ended6월 12일· 1 sources

When Plugin Acquisition Becomes a Security Threat

플러그인 구매 후 악성코드 배포, WordPress.org의 신뢰 체계를 흔들다

Why it matters

WordPress.org's decision to hold plugin updates for 24 hours reflects a fundamental shift in how the platform addresses supply chain threats. After 31 plugins were weaponized through legitimate acquisition in April 2026, infecting over 400,000 sites, the platform realized that author identity alone cannot guarantee safety. This marks a critical turning point where distribution infrastructure must verify every release, not individual developer trustworthiness.

1
Sources
+0
24h
Growth
4d
Active
WordPress.orgplugin securitysupply chain attackbackdoor distributionsecurity verification

Sources

Related Issues