security score.

A higher score indicates a higher potential security risk. Releases that reach the blocking threshold are automatically stopped, and plugin committers receive an email containing the findings.

Importantly, WordPress.org notes that a high security score does not necessarily mean malicious intent. An accidentally introduced vulnerability can receive a similarly high score because the system measures risk rather than intent.

What Happens If a Release Is Blocked?

A blocked release will not be distributed through the WordPress.org Update API until the identified issues are resolved.

Plugin authors should:

  1. Review the reported findings to understand what triggered the block.
  2. Fix the issues and publish a new release. The new version will go through the normal cooldown and security review process.
  3. Contact the Plugins Team if a finding appears to be incorrect.

WordPress.org notes that because the Plugins Team handles a high volume of reviews, publishing a corrected release is usually faster than waiting for a manual review of an appeal.

What Plugin Authors Need to Know

At this time, WordPress.org says emails are sent only when a release is blocked. Plugin authors who have not received a blocking email do not need to take any action.

The new automated review adds another security check before plugin releases are distributed through WordPress.org. For plugin developers, understanding the findings and addressing legitimate security issues will be important whenever a release is blocked by wordpress.org. In our understanding its a huge and amazing step towards a more secure wordpress eco-system.

Sandeep Kumar Mishra

Sandeep Kumar Mishra

Sandeep Kumar Mishra writes about WordPress and Artificial Intelligence, offering tips and guides to help you master your website and stay updated with the latest tech trends.

Explore the latest in WordPress

Trying to stay on top of it all? Get the best tools, resources and inspiration sent to your inbox every Wednesday.