Welcome to the official blog for the Plugins Team.
The team acts as gate-keepers and fresh eyes on newly submitted plugins, as well as reviewing any reported security or guideline violations.
Quick Links
The team acts as gate-keepers and fresh eyes on newly submitted plugins, as well as reviewing any reported security or guideline violations.
Quick Links
tl;dr: Donโt make reviews for your own pluginPlugin A plugin is a piece of software containing a group of functions that can be added to a WordPress website. They can extend functionality or add new features to your WordPress websites. WordPress plugins are written in the PHP programming language and integrate seamlessly with WordPress. These can be free in the WordPress.org Plugin Directory https://wordpress.org/plugins/ or can be cost-based plugin from a third-party.(s) using other peopleโs accounts. We will remove them and warn you first, and if it keeps happening, your plugin will be closed.
There have been a lot of reviews being removed for being invalid in ways beyond a โnormalโ sockpuppetSockpuppet A false online identity, typically created by a person or group in order to promote their own opinions or views. Generally used to promote or down-vote plugins en masse..
We know this is messy and scary because any time we say โDo bad things, and your plugin(s) will be closed!โ is a terrifying prospect. We really do know that. We really donโt want to do it, which is why we warn people instead of just closing everyone who makes mistakes. Our goal is, and has always been, to make a place where users can download functional, safe, plugins that solve the problems faced by users.
At the same time, we know that developers want people to use their plugins, and one of the ways that happens is by being popular. And yes, one of the ways to become โpopularโ is to get a lot of good reviews. Which is how we get here. Sometimes people leave reviews for their own plugins. Actually, a lot of the time.
Weโre not talking about an individual developer using their developer account to leave a review on their own plugin. While thatโs weird and pretty pointless in the long run, itโs not currently prohibited and we leave those alone unless youโve been flagged for fake reviews in general. Instead we recommend you not review your own plugins since it doesnโt help you out. People generally assume you like your own plugin, so your users wonโt learn anything from the review, and since you left it yourself, you wonโt learn anything either, making it a net-loss.
The kinds of reviews weโre talking about is when someone (or a group of someones) makes multiple accounts with which to leave reviews about plugins. And this is a global issue. Fake reviews are a huge problem not just on WordPress.orgWordPress.org The community site where WordPress code is created and shared by the users. This is where you can download the source code for WordPress core, plugins and themes as well as the central location for community conversations and organization. https://wordpress.org/. Amazon in particular is filled with fake reviews, and theyโre getting harder and harder to spot. Itโs an ongoing battle to spot them before they get โtoo bad.โ We arenโt perfect, and thatโs why the first time we see someone leaving fake reviews, we warn them. What happens after that is usually pretty telling.
One big thing to keep in mind, reviews are for two purposes:
Both of those things, when theyโre positive, can help your plugin become more popular. And of course, if theyโre negative, it can hurt you. Which is why people work so hard to earn and merit positive reviews.
A fake review is a review made by someone who is not your actual user.
Sounds simple, right? If you write a review for someone else about your own product and hide who you are, thatโs fake. The most common reason this happens is that an intern or a marketer gets the bright idea to share customer stories on the WordPress.org review system. The problem? Theyโre posting for the customer, which is making a fake review.
Another common way to make fake reviews is to use sockpuppets.
A sock puppet or sockpuppet is an online identity used for purposes of deception. The term references the manipulation of a simple hand puppet made from a sock, and was originally referred to a false identity assumed by someone to hide who they are and talk up themselves.
For example, if you make a second account and post a question about your plugin and then reply as your normal account? Youโve made a sockpuppet.
Sockpuppet accounts are very commonly used to leave positive reviews on plugins.
An invalid review is one that was made under duress or other promotional encouragement, or one that was made on behalf of a real person.
For example, if you offer a discount for your products if a user leaves a review, then youโve actually just bribed them for a review, which makes it an invalid review. When people are compensated for a review, they generally leave better ones than they might if you just asked. Related to this, if you tell someone you wonโt refund their money unless they leave a positive review, youโve blackmailed them, and that too is invalid.
As another example, if someone leaves a great review for you via email or on your website, and you help them make a user account on WordPress.org (or make it for them) just to leave that review, you have invalidate their review. We have no way to be sure you didnโt alter the review, and your involvement could have altered the review content simply by being there.
Another kind of invalid review would be one made by someone with a personal, or professional, relationship to you. In other words, if you ask your parents or co-workers or people who share a co-working-location to leave a review, youโve inadvertently asked them to make invalid reviews. This is a little touchy, since sometimes they are your users. The issue here is that people who know you are more include to leave favorable reviews, but also they can tell you to your face (virtual or otherwise) how they feel. You donโt actually need their review, and they can be more honest by talking to you via your existing connections.
A counter to this is sometimes your friends do legitimately use your plugin and see the note โPlease review!โ in wp-admin and leave you a review. Those are totally fine and rarely raise red flags.
More or less the same way people know when a term paper is plagiarized.
There are significant tells in most reviews that give away the actual author. We also take into account things like the age of the user (that is, how long ago did they create their account), what their other actions were, where they logged in from, what their digital footprint is, what their email is, etc etc. Then we compare that to all the other reviews made for that plugin and for other plugins and themes around the same time.
Or, as we tell people, we have a complex set of heuristics, as well as researchers who are experts with tracking down users.
Two reasons which sum up as privacy and security.
First, the more we let on about exactly how we do this, the more people will learn about how to get around them. Itโs like spam. The more spammers know about how theyโre caught, the more they work to get around those limits.
Second, and this is more important, some of that information is private. Telling people exactly who did the bad thing, how we know, and sharing IPs and emails, is a privacy violation. It would run afoul of GDPR related laws, which by the way is also the case in some states in the US (like California).
Because it wasnโt.
The majority of reviews reported as โfakeโ come from developers reporting a brand new user whose only post in the forums is a negative review on their product.
This does not mean the account is fake. It doesnโt even mean the review is invalid. It means someone was angry enough to make an account and leave a review. Thatโs a pretty painful thing to get, I know, but just because someone doesnโt like your work doesnโt mean they or their comment is invalid.
We use our tools to check on the account and will remove anything that we can prove is fake, but a lot of the time itโs really just angry users.
No, we donโt track VPN usage, but we do take its use into consideration.
Thereโs nothing wrong with using a VPN. Iโm writing this post on one. Whatโs wrong is people using VPNs to get around things like bans or to hide their accounts. Thatโs why flagging the use of a VPN (and which specific VPN it is) is a part of our process, but itโs not the ultimate be-all and end-all of things.
Keep in mind, there are certain VPNs utilized heavily by malicious actors. Some specifically exist to be used to generate fake reviews. If your company is using a VPN, make sure itโs a legit one (not one of those free, fly by night, ones).
First of all, youโll get a warning. In general this is how everyone finds out about being flagged. We will make a note in your plugin as well as on the accounts used.
In that warning email, you will be told why you got flagged, that we saw the reviews and theyโve been removed, and that all suspect accounts have been suspended. We have read-receipts on our emails, so we know if/when someone read it. That means the situation persists, and no one read the email, we will close your plugins to force you to pay attention. If it keeps happening after that, you will find your plugins and account closed.
The email also explains that all we want is for the fake reviews to stop. Mistakes happen, please donโt do it again.
That means either you noticed before you got the email or (more common) we figured out someone else was trying to frame you. We usually donโt tell you so as not to scare you. Removing invalid reviews is a regular occurrence for every single review-platform, and if we told you every time we removed a spam or fake review, youโd get real tired of it real fast.
In most cases, you wonโt.
We know that the reviews appear valid to you, but we can see things you cannot. Just for an example, a real user of yours wouldnโt use a VPN from Russia and a disposable email address to leave that glowing review which is identical to another review also left from Canada and a different VPN at the same time. Also some users think itโs a great idea to make fake accounts to promote you. We have no idea why they think that, but we will remove those and the user will be banned, so all their reviews become invalid.
Thereโs also a common trend where companies make reviews for people. They get a good testimonial and make a review using that. Sounds smart, but itโs still spamming.
As horrible as this soundsโฆ Are you sure? Double check. Do you work with anyone else? Do you share a co-working place with others? Do you and your company all use the same VPN? Did you ask a bunch of people at an in-person event to leave a review? Did your spouse tell you how cool your plugin was and leave a review? All those things can set up warning flags because they mimic suspicious actions.
If any of those sound familiar, fess up. Just tell us โHey, Iโm sorry, I asked my coworkers/spouse/family to leave reviews. I didnโt realize how that looks.โ
If youโre still certain you didnโt do it, just tell us. โI donโt work with anyone else, and I know I didnโt do this.โ Weโll check again. Itโs possible that someoneโs trying to attack you, and while we make every effort to be as certain as we can be that itโs not that, weโre not perfect any more than you.
We are very well aware how painful and scary the email is, and weโve worked on the language to try and make sure itโs less so.
Apologize and donโt do it again. Seriously, thatโs it. Mistakes happen, and itโs okay if you make one. Just donโt repeat it. We absolutely, totally, forgive honest mistakes.
We do remind you to make sure everyone who works with you on the plugin knows this. You are responsible for the actions your employees/coworkers/etc take on your behalf. If they spam, you are on the hook for their actions. Usually we see repeat infractions come from that.
In most cases, yes. However you will be asked to formally take responsibility for all of that personโs actions on WordPress.org for as long as they represent your company. That means everything they do is your responsibility and if they violate any guidelines, you will be on the hook for that infraction.
In some cases, the person is permanently banned and that generally means itโs related to previous guideline issues. If that is the case, we will explain that, under no circumstances, are you to help this person regain access. We recognize that sometimes employees or staff go rogue, and we are attempting to insulate your from their behavior.
Glad you asked! Besides the obvious (donโt hire people to boost your review rating), you should be aware of the following:
You can (and should) ask your users! Put a notice on your plugin settings page. Make a dismissable alert that asks people to review. Post on Twitter or your website. But really? Itโs down to asking your users in a kind, and non spammy, way. Those people will leave the reviews you need.
I understand why people get confused about this one. Asking people for reviews is fine, but then to say asking people you know isnโt? Yeah that sounds weird. But the crux is to think about what a review is for in the first place.
A review is someoneโs experience with your plugin. For good or ill, itโs them using the plugin and sharing their story.
If youโre asking people to leave reviews to learn about what they do and donโt like about your plugin, then thereโs no point to asking folks you know since you can just โฆ ask them. In turn, they can just tell you to your face how they feel. Also theyโre generally more inclined to leave good reviews, though I will admit weโve seen someone leave a 1-star review for their spouse.
Interestingly, that review was invalid, as the review was a personal attack on the developer.
Have a shout.
X-comment from +make.wordpress.org/updates: Comment on Announcement: Incident Response Training
At least once a day, someone has to explain that the only esc_ function you can use to sanitize is esc_url_raw(). This stems from what was (at the time) a logical change. The function sanitize_url() was an alias for esc_url_raw() and itโs redundant to have both.
Except โฆ
Over the years, WordPress has evolved and improved function names to the point that we can nearly say โUse sanitize_ functions to sanitize and esc_ functions to escapeโ which makes life a lot easier for new users. They donโt have to remember any odd-functions-out except the wp_kses* ones.
For WordPress 5.9, I made a ticket to restore sanitize_url() and Iโm delighted to be able to say that itโs back! Itโs un-deprecated!
Nothing, except the name.
Yes, for now. Eventually weโd like to wean people off it, but itโs a process. No worries. If youโre using it, we wonโt ding you.
Because now you (and anyone else) can look at $variable = sanitize_url( $_POST['variable_url'] ); and know โAh, yes, this is sanitized.โ
No. Iโm posting this because I promised some of the people I made that ticket for that I would ๐ Itโs delayed because Iโve been swamped.
Itโs something that changes very little for most people, but will greatly help newer developers and minimize their confusion. And that? That is a fantastic thing!
Tell the people who run the sniffer, but keep in mind theyโre probably adding in a bunch of changes, so it may take a while ๐ Be cognizant of the work they do and respectful of the time they give you. Helps everyone.
If your pluginPlugin A plugin is a piece of software containing a group of functions that can be added to a WordPress website. They can extend functionality or add new features to your WordPress websites. WordPress plugins are written in the PHP programming language and integrate seamlessly with WordPress. These can be free in the WordPress.org Plugin Directory https://wordpress.org/plugins/ or can be cost-based plugin from a third-party. is a FEATURED or BETABeta A pre-release of software that is given out to a large group of users to trial under real conditions. Beta versions have gone through alpha testing in-house and are generally fairly close in look, feel and function to the final product; however, design changes often occur as part of the process. plugin, which means officially recognized as such by the WordPress project, you will no longer be able to add or remove committers, nor will you be able to change ownership.
This change was made due to the high profile nature of those plugins, and the potential for abuse if a plugin is given to someone who turns out to be malicious. We hope that it will prevent issues like a featured plugin being turned into a premium-upsell plugin.
This does not relate to the size of a plugin. If a 2-user plugin is made a Featured Plugin, then it will be have this limitation. That said, it also will not cause any change to proposed feature plugins or self-declared beta.
If you are an owner/committer to one of those plugins, you can add support reps as needed, but you will need to email the plugins team (`plugins@wordpress.orgWordPress.org The community site where WordPress code is created and shared by the users. This is where you can download the source code for WordPress core, plugins and themes as well as the central location for community conversations and organization. https://wordpress.org/`) to have new committers added/removed, and to change ownership if needed.
Around 17:30 UTC on March 23, 2022, I was notified of a pluginPlugin A plugin is a piece of software containing a group of functions that can be added to a WordPress website. They can extend functionality or add new features to your WordPress websites. WordPress plugins are written in the PHP programming language and integrate seamlessly with WordPress. These can be free in the WordPress.org Plugin Directory https://wordpress.org/plugins/ or can be cost-based plugin from a third-party. in the WordPress ecosystem that contributors flagged as potentially violating the plugin directory guidelines. The initial conversation can be found in Slack. Following my review as the Executive Director, the plugin was removed from the directory about an hour later. This post is to provide information about what happened and anticipated next steps.
tl;dr: The Zamir plugin used a loophole in the plugin guidelines created to protect members of the WordPress community. There are no present guidelines that bar the โsupportโ of political leaning or cause, which is what this pluginโs description claimed it was doing. Since Z is emerging as a new symbol of hate and violence, it was considered a grey area in initial checks and on further review was removed.
Does this plugin violate WordPress guidelines?
Yes! Many community members shared how the Z symbol has come to stand as a symbol in support of Russiaโs ongoing war in Ukraine. As a reminder, WordPress guidelines call upon all community membersโincluding extenders like plugin authorsโ to โbe kind, helpful, and respectful.โ A symbol that is connected to an ongoing war and humanitarian crisis is none of those things.ย ย
What actions were taken?
With the help of WordPress contributors and community members, the plugin has since been removed from the plugin directory. While decisions to remove plugins are normally adjudicated in a slower, more collaborative investigation processโquick and decisive action was appropriate to prevent further harm to the community.
Thank you to @santanainniss for pulling together the timeline of the morning and to @ipstenu for working to resolve the issue. Additional thanks to @cbringmann @helen @angelasjin and @eidolonnight for their review. And thank you to our community of contributors for voicing their concerns.
tl;dr: Never test vulnerabilities on someone elseโs live site without their permission.
By now, a lot of you have read the post about the so-called โWordPress Plugin Confusionโ whereby a pluginPlugin A plugin is a piece of software containing a group of functions that can be added to a WordPress website. They can extend functionality or add new features to your WordPress websites. WordPress plugins are written in the PHP programming language and integrate seamlessly with WordPress. These can be free in the WordPress.org Plugin Directory https://wordpress.org/plugins/ or can be cost-based plugin from a third-party. hosted on WordPress.orgWordPress.org The community site where WordPress code is created and shared by the users. This is where you can download the source code for WordPress core, plugins and themes as well as the central location for community conversations and organization. https://wordpress.org/ can โoverrideโ a plugin not hosted here, by using the same name/permalink. Someone even made a CVE for it.
Please stop โtestingโ this vulnerability with us.
This is not a new issue by any means. Heck, this has been something people report on now and then for years. In the past, the plugin team coordinated a release of a plugin to intentionally do that and protect users from a significantly dangerous plugin. Weโve locked out permalinks to prevent abuse and so on.
Sadly, the post conflated a couple of issues, which have to do with social engineering and a misunderstanding of why we have those permalink-checks for trademarks. Also itโs entirely incorrect with this one claim:
and the whole approval process is automated
This could not be further from the truth. All new plugins submitted go through human review. When you submit a plugin, somebody reads your plugin code, your submitted slug and name, checks on the history of the plugin, checks that the developer isnโt a returned banned user, etc. The process is by no means โautomatedโ and while it has some automated pre-flight checks, theyโre really there to weed out things that would end with a pended review, to make the process faster for everyone. While we have some tools we run, they donโt actually approve or reject anything, theyโre just fancy code-sniffers, customized to look for specific patterns or known bad behavior, outside of the overall quality like PHPCSPHP Code Sniffer PHP Code Sniffer, a popular tool for analyzing code quality. The WordPress Coding Standards rely on PHPCS. (you are using that, right?). Submitting things to test out what you think is an โautomatedโ system is wasting the time of our volunteers and reviewers.
See, that trademark โblockBlock Block is the abstract term used to describe units of markup that, composed together, form the content or layout of a webpage using the WordPress editor. The idea combines concepts of what in the past may have achieved with shortcodes, custom HTML, and embed discovery into a single consistent API and user experience.โ isnโt actually there to protect trademarks for the owners. We have them to make our life easier and to protect you, the developers, from making some pretty common mistakes. Just for an example, we block โakismetโ not because we were asked to by Automattic, but because over 50 people a year tried to submit a copy of Akismet instead of uploading it to their own site.
As the post (properly) notes, you canโt submit a plugin with a permalink thatโs already in use, be it on WordPress.org or if it has a notable user-base outside of WordPress.org. Even if a name gets by those checks, the review team can see if the permalink is being used and by (roughly) how many people. Thatโs a large part of why we have humans checking these things. A human can look at an email and a plugin and check for proper ownership.
By the way, as a number of people have complained about, this is why we require official plugins to be owned by demonstrably official accounts (like with an email address that uses the right domain, and so on). Itโs not just to prevent trademark abuse, itโs to ensure that kind of thing is less likely to happen.
Now. Do you need to test this? No. All youโre doing is making things more stressful and more likely to be missed, which doesnโt solve a problem. Do you need to add your trademark to the blocked list? Again, no. Unless itโs being actively abused, or thereโs a high-risk situation that it might be, itโs just adding more work for a low (to negligible) risk in the first place.
How DO you protect your own, non-org hosted plugins, from this?
Use the UPDATE URI flag.
We check for it on .org, and wonโt allow you in with it (sinceโฆ why?) but for plugins we donโt host, well thatโs literally why it exists ๐ Use it. Love it. But please, remember the first step in ethical hacking is never trying out a vulnerability on someone elseโs site without their permission.
Hi Devs!
Weโre getting nearer to WordPress 5.9, and that means the email will be headed out soon.
This is the perfect time to double check the email on your accounts, especially if itโs a group email/mailing list. Make sure external emails (like โฆ us) can contact you without bounces or autoreplies.
You also should check everyone who has commit access to your pluginPlugin A plugin is a piece of software containing a group of functions that can be added to a WordPress website. They can extend functionality or add new features to your WordPress websites. WordPress plugins are written in the PHP programming language and integrate seamlessly with WordPress. These can be free in the WordPress.org Plugin Directory https://wordpress.org/plugins/ or can be cost-based plugin from a third-party.! Did someone leave? Itโs okay to remove their access, and in fact is great to do so for security ๐
And as a regular reminder: Never share accounts! Every individual human should have their own individual account. That lets you (and us) keep tabs on who did what.
tl;dr Starting in October, you will have THREE (3) months to complete your review before we reject it.
This will not affect most of you who actively read this site.
For a very long time, weโve allowed plugins 6 months to finish a pluginPlugin A plugin is a piece of software containing a group of functions that can be added to a WordPress website. They can extend functionality or add new features to your WordPress websites. WordPress plugins are written in the PHP programming language and integrate seamlessly with WordPress. These can be free in the WordPress.org Plugin Directory https://wordpress.org/plugins/ or can be cost-based plugin from a third-party. review. Thatโs more than enough time for any reasonably attentive developer to make changes (especially considering the majority are โplease sanitize/escapeโ).
In January 2021, we had 596 โpendingโ reviews, which meant there just under 600 plugins that had been reviewed and we were waiting on a reply/completion. Weโre seeing over 800 in September.
That rise is out of step with the number of plugin submissions. In fact, if you look at our posts to Make/Updates, you can see weโre pretty stable around 140 plugins submitted a week, but the โpending; replied toโ value is inching up.
Since the majority of those plugins that donโt reply or finish in 3 months arenโt going to any time soon, weโre changing our policy to try and be more sustainable and less work. From now on, you have THREE months to finish a review before we reject it.
Thereโs no change to existing submissions. Which means the โReject all reviews pending completionโ logic works like this:
Yes, itโs a little messier for us, but itโs the most fair we can be to existing reviewers. It would not be kind to pull the rug out from under them.
Just keep replying to the review! Weโll work through it with you and tell you to resubmit when the review is good. That also lets us fast track you since youโve worked so hard!
You could, but weโd pend your review and ask you why you never finished the previous one, which means your whole review will take longer, and weโll make a note on your account about not following directions.
We get it. Mistakes happen. Weโve all deleted the important email! Email us at plugins@wordpress.org from the account/address that submitted the plugin and we will re-send it for you.
There are two cases where this could happen:
In both cases, reply to the rejection email and ask.
Not yet, no, but Iโd like it to be eventually.
UYes, this means every month end, someone goes through and selects all submissions from a time period and changes the status en bulk.
Human error. Or internet greebles. Probably the first. We do our best, but sometimes a mouse didnโt click when we thought it did, or a human got distracted, and mistakes happen. Those are generally our mistakes, and we are sorry when that happens.
Please email us back and tell us. Weโll get you fast tracked and sorted.
Have a shout in the comments.
#reviews, #timelineX-comment from +make.wordpress.org/docs: Comment on [Announcement] New workflow for reporting documentation issues