Audits

7 suspicious audits. · 201 IOCs catalogued.

Verdict: All (38) Malicious (14) Cleaned (6) Suspicious (7) Inconclusive (0) Benign (11) In progress (0)
Suspicious

Audit #40 Kirki – Freeform Page Builder, Website Builder & Customizer — 500k+ installs

Verdict: SUSPICIOUS. The legitimate Kirki Customizer Framework (Aristeides Stathopoulos, 2014–2023, 500,000 active installs, used by hundreds of WordPress themes as a dependency) was effectively replaced at v6.0.0 (rele…

baseline 5.2.3 → head 6.0.6 Themeum cluster · 1mo ago
Suspicious

Audit #39 2-plugin suite — 8k+ combined installs

This audit re-examines the JoomSky vendor portfolio after audit #23 found setup.joomsky.com was the C2 endpoint for an eval(curl_exec(JCONSTINST)) remote-PHP-execution primitive shipped in js-support-ticket through 2017…

baseline → head 2.0.2 4 IOCs · 1mo ago
Suspicious

Audit #37 Category Country Aware WordPress — 100 installs

What's flagged. Same author + same pattern as audit #36 (country-caching-extension-for-wp-super-cache). The plugin wires the Yahnis Elsts Plugin Update Checker (PUC) into a literal-placeholder URL that the author never …

baseline → head 1.2.3 4 IOCs · 1mo ago
Suspicious

Audit #36 Country Caching For WP Super Cache — 200 installs

What's flagged. The plugin wires the Yahnis Elsts Plugin Update Checker (PUC) into a literal-placeholder URL that the author never replaced before publishing: `` cc_wpsc_init.php:17-18 $myUpdateChecker = Puc_v4_Factory:…

baseline → head 0.8.0 3 IOCs · 1mo ago
Suspicious

Audit #38 WYSIWYG Character Limit for ACF — 100 installs

Verdict: SUSPICIOUS. On 2026-05-06, codeandcore released v4.1.2 of WYSIWYG Character Limit for ACF with a single line change: the activation/opt-in/uninstall tracker that POSTed to wordpress-plugins.pro/receiver.php was…

baseline 4.1.1 → head 4.1.2 Codeandcore cluster · 1mo ago
Suspicious

Audit #35 Muchat – AI Chatbot (with Autosync) — 200 installs

Verdict: SUSPICIOUS — vendor self-own, not a supply-chain attack. muchat-ai v2.0.55 (released 2026-04-29 to wp.org, ~100 active installs) ships with API authentication explicitly disabled. The plugin's AuthMiddleware::v…

baseline 2.0.54 → head 2.0.55 Muchatai cluster · 1mo ago
Suspicious

Audit #34 Speedy Go — 40 installs

Verdict: SUSPICIOUS. Speedy Go v2.1.0 (released 2026-05-04) is a hostile-shape release pushed to the wp.org slug under the legitimate author's account. The changelog literally advertises "Bypassed all API key and licens…

baseline 2.0.3 → head 2.1.0 Codeandcore cluster · 1mo ago