Malicious Closed by wp.org
Audit #25
WP Advanced Math Captcha
— 6k+ installs
Two distinct supply-chain attack chains in a single 6,000-install plugin, both operated by SiteGuarding (siteguarding.com) through two anonymous wp.org committer accounts. wp.org Plugin Review Team (PRT, plugin-master) closed the plugin on…
Malicious Closed by wp.org
Audit #26
Web Image Optimization X
— 100 installs
Attacker-controlled side-channel update endpoint shipped under the cover of "license validation" — same operator (SiteGuarding) and same sibling-plugin pair as audit #25 (wp-advanced-math-captcha). Where the wp-advanced-math-captcha audit …
Malicious Closed by wp.org
Audit #28
WP Antivirus Site Protection (by SiteGuarding.com)
— 4k+ installs
SiteGuarding 27-plugin portfolio (2013-2020) — 15 plugins shipped siteguarding_tools.php v1.7 RCE backdoor INLINE in the plugin folder; 12 sibling plugins shipped phone-home guideline violations. wp.org closed all 27 in May-June 2020. Oper…