Suspicious
Audit #40
Kirki – Freeform Page Builder, Website Builder & Customizer
— 500k+ installs
Verdict: SUSPICIOUS. The legitimate Kirki Customizer Framework (Aristeides Stathopoulos, 2014–2023, 500,000 active installs, used by hundreds of WordPress themes as a dependency) was effectively replaced at v6.0.0 (rele…
Suspicious
Audit #39
2-plugin suite
— 8k+ combined installs
This audit re-examines the JoomSky vendor portfolio after audit #23 found setup.joomsky.com was the C2 endpoint for an eval(curl_exec(JCONSTINST)) remote-PHP-execution primitive shipped in js-support-ticket through 2017…
Suspicious
Audit #37
Category Country Aware WordPress
— 100 installs
What's flagged. Same author + same pattern as audit #36 (country-caching-extension-for-wp-super-cache). The plugin wires the Yahnis Elsts Plugin Update Checker (PUC) into a literal-placeholder URL that the author never …
Suspicious
Audit #36
Country Caching For WP Super Cache
— 200 installs
What's flagged. The plugin wires the Yahnis Elsts Plugin Update Checker (PUC) into a literal-placeholder URL that the author never replaced before publishing: `` cc_wpsc_init.php:17-18 $myUpdateChecker = Puc_v4_Factory:…
Suspicious
Audit #38
WYSIWYG Character Limit for ACF
— 100 installs
Verdict: SUSPICIOUS. On 2026-05-06, codeandcore released v4.1.2 of WYSIWYG Character Limit for ACF with a single line change: the activation/opt-in/uninstall tracker that POSTed to wordpress-plugins.pro/receiver.php was…
Suspicious
Audit #35
Muchat – AI Chatbot (with Autosync)
— 200 installs
Verdict: SUSPICIOUS — vendor self-own, not a supply-chain attack. muchat-ai v2.0.55 (released 2026-04-29 to wp.org, ~100 active installs) ships with API authentication explicitly disabled. The plugin's AuthMiddleware::v…
Suspicious
Audit #34
Speedy Go
— 40 installs
Verdict: SUSPICIOUS. Speedy Go v2.1.0 (released 2026-05-04) is a hostile-shape release pushed to the wp.org slug under the legitimate author's account. The changelog literally advertises "Bypassed all API key and licens…