Audits

38 audits. · 201 IOCs catalogued.

Verdict: All (38) Malicious (14) Cleaned (6) Suspicious (7) Inconclusive (0) Benign (11) In progress (0)
Suspicious

Audit #40 Kirki – Freeform Page Builder, Website Builder & Customizer — 500k+ installs

Verdict: SUSPICIOUS. The legitimate Kirki Customizer Framework (Aristeides Stathopoulos, 2014–2023, 500,000 active installs, used by hundreds of WordPress themes as a dependency) was effectively replaced at v6.0.0 (rele…

baseline 5.2.3 → head 6.0.6 Themeum cluster · 1mo ago
Suspicious

Audit #39 2-plugin suite — 8k+ combined installs

This audit re-examines the JoomSky vendor portfolio after audit #23 found setup.joomsky.com was the C2 endpoint for an eval(curl_exec(JCONSTINST)) remote-PHP-execution primitive shipped in js-support-ticket through 2017…

baseline → head 2.0.2 4 IOCs · 1mo ago
Suspicious

Audit #37 Category Country Aware WordPress — 100 installs

What's flagged. Same author + same pattern as audit #36 (country-caching-extension-for-wp-super-cache). The plugin wires the Yahnis Elsts Plugin Update Checker (PUC) into a literal-placeholder URL that the author never …

baseline → head 1.2.3 4 IOCs · 1mo ago
Suspicious

Audit #36 Country Caching For WP Super Cache — 200 installs

What's flagged. The plugin wires the Yahnis Elsts Plugin Update Checker (PUC) into a literal-placeholder URL that the author never replaced before publishing: `` cc_wpsc_init.php:17-18 $myUpdateChecker = Puc_v4_Factory:…

baseline → head 0.8.0 3 IOCs · 1mo ago
Suspicious

Audit #38 WYSIWYG Character Limit for ACF — 100 installs

Verdict: SUSPICIOUS. On 2026-05-06, codeandcore released v4.1.2 of WYSIWYG Character Limit for ACF with a single line change: the activation/opt-in/uninstall tracker that POSTed to wordpress-plugins.pro/receiver.php was…

baseline 4.1.1 → head 4.1.2 Codeandcore cluster · 1mo ago
Suspicious

Audit #35 Muchat – AI Chatbot (with Autosync) — 200 installs

Verdict: SUSPICIOUS — vendor self-own, not a supply-chain attack. muchat-ai v2.0.55 (released 2026-04-29 to wp.org, ~100 active installs) ships with API authentication explicitly disabled. The plugin's AuthMiddleware::v…

baseline 2.0.54 → head 2.0.55 Muchatai cluster · 1mo ago
Suspicious

Audit #34 Speedy Go — 40 installs

Verdict: SUSPICIOUS. Speedy Go v2.1.0 (released 2026-05-04) is a hostile-shape release pushed to the wp.org slug under the legitimate author's account. The changelog literally advertises "Bypassed all API key and licens…

baseline 2.0.3 → head 2.1.0 Codeandcore cluster · 1mo ago
Benign

Audit #33 5-plugin suite — 370 combined installs

Verdict: BENIGN. Five plugins published by author Mathew (mathewt) on wp.org — add-as-preferred-source (90 installs), browser-address-bar-color-changer (50), image-zoom-on-hover (30), disable-right-click-content-copy-pr…

baseline 1.1 → head 1.2 Mathewt cluster · 1mo ago
Benign

Audit #31 WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping — 10k+ installs

Verdict: benign — wp.org guideline violation, not malware. WP Product Feed Manager (display name "WPMR Google Feed Manager for WooCommerce") was closed by wp.org on 2026-04-27 with the standard silent-closure notice ("T…

baseline 2.22.0 → head 2.23.1 Aukejomm cluster · 1mo ago
Benign

Audit #29 Greenshift – animation and page builder blocks — 70k+ installs

Verdict: benign — wp.org guideline violation, not malware. Greenshift was closed by wp.org twice in four months (2026-01-15 and 2026-04-29) over the same root cause: the free plugin shipped a full paid-license activatio…

baseline 12.5.7 → head 12.9.5 Wpsoul cluster · 1mo ago
Cleaned

Audit #23 JS Help Desk – AI-Powered Support & Ticketing System — 8k+ installs

Historical audit. The proinstaller module shipped versions 1.0.3 through ~2.0.1 (2015-02 to 2017-03) carrying an eval(curl_exec(JCONSTINST)) primitive — a vendor-controlled remote-PHP-execution channel pointed at setup.…

baseline 1.0.3 → head 3.0.8 7 IOCs · 1mo ago
Benign

Audit #18 WPBot – AI ChatBot for Live Support, Lead Generation, AI Services — 6k+ installs

Suspect-shape but multiply-unreachable dead code — benign. WPBot's includes/openai/plugin-upgrader/ and includes/integration/openai/plugin-upgrader/ directories ship a self-update class (QCLD_openaiaddon_AutoUpdate) who…

by quantumcloud · baseline 0.9.0 → head 8.2.4 1mo ago
Benign

Audit #17 YARPP – Yet Another Related Posts Plugin — 100k+ installs

Suspect-shape but structurally unreachable — benign with one regression to flag. YARPP's version_info() matches the high-confidence catalog IOC unserialize_after_remote_call (@unserialize of wp_remote_post body, hardcod…

by jeffparker · baseline 1.0 → head 5.30.11 1mo ago
Benign

Audit #16 Media Cloud for Bunny CDN, Amazon S3, Cloudflare R2, Google Cloud Storage, DigitalOcean and more — 7k+ installs

Clean — no supply-chain anomaly. Full git-level audit of ilab-media-tools (Media Cloud by interfacelab) covering all 162 published versions back to 2016-07. Single committer for 8 years, zero detection events, zero IOC …

by interfacelab · baseline 1.0.0 → head 4.6.4 1mo ago
Benign

Audit #15 Content Egg – Affiliate Product Importer & Price Comparison — 10k+ installs

Historical PHP Object Injection chain in Admitad integration — gated since v6.0.0 (2023-08-21), endpoint dead. Two compounding patterns in application/libs/admitad/AdmitadProducts.php + application/libs/RestClient.php f…

by keywordrush · baseline 11.0.0 → head 11.0.0 3 IOCs · 1mo ago
Benign

Audit #30 Subscribe To Comments Reloaded — 10k+ installs

Verdict: benign — abandonment closure, not malware. Subscribe To Comments Reloaded was closed by wp.org on 2026-04-28 with the standard silent-closure notice ("This closure is temporary, pending a full review"). The clo…

baseline 220725 → head 240119 Wpkube cluster · 1mo ago
Cleaned

Audit #14 Social Sharing Plugin – Social Warfare — 20k+ installs

Confirmed malicious supply-chain compromise. Between 2024-04-05 and 2024-06-22 the WarfarePlugins wp.org committer account was used to push six tagged releases (4.4.6.4, 4.4.6.5, 4.4.6.6, 4.4.6.8, 4.4.6.9, 4.4.7.1) cont…

baseline 4.4.6.3 → head 4.4.7.1 17 IOCs · 1mo ago
Benign

Audit #32 83-plugin suite — 203k+ combined installs

Verdict: benign — portfolio-wide guideline violation, not malware. On 2026-04-27 WordPress.org closed 83 plugins from WPFactory's family of author accounts (wpcodefactory, algoritmika, and woobewoo) in a single one-hour…

baseline 4.6.0 → head 4.6.2 Wpcodefactory cluster · 1mo ago
Malicious Closed by wp.org

Audit #12 Scroll To Top — 20k+ installs

Update-checker hijack with active stored-XSS / RCE primitives served from a Panama-fronted C2. scroll-top (20,000 active installs) was sold by original author Ga Satrya (@gasatrya) to an actor identified as Benjamin (wp…

baseline → head 1.5.3 11 IOCs · 1mo ago
Benign

Audit #11 MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites — 700k+ installs

Who made the change. Committer thanghoang pushed their first commit to this plugin on 2024-07-09, when their WordPress.org account was only 12 days old (created 2024-06-27). New-account commits on established plugins ar…

by thanghoang · baseline 5.1 → head 5.1.1 1mo ago
Benign

Audit #6 Smash Balloon Social Photo Feed – Easy Social Feeds Plugin — 1M+ installs

Verdict: legitimate team onboarding — not a takeover. alexopen is a Smash Balloon employee ("Alex at Smash Balloon" display name), added as a committer to the five Smash Balloon social-feed plugins owned by Awesome Moti…

by alexopen · baseline 6.9.1 → head 6.10.0 1mo ago
Malicious Closed by wp.org

Audit #43 WP Install From Web — 100 installs

This is a previously-undocumented SiteGuarding supply-chain backdoor burner. It was surfaced by hunting for plugins that WP.org cleaned on closure — i.e. where a Plugin Review Team account force-pushed a code change at …

by safetydev · baseline → head 1.10.1 SiteGuarding cluster · 3 IOCs · 1d ago
Malicious Closed by wp.org

Audit #10 Widget Logic — 100k+ installs

Verdict: malicious. Confirmed supply-chain compromise matching the disclosed attack at anchor.host/how-i-caught-a-wordpress-plugin-supply-chain-attack and covered by TheNextWeb, Yahoo Tech, BigGo, byteiota, and others. …

by widgetlogics · baseline 5.10.4 → head 6.0.0 8 IOCs · 1mo ago
Malicious Closed by wp.org

Audit #13 Quick Page/Post Redirect Plugin — 70k+ installs

The original author intentionally weaponized wordpress.org distribution to seed an out-of-band update channel they controlled — and then served tampered builds through that channel after the wp.org-distributed code went…

by anadnet · baseline 5.2.1 → head 5.2.4 12 IOCs · 2mo ago
Malicious Closed by wp.org

Audit #4 33-plugin suite — 195k+ combined installs

Marketplace acquisition of an established 30-plugin portfolio used as a vehicle for a fleet-wide PHP-deserialization RCE backdoor with on-chain C2 resolution. A buyer identified only as "Kris" purchased the entire Essen…

by essentialplugin · baseline 2.6.6 → head 2.6.9.1 15 IOCs · 1mo ago
Malicious Closed by wp.org

Audit #25 WP Advanced Math Captcha — 6k+ installs

Two distinct supply-chain attack chains in a single 6,000-install plugin, both operated by SiteGuarding (siteguarding.com) through two anonymous wp.org committer accounts. wp.org Plugin Review Team (PRT, plugin-master) …

baseline 2.1.8 → head 2.1.9.1 SiteGuarding cluster · 33 IOCs · 1mo ago
Malicious Closed by wp.org

Audit #26 Web Image Optimization X — 100 installs

Attacker-controlled side-channel update endpoint shipped under the cover of "license validation" — same operator (SiteGuarding) and same sibling-plugin pair as audit #25 (wp-advanced-math-captcha). Where the wp-advanced…

baseline 1.0.8 → head 1.4.0 SiteGuarding cluster · 15 IOCs · 1mo ago
Malicious Closed by wp.org

Audit #42 Speedup Optimization — 100 installs

A previously-undocumented SiteGuarding burner, surfaced by the clean-on-closure hunt and closed in the same 2026-04-07 wave that took down the two documented burners. The backdoor. speedup-optimization.php defines speed…

by charlycharm · baseline → head 1.2.1 SiteGuarding cluster · 3 IOCs · 1d ago
Malicious Closed by wp.org

Audit #45 WP Google Core Web Vitals Fix — 400 installs

A SiteGuarding burner with a full remote-code-execution + persistence backdoor — Tier A. Surfaced by the closed-plugin blob scan (the new payload-decode scanner), which matched cmsplughub.com in the trunk that the old P…

by roshellco · baseline → head 1.0.4 SiteGuarding cluster · 4 IOCs · 1d ago
Malicious Closed by wp.org

Audit #46 Code Quality Control Tool — 50 installs

A SiteGuarding burner with an undisclosed wp-config.php persistence injection — Tier A. Surfaced by the closed-plugin blob scan, which matched safetybis.com in the trunk. The persistence mechanism. Patch_WPconfig_file()…

by nickclarkweb · baseline → head 2.1 SiteGuarding cluster · 3 IOCs · 1d ago
Malicious Closed by wp.org

Audit #47 Magex AI Bot Defender — 10 installs

A SiteGuarding burner that routes through the safetybis.com C2 — Tier B (undisclosed phone-home / proxy, no in-plugin RCE sink). Surfaced by the closed-plugin blob scan via siteguarding.com + safetybis.com references in…

by viktoriasantos · baseline → head 1.5.8 SiteGuarding cluster · 3 IOCs · 1d ago
Malicious Closed by wp.org

Audit #44 ByteDefense Security — — installs

A SiteGuarding security-branded front, surfaced by the clean-on-closure hunt. Unlike the documented closures that left malware in trunk, WP.org's plugin-master force-pushed a "Removing" commit at closure that stripped t…

by lanechristian891 · baseline → head 2.1 SiteGuarding cluster · 3 IOCs · 1d ago
Malicious Closed by wp.org

Audit #48 9-plugin suite — 80 combined installs

Verdict: malicious — a previously-undocumented 2024 wave of nine SiteGuarding supply-chain burner plugins, each on its own throwaway wp.org account. This is a distinct third operational phase of the SiteGuarding operati…

baseline → head (suite — 9 plugins) SiteGuarding cluster · 3 IOCs · 1d ago
Cleaned

Audit #20 Contact Form Multi-Step Addon — 300 installs

Confirmed malicious supply-chain compromise of themerex SVN account, recovered by the legitimate maintainer. Between 2024-06-23 22:47 UTC and 2024-06-24 04:10 UTC the themerex account was used to push two malicious "Upg…

by themerex · baseline trunk@r3071804 → head trunk@r3106511 1y ago
Cleaned

Audit #19 BLAZE Retail Widget — 10 installs

Confirmed malicious supply-chain compromise — 30 commits in a 28-hour burst. Between 2024-06-21 23:21 UTC and 2024-06-24 03:50 UTC the legitimate blazeretail SVN account was used to push 30 commits (all with the message…

by blazeretail · baseline trunk@r2268077 → head trunk@r3106494 8 IOCs · 1y ago
Cleaned

Audit #21 Simply Show Hooks — 4k+ installs

Confirmed malicious supply-chain compromise — stuartobrien SVN account compromised after 8-year dormancy. The plugin had been completely silent since 2016-10-27 (r1522935). On 2024-06-21 23:55 UTC the dormant account wa…

by stuartobrien · baseline trunk@r1522935 → head trunk@r3105891 1y ago
Cleaned

Audit #22 Wrapper Link Elementor — 700 installs

Confirmed malicious supply-chain compromise — and the only one in the wave that was self-cleaned by the legitimate author before PRT intervened. Between 2024-06-23 22:42 UTC and 2024-06-24 04:07 UTC the pedrogusmao02 SV…

by pedrogusmao02 · baseline trunk@r2903023 → head trunk@r3106508 1y ago
Malicious Closed by wp.org

Audit #28 27-plugin suite — 8k+ combined installs

SiteGuarding 27-plugin portfolio (2013-2020) — 15 plugins shipped siteguarding_tools.php v1.7 RCE backdoor INLINE in the plugin folder; 12 sibling plugins shipped phone-home guideline violations. wp.org closed all 27 in…

baseline 1.2 → head 7.5.4 SiteGuarding cluster · 7 IOCs · 1mo ago