Are there procedures to prevent malicious plugin updates?

TLDR: No. It’s all about trust.

So there are some very basic checks on wp.org but generally this can happen (and probably also does happen from time to time). Of course if something like this happens and people notice it wp.org can block updates or replace them with something safe.

Also have a look at the WordPress.org Theme and Plugin Repositories section.

What you can do is not really any different than what you’d do whenever you install software, things like:

  • look at the source code
  • research on the plugin and/or the developer to decide if they deserve your trust
  • talk to other people about the plugin
  • do not randomly install plugins you come along
  • hire someone to do audits

Leave a Comment