Adds warning message to WordPress Plugin Directory pages when plugins are from developer we have released security advisories for.
One of the little understood realities of security issues with WordPress plugins is that the insecurity of them is not evenly spread across those plugins. Instead, many developers are properly securing their plugins and others get them properly secured when alerted they haven’t done that, while other plugin developers either are unable or unwilling to properly secure their plugins. With the latter group, among the issues we have seen, are developers who have introduced new serious vulnerabilities that are substantially similar to vulnerabilities that they know have been exploited in their plugins.
In situations where we become aware of developers who have shown that inability or unwillingness to properly secure their plugin, we are releasing advisories to warn customers of our service and the wider WordPress community of the risk of utilizing those developers' plugins. This extension adds a notice on the pages of the WordPress Plugin Directory for the plugins from those developers.
Latest reviews
- (2022-09-14) Trone: This extension just displayed a warning on a plugin page in the WordPress repository -- which is exactly what it's supposed to do. A link was included for more information. Thanks to the devs for making this available! If possible, it would be great if you could make similar warnings appear when we find plugins in our dashboards, before installation. That would save us from needing to check the repository page for warnings.