10 Jan 2025

Automattic Employee Changed WordPress Plugin Directory Search Algorithm to Promote Automattic’s Jetpack Plugin

As part of working on our Plugin Security Scorecard last year, we spent a fair amount of time using the search functionality of the WordPress Plugin Directory. Through that, we again and again ran across search results that prominently featured plugins with high install counts that were not relevant to the search results, while relevant plugins were sometimes buried later in the results.

One of the examples were you can see that happening is on a search for “translation”, which has as its fourth result, a 3+ million install backup plugin: [Read more]

3 Jan 2025

Locking Down Security With WooCommerce Plugins Involves Assessing Its Security, Not Unrelated Things Like When It Was Last Updated

We just soft launched a new option for searching for WordPress plugins. As part of making sure we produced the best tool we can, we revisited another option launched last year, Ploogins, which we mentioned back in September. As part of looking more into that, we ran across a post from the company behind that promoting it, while giving some really bad advice on assessing the security of WooCommerce extending plugins. Here that the most relevant portion:

Locking Down Security

Security is a big deal. A bad plugin can open the door to hackers, malware, and other nasty stuff. Here’s how to keep your site locked tight: [Read more]