Somebody Bought Your Plugin and You Weren't Told

In early 2025 a portfolio of around thirty WordPress plugins was sold on a marketplace to a buyer known publicly only as Kris. The plugins carried on working exactly as before. Nobody running them heard anything about it.

Eight months later, they woke up.

What happened

The buyer added code after the acquisition and left it dormant. Not doing anything, not calling home, nothing that would show up if you went looking. It sat there through the best part of a year of ordinary updates.

In early April 2026 it activated, through a shared analytics component the plugins had in common. Once awake it wrote itself into wp-config.php, which is the file that holds your site's core settings and database credentials, and opened a channel to a machine the attacker controlled. From there they could run whatever they liked on the site, hand themselves administrator access, and inject spam into the pages to game search results.

WordPress permanently closed thirty-one plugins on 16 April 2026 and force-pushed updates within hours, which is about as fast as that machinery moves.

Reported reach varies between sources. Some put it at around 400,000 installs and roughly 20,000 active sites, others higher. Take the lower figure and it is still a lot of businesses who had no idea they had acquired a new supplier.

Why this is the story that matters

Most security advice treats a plugin as a feature you install. It is more useful to think of it as a supplier relationship, and one with unusual terms.

You never signed anything. There is no contract, no notice period, and no obligation on the supplier to tell you when the business changes hands. The relationship transfers silently and keeps running with full privileges on your website.

If a supplier who held keys to your office was sold to somebody you had never heard of, you would expect a phone call. With software you get an update notification that looks identical to every other update notification.

The sibling case

In July 2025 the official download for Gravity Forms, a forms plugin running on something like a million sites, was backdoored for roughly two days.

The detail to keep is who got hit. Anyone who downloaded the file by hand during those two days got the tampered version. Anyone whose site updated itself automatically did not.

That cuts against the instinct that careful, hands-on people are safer. Sometimes the automated path is the safer one, because it is the path everybody is watching.

What an owner can reasonably do

Know what is installed. This keeps coming up because it keeps being the answer, and it is the same list we build first on any site we inherit. You cannot assess a supplier you cannot name.

Know who maintains each one now, not who wrote it originally. The WordPress directory shows the current author and the last update date. A plugin whose ownership has changed is not automatically a problem, but it deserves a look.

Treat "last updated three years ago" as a warning rather than a sign of stability. Stable software still needs someone minding it.

And prefer components with a named team and a visible business behind them. Not a guarantee, but a company with a reputation to lose behaves differently to an anonymous buyer on a marketplace.

Then keep the number low (How to Judge Software Before You Hand It Your Data is the longer version of this), because every one of these is a relationship, and you would not sign thirty supplier contracts for a website if anybody made you read them.

We can tell you what is installed on your site and who maintains it now, which is usually a more interesting list than people expect. Get in touch if you would like to see yours.

One email a month...

Most months we publish a handful of articles about running a website: what things cost, where the money goes, what's changing in search and which bits of AI are worth a small business's time. Once a month we gather them into a single email. It waits in your inbox until you have ten minutes spare, whether that's the same day or the end of the month.

← All articles