ended6월 12일· 1 sources
When Plugin Acquisition Becomes a Security Threat
플러그인 구매 후 악성코드 배포, WordPress.org의 신뢰 체계를 흔들다
Why it matters
WordPress.org's decision to hold plugin updates for 24 hours reflects a fundamental shift in how the platform addresses supply chain threats. After 31 plugins were weaponized through legitimate acquisition in April 2026, infecting over 400,000 sites, the platform realized that author identity alone cannot guarantee safety. This marks a critical turning point where distribution infrastructure must verify every release, not individual developer trustworthiness.
1
Sources
+0
24h
—
Growth
4d
Active
WordPress.orgplugin securitysupply chain attackbackdoor distributionsecurity verification