Know who controls your WordPress plugins

And whether anyone changed their code. Touchstone tells you when a plugin on your site changes hands, checks every code file against WordPress.org’s official copy, and stops code being changed from the admin. Replayed against the 31 plugins backdoored in 2026, it warns on every one, a median of 139 days before the backdoor switched on.

  • Free and GPLv2
  • No telemetry, no licence check
  • Runs entirely on your own site
The Touchstone overview screen inside WordPress admin: a Your site at a glance report, a status panel reading nothing needs your attention, a donut chart of every installed plugin, and a table of plugins with trust scores, statuses and findings
8
Detection rules, all free
0
Telemetry or analytics calls
31/31
Backdoored plugins it warns on, replayed
1 day
From install to your first finding

Nobody reviews a change of ownership

A change of ownership is the quietest supply-chain attack on WordPress, because nothing about the code looks wrong yet.

When a plugin is sold, WordPress.org performs no audit and sends no notification. The new owner inherits commit access, and their first release reaches every site running it through the ordinary update channel.

This is a documented gap, not an inference. WordPress meta ticket #5509, Notify users of changes to plugin ownership, was opened to add exactly that notification. It is still open and unresolved.

In April 2026 the WordPress Plugins Team closed 31 plugins at once. A single buyer had acquired the portfolio through Flippa, planted a backdoor across all of them, and waited. Most of those sites were running a vulnerability scanner the entire time, and a scanner has nothing useful to say about a plugin whose code has not turned malicious yet.

We replayed Touchstone against their public history. It warns on all 31, naming the account that shipped the backdoor, a median of 139 days before it switched on. See the replay, method and limits included.

Both 2026 incidents, dated and sourced — including the one this plugin would not have caught.

60 seconds, silent and captioned: how Touchstone would have warned, and what you can do.

A transfer is not an attack. It is the window in which one becomes possible — and the only moment at which you still get to choose.

31
Plugins closed by the WordPress Plugins Team on 7 April 2026
8
Months the backdoor sat dormant after being planted in August 2025
139
Days early, the median warning in our replay of all 31
0
Notifications WordPress.org sends when a plugin changes hands

A provenance record for every plugin you run

Three steps, every day, from public sources and your own files.

1

Baseline

On the first scan it inventories every installed plugin and reads back up to 200 commits of SVN history, recording each committer with their first and last revision.

Recorded plugin-slug · committer-a r1–r2981 · committer-b r302–r2104

The committer history panel on a plugin detail screen, listing each committer with the first and last SVN revision they touched
2

Compare

Every day it re-reads the public record and diffs it against what it stored, and checks every code file against WordPress.org’s official fingerprints. A new name, or a file that no longer matches, is the signal; eight rules decide what kind.

Changed author replaced · +1 unseen committer at r2982

3

Decide

The trust score moves, the plugin rises to the top, and anything serious reaches your inbox within the hour. You acknowledge it, mute the plugin, or turn off its auto-updates in one click.

Scored trust 94 → 61 · band ok → watch

Everything runs in the background, a little at a time, never during a front-end request. Your visitors never touch this code.

Eight detection rules: ownership, code and access

Five watch who controls each plugin. Three watch the code itself and who can change it. Control usually changes months before the code does, so you hear about both.

R1 Risk

Ownership change

The listed author or contributor list no longer matches the stored snapshot. A dropped original author means the handover is already complete.

R2 Risk

New committer

A previously unseen SVN username has committed for the first time. This is the event that precedes a payload, usually by weeks or months.

R3 Watch

Dormant then active

180 days of silence followed by a commit. Escalates when it lands alongside an ownership change or a new committer.

R4 Watch

Abandoned or withdrawn

No update in 365 days, escalating past 730. Closed or removed from the directory is a high-risk finding with the date and reason, even if it was closed before you installed Touchstone.

R5 Watch

Unknown origin

The plugin is not in the directory, so it has no public history and cannot be monitored. It is listed as a blind spot rather than given a grade it has not earned.

R6 Risk

Code changed

A file in WordPress core or a plugin no longer matches WordPress.org’s official fingerprint, or the first copy Touchstone saw. Named by file, and emailed within the hour. Put it back and the finding says so.

R7 Risk

Unexpected code

A code file that should not be there: added to a plugin, dropped into wp-content, or any PHP file in uploads, where a backdoor usually hides.

R8 Risk

Access change

A new administrator, a role raised to administrator, a changed admin email or a new application password. The quiet ways someone keeps a way back in.

One number a client can understand

Every plugin carries a deterministic score from 0 to 100. Same inputs, same score, with nothing you cannot explain to the person paying the invoice.

Time-decaying
A deduction applies in full for 90 days, at half weight to 180, then expires.
Acknowledgement-aware
An event you have reviewed and accepted deducts nothing.
Mute-aware
A muted plugin is still scored, just kept out of the default view and out of your inbox.

0/100

Band boundaries are fixed and published.

  • Risk 0–49
  • Watch 50–79
  • OK 80–100

Plugin security inside the admin you already use

No new dashboard to log into, and nothing for your client to learn.

  • Inventory sorted by risk, so the plugin that needs you is first
  • The full committer timeline for every directory plugin
  • Acknowledge or mute in one click, per event or per plugin
  • Code lock and a code check: every part of the site, genuine or named by file
Touchstone overview screen: a status panel, a fleet donut chart, and a sortable table of installed plugins with trust scores, statuses and findings
Every plugin, sorted so the riskiest is first.
Plugin detail screen: the trust score as a ring, a panel of plugin facts, its findings, and the full committer history with first and last revision for each person
One plugin: its score, its committers, and what changed.
The Code screen: Code lock allowing code changes only over FTP, the plugins that could get around it, who can change the site, and every part of the site checked against WordPress.org
Code lock, and every part of the site checked.
Events log: filter chips across event types, and rows showing when each finding was detected, which plugin it belongs to, the event type, and the detail behind it
Every finding, newest first, including a file put back.

Everything it reads is public. Your files never leave your site.

There are no certifications on this page because there are none to show. Here is the whole mechanism instead.

The only places it contacts, all WordPress.org

api.wordpress.org/plugins/info/1.2/
Listed author, contributor list, last update date.
plugins.svn.wordpress.org/
Public commit history — who committed, and when.
downloads.wordpress.org/plugin-checksums/
The official fingerprint of every file, for the code check (core’s come from api.wordpress.org).

A plugin slug and its version are all that is sent. Your files are compared on your own server; no file contents ever leave it.

What it refuses to do

  • Change an update by itself — you decide, in one click
  • Guess at malware — it checks your code is genuine instead
  • Check for known vulnerabilities — keep your scanner
  • Send telemetry, analytics or a licence check

The one it would have missed

In June 2026 ShapedPlugin’s build pipeline was compromised and a malicious build shipped under the existing maintainer’s name (CVE-2026-10735). No author changed. No new committer appeared. Touchstone’s ownership rules would have shown nothing, and because the poisoned build was the official release, its code check would have matched too.

It detects a change in who holds control. It cannot detect an existing owner’s pipeline being turned against them. That is what your malware scanner is for, and it is why this runs alongside one rather than instead of it.

GPLv2, and the plugin ships as plain PHP with no build step: every outbound call is readable in src/Api/ and src/Integrity/. The free build contains no licensing code at all.

Detection is free, and stays free

Every rule, the code check, Code lock and every screen, on every site, with nothing held back to sell you later. Pro is for acting on what it finds.

Free

Submitted for review

$0forever

  • All eight detection rules, and a trust score for every plugin
  • Daily code check against WordPress.org’s official fingerprints
  • Code lock: code changes only over FTP, loosened only by a site owner
  • Access watch: new administrators, admin email, application passwords
  • Urgent email within the hour, and a weekly all-clear
  • One click to turn off auto-updates for a plugin that changed hands
Coming soon

Pro

Built, coming soon

$59/yr, 5 sites

  • Update quarantine — a risky update waits for you to approve that exact version, and you get an email showing what it changes
  • The changed lines, and the genuine file put back in one click
  • Developer access that ends by itself and stays in its areas; a change anywhere else suspends it
  • Policy gates, release diff, trust timeline, check before you install
Tell me when it ships

Agency

In development

$179/yr, 25 sites

  • Everything in Pro, on 25 sites
  • Every client site on one screen
  • Approve an update once, for every site
  • Client reports with your own logo
Tell me when it ships

Pro is built and goes on sale soon; Agency follows. Neither is purchasable yet, and neither will ever live inside the free plugin — WordPress.org forbids paywalls in a hosted plugin, which is why the free build carries no licence code at all. Moving from Pro to Agency is a licence change, never a reinstall.

Questions worth asking first

Replayed against the public history of all 31 plugins closed in April 2026, it raises a high-severity new-committer warning on every one, naming the account that shipped the backdoor, a median of 139 days before the backdoor switched on. The backdoor itself was inside the official releases, so a file check alone would not have caught it; the change of hands is the signal. The replay, method and limits included.

They look for code that is already known to be bad. Touchstone watches who is behind your code and whether it is still genuine: an ownership transfer, a new committer, a file that no longer matches WordPress.org’s official copy. Wordfence checks the code; Touchstone checks who is behind it. Run them side by side.

Manually: open the plugin’s WordPress.org page, read the listed author and contributors, then open its SVN development log and compare the committer usernames against what you saw last time. That works for one plugin, once. Touchstone does it for every plugin on your site, every day, and tells you only when something changed.

No. Ownership scans and the code check run in the background in small batches, never during a front-end page load, and the plugin produces no public-facing output at all.

Plugin slugs, plus each plugin’s version for its official checksums, to WordPress.org only: api.wordpress.org, plugins.svn.wordpress.org and downloads.wordpress.org. No file contents ever leave your site. No telemetry, no analytics, no licence check. It is listed in the readme under External Services.

The free plugin gives you the moment and the switch: it warns within the hour and offers one click to stop WordPress auto-updating a plugin that changed hands. Touchstone Pro goes further and holds the update until someone approves that exact version. Pro is built and coming soon.

Most are, yes. So you acknowledge it once and it deducts nothing from the score ever again, or you mute the plugin entirely. Staying quiet until something genuinely changes is the whole design — an alert you learn to ignore is worse than no alert.

Their ownership cannot be monitored, because they have no public commit history: they are listed as unknown origin rather than given a grade they have not earned. Their code is still checked, against the first copy Touchstone saw, so a changed or added file is still named.

How many of your plugins changed hands this year?

Thirty client sites is several hundred plugin installs, and no record anywhere of which of them changed owner or had their code touched. Touchstone builds that record, and in our replay it would have warned 139 days early. It is finished and in review at WordPress.org.

One email, when it ships. No newsletter, no list sold, no tracking.

Free and GPLv2. Requires WordPress 6.2 and PHP 7.4 or newer.
Until then, read the replay or check one plugin by hand. One view across every client site is the Agency tier, coming after Pro.