This is already happening. In 2026 alone, three documented incidents involved compromised releases of five premium WordPress plugins: Smart Slider 3 Pro, three ShapedPlugin products, and Admin Menu Editor Pro. In each case, malicious code reached customers through the vendor’s own distribution infrastructure.
When trust model goes wrong
For a long time, the WordPress ecosystem ran on a simple trust model. You install a plugin, and you trust that the developer can secure their code, their development environment, their update infrastructure, everything. That trust is getting harder to justify. The speed at which vulnerabilities are found, chained together, and exploited is already relentless, and AI is accelerating that pace even further.
But the deeper issue is the model itself. WordPress lets any developer push code to your site and execute it without real constraints. So choosing a plugin isn’t just about assessing functionality. It’s about asking: can I trust this developer? Can I trust their company? Can I trust that their infrastructure won’t be the weak link that compromises mine?
An attacker might compromise a developer’s server, code repository or release system through a simple vulnerability, or they might have an AI agent spend days probing for one. Either way, the goal is the same: alter the next update. But there are simpler paths.
Someone can buy the plugin. A new owner inherits an established product, its reputation and a way to deliver updates to existing users. A malicious buyer can use that access to introduce a backdoor. Wordfence documented this with Display Widgets after the plugin changed hands in 2017. More recently, Anchor Hosting investigated backdoors introduced after the sale of the Essential Plugin business.
Someone can take over an abandoned update domain. A developer moves on, lets a domain expire, and someone else registers it. If installed copies of the plugin still trust that domain for updates and have no independent way to verify the publisher, its new owner may be able to push malicious packages. The address looks familiar even though the person behind it has changed.
In each of these situations, a small code addition can create a hidden administrator, open a backdoor, steal credentials or download more malware later. For the website owner, the update looks routine: a familiar plugin, a valid license and a download from the expected place.
A plugin’s name and history can stay the same while control of its updates changes. That’s why we need to look at what’s actually in the code being delivered, even when we’ve used the plugin for years.
This month’s Admin Menu Editor Pro incident is a clear example. On 14 September, its author, Jānis Elsts, discovered a malicious package being distributed as version 2.35. It installed a web shell that could give an attacker control of an affected site. A clean replacement, version 2.36, was then compromised as well. Someone installing the tampered update through the normal WordPress update process could infect their site.
Jānis initially estimated that about 230 customers were affected, often with multiple websites per customer. That figure covered the initial compromise, and the full affected customer list remained incomplete. The number of affected websites could be considerably larger, but the advisory does not establish a reliable total.
At Awwwsome, keeping your site updated is part of the service our team manages for you. We normally run routine updates every two weeks and allow new packages a cooldown period before installing them. That gives problems time to surface before a release reaches the websites in our care.
In this case, our managed update process avoided the compromised Admin Menu Editor Pro package.
But waiting is only one part of the process. Sometimes an update closes a vulnerability that needs urgent attention, especially when we can’t rely on our existing protections, including Patchstack, to cover it. In those situations, we need to move quickly. A cooldown also can’t tell us what’s actually inside a package.
So, being the geeks we are, we started thinking about how to take a closer look. We wanted to examine the code arriving in an update, identify suspicious changes and give our team useful evidence before deciding whether to install it.
That became Awwwsome Defensify.
Defensify helps our team catch malicious plugin changes before they reach your website. It combines automated code checks with AI-assisted analysis and a review by our team. We’re rolling it out in beta now as part of the Awwwsome platform, alongside the fully managed hosting and updates our clients already rely on.
How Defensify works
Here’s how the review process works:
- Establish a comparison point. Defensify records the plugins installed on a connected site. These become the starting point for comparing future updates.
- Collect the update. It retrieves the available package through WordPress’s existing download mechanisms, including supported premium-plugin integrations.
- Examine what changed. It compares the package with the site’s recorded version and checks added or modified code for suspicious behavior. The analysis does not run the plugin code.
- Prepare the evidence. AI-assisted analysis examines the findings and produces a report with reasoning, references to the relevant code and any gaps in the checks.
- Our team makes the final call. We review the evidence and approve, hold or reject the package. AI never grants installation permission.
The checks look for signs of backdoors, hidden administrator accounts, credential theft and code designed to download malicious payloads or preserve unauthorized access.
Approval is tied to the actual package contents and the site’s comparison history. If someone changes the package while keeping the same version number, those different contents can’t inherit an earlier approval. That’s particularly relevant when an attacker can replace a download on a vendor’s server.
For sites using Defensify, all of this is work for our team. You won’t need to interpret security reports or make technical decisions about suspicious plugin code. Defensify gives the people already managing your website another way to investigate updates and keep a record of the decisions they make.
Awwwsome Defensify will be $50 per month per site during beta, and $100 per month when it launches. Pricing is per site, regardless of the number of plugins or update frequency. Discounts are available to our Agency Partners.
Running this review process has ongoing costs: the infrastructure that scans and stores update packages, the AI models used in assessments, and the time our team spends reviewing findings and making update decisions. That’s what’s behind the price. The beta price reflects that we’re still refining the process. The launch price reflects what it takes to run it at scale.
What’s included in the beta (and what’s next)
We’re bringing Defensify into beta with a clear scope and more work ahead:
- The default mode observes updates. It collects packages and displays advisory results without automatically blocking installations. Optional blocking has been tested on disposable sites and still needs broader compatibility testing.
- It can’t guarantee that an update is safe. The checks target malicious changes; they don’t find every vulnerability or replace the other protections around your website.
- The starting point is trusted. Recording an installed plugin doesn’t audit it for existing malware. The review focuses on subsequent changes.
- Coverage has limits. Vendor integrations and update methods need further testing. Remote scripts can be flagged, but their contents aren’t downloaded or continuously monitored; those scripts can change without a plugin update. Incomplete checks remain visible in the report.
Two further capabilities are planned:
- A WordPress-specific antivirus scanner. We plan to integrate a scanner focused on WordPress malware, adding another detection layer alongside the existing code checks and AI-assisted assessments.
- Review of dynamically loaded third-party code. Some plugins load code from outside the update package, such as scripts hosted on the developer’s content delivery network. That code can change independently of the installed plugin. We plan to extend our review to address those dependencies, so we can better assess what a plugin loads as well as what its package contains.
These are roadmap items, not capabilities included in the current beta. Alongside them, we’ll test more real update paths, evaluate detection on a broader set of benign and malicious code, and refine the review process around what our team learns.
We’re proud to be adding Defensify to the Awwwsome platform. Fully managed hosting means trusting us with the ongoing care of your website, including the judgment behind its updates.
Building better tools for that work is part of how we earn that trust.
If you want to add Defensify to your site, get in touch and we’ll get you set up.