Bad actors purchased popular plugins hosted on WordPress.org and added malware that was downloaded to users sites.

Supply Chain Attack Using the WordPress Directory
Austin Ginder @ anchor.host • 7 days ago

Austin Ginder @ anchor.host • 7 days ago
Bad actors purchased popular plugins hosted on WordPress.org and added malware that was downloaded to users sites.

Matt Cromwell @ therepository.email • 1 month ago
You may have noticed the Ollie Menu Designer and other newer plugins showing up first when you go to install a plugin. This is new and part of a move to help “hidden gems” get discovered.

George Demet @ youtube.com • 12 months ago
This is a presentation given at Drupal Con about the WordPress conflict. There are a lot of comparisons between the projects that people might find interesting.

David McCan @ wpdaily.news • 1 year ago
And the controversy continues! Checkout the new WordPress org login form. I hope you like pineapple on pizza.

Oliver Sid @ patchstack.com • 1 year ago
Patchstack reports on a WordPress security cleanup last month of plugins in the directory with vulnerabilities.

dd32 @ github.com • 1 year ago
If a site has a plugin installed that was closed in the WP plugin directory there is no notice in the site admin, which could be a security issue. The WordPress org Experiments plugin adds the notice in the admin that users would see if they were on the dot org site.

Matt Mullenweg @ wordpress.org • 2 years ago
Mary Hubbard is the new Executive Director of the WordPress.org.

Joost de Valk @ joost.blog • 2 years ago
Here is a great post from Joost that provides some insight into the current conflict with WP Engine.

Ramsés Del Rosario @ webdevstudios.com • 2 years ago
The html-tag-processor is a core WordPress class used by developers to find and modify attributes in an HTML document. This article discusses its benefits and performance. The article is more of an informational summary than a tutorial.