2 Aug 2019

Plugin New to WordPress Plugin Directory with “400,000+ Installs” Is Lacking Basic Security

The plugin Essential Grid Portfolio – Photo Gallery was closed on the WordPress Plugin Directory yesterday. That is one of the 1,000 most popular plugins with 400,000+ installs, so we were alerted to its closure. When we started looking in to the plugin to see if there were any vulnerabilities we should be warning users of the plugin that also use our service, we found that the situation with the plugin seemed odd. The plugin has 400,000+ installs, but was only added to the Plugin Directory on July 22.

In looking into what might explain that discrepancy led us to some oddities. Here is the bio for the developer on their website, navyplugins.com: [Read more]