Jun 03, 2026
WP Tavern: How AI Is Exposing Hidden Threats in WordPress Plugin Updates
I joined Nathan Wrigley on the WP Tavern Jukebox podcast to talk about WordPress plugin supply chain attacks — how bad actors acquire legitimate plugins to inject malicious code or hijack update mechanisms, how AI is changing the way these threats get caught, and WP Beacon, the resource I built to document known compromises across the ecosystem.