Ownership change
The listed author or contributor list no longer matches the stored snapshot. A dropped original author means the handover is already complete.
And whether anyone changed their code. Touchstone tells you when a plugin on your site changes hands, checks every code file against WordPress.org’s official copy, and stops code being changed from the admin. Replayed against the 31 plugins backdoored in 2026, it warns on every one, a median of 139 days before the backdoor switched on.
A change of ownership is the quietest supply-chain attack on WordPress, because nothing about the code looks wrong yet.
When a plugin is sold, WordPress.org performs no audit and sends no notification. The new owner inherits commit access, and their first release reaches every site running it through the ordinary update channel.
This is a documented gap, not an inference. WordPress meta ticket #5509, Notify users of changes to plugin ownership, was opened to add exactly that notification. It is still open and unresolved.
In April 2026 the WordPress Plugins Team closed 31 plugins at once. A single buyer had acquired the portfolio through Flippa, planted a backdoor across all of them, and waited. Most of those sites were running a vulnerability scanner the entire time, and a scanner has nothing useful to say about a plugin whose code has not turned malicious yet.
We replayed Touchstone against their public history. It warns on all 31, naming the account that shipped the backdoor, a median of 139 days before it switched on. See the replay, method and limits included.
Both 2026 incidents, dated and sourced — including the one this plugin would not have caught.
A transfer is not an attack. It is the window in which one becomes possible — and the only moment at which you still get to choose.
Three steps, every day, from public sources and your own files.
On the first scan it inventories every installed plugin and reads back up to 200 commits of SVN history, recording each committer with their first and last revision.
Recorded plugin-slug · committer-a r1–r2981 · committer-b r302–r2104
Every day it re-reads the public record and diffs it against what it stored, and checks every code file against WordPress.org’s official fingerprints. A new name, or a file that no longer matches, is the signal; eight rules decide what kind.
Changed author replaced · +1 unseen committer at r2982
The trust score moves, the plugin rises to the top, and anything serious reaches your inbox within the hour. You acknowledge it, mute the plugin, or turn off its auto-updates in one click.
Scored trust 94 → 61 · band ok → watch
Everything runs in the background, a little at a time, never during a front-end request. Your visitors never touch this code.
Five watch who controls each plugin. Three watch the code itself and who can change it. Control usually changes months before the code does, so you hear about both.
The listed author or contributor list no longer matches the stored snapshot. A dropped original author means the handover is already complete.
A previously unseen SVN username has committed for the first time. This is the event that precedes a payload, usually by weeks or months.
180 days of silence followed by a commit. Escalates when it lands alongside an ownership change or a new committer.
No update in 365 days, escalating past 730. Closed or removed from the directory is a high-risk finding with the date and reason, even if it was closed before you installed Touchstone.
The plugin is not in the directory, so it has no public history and cannot be monitored. It is listed as a blind spot rather than given a grade it has not earned.
A file in WordPress core or a plugin no longer matches WordPress.org’s official fingerprint, or the first copy Touchstone saw. Named by file, and emailed within the hour. Put it back and the finding says so.
A code file that should not be there: added to a plugin, dropped into wp-content, or any PHP file in uploads, where a backdoor usually hides.
A new administrator, a role raised to administrator, a changed admin email or a new application password. The quiet ways someone keeps a way back in.
Every plugin carries a deterministic score from 0 to 100. Same inputs, same score, with nothing you cannot explain to the person paying the invoice.
0/100
Band boundaries are fixed and published.
No new dashboard to log into, and nothing for your client to learn.
There are no certifications on this page because there are none to show. Here is the whole mechanism instead.
A plugin slug and its version are all that is sent. Your files are compared on your own server; no file contents ever leave it.
In June 2026 ShapedPlugin’s build pipeline was compromised and a malicious build shipped under the existing maintainer’s name (CVE-2026-10735). No author changed. No new committer appeared. Touchstone’s ownership rules would have shown nothing, and because the poisoned build was the official release, its code check would have matched too.
It detects a change in who holds control. It cannot detect an existing owner’s pipeline being turned against them. That is what your malware scanner is for, and it is why this runs alongside one rather than instead of it.
GPLv2, and the plugin ships as plain PHP with no build step: every outbound call is readable in src/Api/ and src/Integrity/. The free build contains no licensing code at all.
Every rule, the code check, Code lock and every screen, on every site, with nothing held back to sell you later. Pro is for acting on what it finds.
Submitted for review
$0forever
Built, coming soon
$59/yr, 5 sites
In development
$179/yr, 25 sites
Pro is built and goes on sale soon; Agency follows. Neither is purchasable yet, and neither will ever live inside the free plugin — WordPress.org forbids paywalls in a hosted plugin, which is why the free build carries no licence code at all. Moving from Pro to Agency is a licence change, never a reinstall.
Replayed against the public history of all 31 plugins closed in April 2026, it raises a high-severity new-committer warning on every one, naming the account that shipped the backdoor, a median of 139 days before the backdoor switched on. The backdoor itself was inside the official releases, so a file check alone would not have caught it; the change of hands is the signal. The replay, method and limits included.
They look for code that is already known to be bad. Touchstone watches who is behind your code and whether it is still genuine: an ownership transfer, a new committer, a file that no longer matches WordPress.org’s official copy. Wordfence checks the code; Touchstone checks who is behind it. Run them side by side.
Manually: open the plugin’s WordPress.org page, read the listed author and contributors, then open its SVN development log and compare the committer usernames against what you saw last time. That works for one plugin, once. Touchstone does it for every plugin on your site, every day, and tells you only when something changed.
No. Ownership scans and the code check run in the background in small batches, never during a front-end page load, and the plugin produces no public-facing output at all.
Plugin slugs, plus each plugin’s version for its official checksums, to WordPress.org only: api.wordpress.org, plugins.svn.wordpress.org and downloads.wordpress.org. No file contents ever leave your site. No telemetry, no analytics, no licence check. It is listed in the readme under External Services.
The free plugin gives you the moment and the switch: it warns within the hour and offers one click to stop WordPress auto-updating a plugin that changed hands. Touchstone Pro goes further and holds the update until someone approves that exact version. Pro is built and coming soon.
Most are, yes. So you acknowledge it once and it deducts nothing from the score ever again, or you mute the plugin entirely. Staying quiet until something genuinely changes is the whole design — an alert you learn to ignore is worse than no alert.
Their ownership cannot be monitored, because they have no public commit history: they are listed as unknown origin rather than given a grade they have not earned. Their code is still checked, against the first copy Touchstone saw, so a changed or added file is still named.
Thirty client sites is several hundred plugin installs, and no record anywhere of which of them changed owner or had their code touched. Touchstone builds that record, and in our replay it would have warned 139 days early. It is finished and in review at WordPress.org.
Free and GPLv2. Requires WordPress 6.2 and PHP 7.4 or newer.
Until then, read the replay or check one plugin by hand. One view across every client site is the Agency tier, coming after Pro.