Welcome to the official blog for the Plugins Team.
The team acts as gate-keepers and fresh eyes on newly submitted plugins, as well as reviewing any reported security or guideline violations.
Quick Links
The team acts as gate-keepers and fresh eyes on newly submitted plugins, as well as reviewing any reported security or guideline violations.
Quick Links
We’re launching an automated security review for every pluginPlugin A plugin is a piece of software containing a group of functions that can be added to a WordPress website. They can extend functionality or add new features to your WordPress websites. WordPress plugins are written in the PHP programming language and integrate seamlessly with WordPress. These can be free in the WordPress.org Plugin Directory https://wordpress.org/plugins/ or can be cost-based plugin from a third-party. release. Before a release is distributed through the WordPress.orgWordPress.org The community site where WordPress code is created and shared by the users. This is where you can download the source code for WordPress core, plugins and themes as well as the central location for community conversations and organization. https://wordpress.org/ update APIAPI An API or Application Programming Interface is a software intermediary that allows programs to interact with each other and share data in limited, clearly defined ways., it is analyzed for security issues and releases that are considered to pose a potential security risk (either intentional or unintentional).
This post explains how the process works and what is expected from plugin authors when a release is blocked.
New plugins are reviewed before they enter the directory, but updates ship continuously after that. A plugin can be secure today and introduce a vulnerability, or malicious code, in a future release. Until now there was no consistent review step between a release being committed and that release reaching millions of sites.
On July 28, a backdoor was committed to a release of a plugin with around 20,000 active installations. The automated review detected it and assigned a high security score, and because the release was still inside the cooldown window, the compromised version was never distributed through the WordPress.org update API. The plugin was closed for downloads 26 minutes after the Plugins Team was notified by Wordfence about the update.
That incident also made clear the missing piece: a high-risk result should stop distribution automatically, without depending on someone from the Plugins Team being available. That’s what we’re launching now.
Since June 5, every plugin and theme release goes through a cooldown before it is distributed through the WordPress.org update API, including one-click updates from the WordPress dashboard. The cooldown period is currently at 6 hours.
During the cooldown, the changes in each release are analyzed in WordPress.org by several AI models together with Jetpack Scan. The results are cross-checked and combined into findings with a security score. The higher the score, the higher the potential risk. Cross-checking multiple tools keeps accuracy high and false positives low, but not zero.
Releases with a high risk score are blocked automatically as soon as the security review finishes, and all plugin committers receive an email with the findings. Releases below that threshold continue through the normal process.
A high score does not mean malicious intent. An accidentally introduced vulnerability can score just as high as intentional malware. The score measures risk, not intent.
Right now, emails are only sent when a release is blocked. Authors who haven’t received an email don’t need to take any action.
A high risk score means the release will not be distributed through the update API until the issues are resolved.
The fastest way to get a release unblocked:
This process will keep evolving as we collect more data and improve the checks. Feedback about false positives is the most useful thing plugin authors can give us to make the system better.
Post written by @davidperez, reviewed by @frantorres, @lucasbustamante, @obenland.
The Plugins Team is aware of an issue currently affecting pluginPlugin A plugin is a piece of software containing a group of functions that can be added to a WordPress website. They can extend functionality or add new features to your WordPress websites. WordPress plugins are written in the PHP programming language and integrate seamlessly with WordPress. These can be free in the WordPress.org Plugin Directory https://wordpress.org/plugins/ or can be cost-based plugin from a third-party. releases and is actively investigating it.
At this time, newly released plugin ZIP files are not being generated as expected. We are also aware that some users are experiencing issues accessing SVNSVN Short for "SubVersioN", it's the code management system used to maintain the plugins hosted on WordPress.org. It's similar to git..
We will provide updates by editing this post as more information becomes available.
Thank you for your patience while we work to resolve the problem.
#pluginreview SlackSlack Slack is a Collaborative Group Chat Platform https://slack.com/. The WordPress community has its own Slack Channel at https://make.wordpress.org/chat/ channel and via email.To help us keep communication channels available for new reports and other requests, please do not email the Plugins Team about this issue. We will continue to update this post as more information becomes available.
This issue has now been resolved. Sorry for the inconvenience, and thank you for bringing it to our attention.
X-comment from +make.wordpress.org/project: Comment on WordPress Credits Updates
TL;DR: Three new reviewers have completed their onboarding and are now actively reviewing plugins. Thanks to them, and to the whole team, the review queue went from a mid-April peak of roughly 1,050 plugins back to nearly zero, even as submissions hit new records. And we have great news: the application form is open again for a second round. Apply here before 26 June 2026.
Back in March we published Contribute to the Plugins Team!, where we explained that you were submitting plugins faster than ever, and that we needed more hands on deck to keep up.
You answered. We received a wonderful response from the community, selected a first group of candidates, and started their training. Today we want to introduce the people who completed that process, show you what their contribution has already achieved, and let you know that the form is open again for anyone who wants to join the next round.
After roughly two months of onboarding and mentoring, three new members have joined the team and are already reviewing plugins and replying to authors every week. Please join us in welcoming:
Their work has been essential to the stability of the review queue. Beyond the reviews themselves, having more reviewers sharing the load means other members can devote more time to projects that improve the directory for everyone, such as Plugin Check and our internal scanner tooling. A healthy queue is not just about clearing a backlog, it is what makes the rest of the team’s work possible.
You can find them, and the rest of us, on the team page.
The best way to thank our new contributors is to show what changed. Here is how the review queue evolved through the first half of 2026, alongside the number of new plugins you submitted each week.


The story in numbers:
In other words: the team absorbed a rising tide of submissions and cleared a huge backlog at the same time. This was achieved thanks to the efforts of both existing and new team members. You are still increasing the number of plugins you submit, and besides plugin reviews we also have many more emails to manage regarding all kind of queries about the directory, its use and guidelines.
We’ve continued to lean on automated tooling to make reviews faster, and AI-assisted checks did help us handle this volume. But we want to be clear about something: these tools support reviewers; they don’t replace them.
Judgement calls, conversations with authors, security context, manage of guideline violations and the many edge cases that don’t fit a pattern all still depend on experienced humans. This is a combination of tooling and committed people working together.
The team is in better shape, but submissions keep increasing, we have new challenges ahead and want to be future-proof. As we announced in March, we’re opening a second round of applications. If you’d like to help keep the plugin directory healthy, secure, and reliable for the millions of sites that depend on it, we’d love to hear from you.
There are still two ways to contribute:
The deadline to apply for this round is 26 June 2026.
If you already submitted it back in March, you don’t need to do it again, we have your submission and it will be taken into account.
I want to apply to join the Plugins Team »
To Marcel, Shiva, and Shameem: thank you for the time, care, and energy you’ve already put in. To the reviewers who mentored them, the rest of the team and to the sponsors who help volunteers to devote their time and cover costs such as the intensive use of AI: thank you. And to everyone who submits and maintain plugins making the plugins directory a trusted place for extending WordPress’s functionality.
X-comment from +make.wordpress.org/docs: Comment on WordPress Documentation Team Closes 200+ Issues — and Needs Your Help
X-post from +make.wordpress.org/meta: Plugin Directory MCP Server
TL;DR: We are looking for contributors and/or organizations that are willing to contribute to the Plugins Team. Apply here.
In recent years, the Plugins Team has gone through several phases, and we have been able to meet the challenges you have set for us. In 2025, we were excited to manage twice as many plugins as in 2024 with approximately the same number of volunteers. This was possible thanks to improved processes and tools, as well as the higher quality of the plugins you submitted. Thank you very much for that.
It’s 2026, and… let’s be clear: you’re absolutely crushing it with plugins.

In previous years, we typically received 100–150 new pluginPlugin A plugin is a piece of software containing a group of functions that can be added to a WordPress website. They can extend functionality or add new features to your WordPress websites. WordPress plugins are written in the PHP programming language and integrate seamlessly with WordPress. These can be free in the WordPress.org Plugin Directory https://wordpress.org/plugins/ or can be cost-based plugin from a third-party. submissions per week. In 2025, that number started at over 200 per week and rose to more than 300 by the end of the year. In 2026, the pace is accelerating even further, exceeding 500 weekly submissions by March.
To keep up with this rapid growth, we need more hands on deck.
There are two ways to contribute to the team.
Our team is looking for new members who are able to join the team for reviewing plugins.
Your tasks would look like this:
Our current team members will guide and train you on how to perform these tasks. The training period takes about two months.
There are three essential requirements for successfully joining the team and contributing:
This three requirements and expectations are further explained in the form, you can check it out and submit your application now.
We know that it is not easy to reach the level of commitment that this team requires, which is why we know that sponsors are essential for the stability of this team.
We would like to thank all of the sponsors who support the volunteers on this team. Here are some of the achievements made in 2025 thanks to the support of the following sponsors:
The WordPress.orgWordPress.org The community site where WordPress code is created and shared by the users. This is where you can download the source code for WordPress core, plugins and themes as well as the central location for community conversations and organization. https://wordpress.org/ Plugins Team plays a vital role in maintaining the health, security, and reliability of the plugins directory, which serves millions of WordPress sites worldwide. By sponsoring volunteers on this team, you help ensure that contributors can dedicate time to reviewing plugins, maintaining quality standards, enforcing guidelines, and improving security across the ecosystem. This helps ensure that the plugins in the directory remain a trustworthy and reliable source of functionality that meets the essential standards expected within the WordPress environment.
You can sponsor the team by contributing the time of people from your organization or by supporting volunteers who are (or could be) on the team. If you don’t know anyone who you could sponsor, we will help you find them.
Our timeline:
Feel free to ask questions or share any feedback in the comments or email plugins at wordpress.org.
Thanks to @davidperez , @nilambar and @lukecarbis for their feedback for creating this process.