WordPress Introduces AI-Enabled Security Assessment to Prevent Harmful Plugin Updates

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

WordPress Unveils AI-Enhanced Security Review for Plugin Releases

WordPress has rolled out an innovative, AI-driven security assessment protocol for every plugin release. This new endeavor seeks to intercept potentially vulnerable or malevolent updates before they are disseminated to millions of websites within its extensive update ecosystem.

The advanced system scrutinizes plugin updates prior to their release via the WordPress.org update API, encompassing updates installed directly from the WordPress dashboard.

Releases deemed to pose a substantial security threat will now be autonomously blocked, mitigating reliance on manual oversight by the Plugins Team.

AI-Powered Security Review Initiative

This initiative confronts a persistent shortcoming in supply-chain security within the WordPress environment. Although new plugins undergo an initial vetting before entering the official repository, developers can perpetually issue subsequent updates.

A plugin that is stable at launch may subsequently introduce vulnerabilities, compromised dependencies, or intentionally embedded malicious elements over time.

WordPress indicated that this capability supplements a cooldown mechanism unveiled on June 5 for both plugin and theme releases. The platform now retains each release prior to its distribution via the update API, with a current cooldown duration of six hours.

This interval provides automated systems with the necessary time to review code alterations before they impact active installations. Throughout this timeframe, WordPress.org evaluates each release through the application of multiple AI models and Jetpack Scan.

The employed tools undertake cross-verifications, aggregating their findings into a security rating. A heightened score signifies an escalated potential security risk, though it does not ascertain whether suspicious code was integrated with malicious intent or by inadvertence.

Factors such as a recently introduced authentication bypass, unsanctioned file-upload handler, remote code execution vulnerabilities, obfuscated code loaders, credential-stealing mechanisms, or concealed backdoors could all result in a heightened risk categorization.

The automated scoring system quantifies the security ramifications and the probability of exploitation, rather than the developer’s motivation.

WordPress claimed that it employs an array of analytical systems to enhance detection precision and diminish false positives, although it acknowledged the possibility of erroneous alerts.

Releases that fail to meet the blocking criteria will undergo the conventional cooldown and distribution procedure. Conversely, high-risk releases will be automatically prevented from reaching the WordPress.org update API upon the conclusion of the security assessment.

All registered plugin committers will receive an email detailing the findings that prompted the blockage. Developers whose releases are not impeded will not receive a notification and need not take further action.

This modification comes in the aftermath of a July 28 incident involving a plugin with approximately 20,000 active installations. A backdoor was inadvertently integrated into a release, yet the automated review assigned it a high security rating while still within the cooldown timeframe.

Consequently, WordPress did not disseminate the compromised iteration via the update API. WordPress further reported that the plugin was withdrawn from downloads a mere 26 minutes after the Plugins Team received an alert from Wordfence.

For blocked releases, WordPress advises authors to initially scrutinize the reported issues, rectify the problems, and proceed with publishing a revised version.

Should the replacement release achieve a score below the threshold, it will continue through the standard cooldown protocol.

Blue circle icon with two interlocking plugs, one featuring the WordPress logo, symbolizing WordPress plugins or connectivity.

Plugin authors can reach out to the Plugins Team if they suspect an inaccurate detection. However, WordPress warned that manual reviews may experience delays due to review volume, rendering the issuance of a corrected release the most expedient means to restore update availability.

Enhance your threat detection by 58% with cutting-edge intelligence sourced from over 16,000 organizations. Integrate Threat Intelligence Feeds into your Security Operations Center.

Source link: Cyberpress.org.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading