We’re launching an automated security review for every plugin release. Before a release is distributed through the WordPress.org update API, it is analyzed for security issues and releases that are considered to pose a potential security risk (either intentional or unintentional).
This post explains how the process works and what is expected from plugin authors when a release is blocked.
Why we’re doing this
New plugins are reviewed before they enter the directory, but updates ship continuously after that. A plugin can be secure today and introduce a vulnerability, or malicious code, in a future release. Until now there was
Click here to continue reading this article.
