WordPress.org Rolls Out AI-Assisted Reviews, Bringing 24-Hour Cooldown to Plugin and Theme Auto-Updates

  • News

WordPress co-founder Matt Mullenweg has announced a new security initiative called Protect The Shire, aimed at strengthening the security of all 78,000 plugins and themes on WordPress.org. The initiative introduces a temporary 24-hour delay before plugin and theme releases are distributed through auto-updates, allowing additional time for review, with an AI Wapuu named Gandalf also introduced to assist in the process.

24-Hour delay added to plugin and theme auto-updates

Mullenweg said WordPress’s plugin and theme ecosystem has traditionally operated on a fast-release model, where updates are distributed as soon as developers publish them.

Under the new Protect The Shire initiative, that approach is being adjusted with the introduction of a 24-hour delay before plugin and theme updates are pushed through auto-updates. The change is intended to create a short review window before new releases reach users at scale. As part of this process, Mullenweg also introduced an AI Wapuu named Gandalf to assist in reviewing changes during the delay period.

Explaining the shift, Mullenweg said, “For now, each new plugin release will wait up to 24 hours before being distributed through auto-updates. This will give everyone, including a new Wapuu we call Gandalf, a chance to review changes.”

He added that the timeline is not fixed and could be shortened as the system develops and improves over time, “I expect 24 hours could be reduced to minutes as the process evolves, but we’ll err on the side of caution while AI models are advancing so rapidly.”

Mullenweg also shared his view on how update practices may evolve, “ We’re in a liminal period now, and I believe 2026 will be a year of tension between two approaches: updating as quickly as possible to stay secure, and holding back on updating to stay secure.”

Mullenweg said concerns over supply-chain attacks have grown across a number of software ecosystems, including npm, PyPI, GitHub, and RubyGems. He also referenced the Essential Plugins incident reported by Austin Ginder (Founder of Anchor Hosting) as an example of how similar risks can affect the WordPress ecosystem. Ginder also reported three other supply chain attacks involving Widget Logic, Quick Page/Post Redirect Plugin, and Scroll To Top plugin.

Previous efforts to improve plugin security

Earlier, another initiative, which was proposed by Matt, was put into effect, known as phased plugin releases. The move that was introduced last year made updates available to a limited number of sites before a broader rollout. This workflow gave plugin developers a chance to identify problems earlier, before they affect the entire user base. This was also highlighted during State of the Word 2025.

The Plugins Team also introduced automatic security scans and reports for plugin updates last year. It was included in the Plugin Check Plugin as a new feature that automatically generates security reports for all plugin updates.

Earlier this year, the Plugins Team opened its call to expand as plugin submissions quadrupled, a growth that is influenced by the usage of AI tools. Mullenweg also highlighted the sheer number of commits to the plugin repository, “ There were over 3,000 commits to the plugin repository yesterday! “

Mullenweg also highlighted that AI could significantly expand the scale and depth of plugin reviews, helping complement the work of human reviewers, “ Our plugin review team seems superhuman, but still needs to sleep. But bots don’t, and a depth of review that seemed unimaginable before is now a matter of time and tokens.”

The initiative will largely remain behind the scenes, with its success defined largely by what does not happen.

Community Response

Adam Preiser on X  voiced, “ Am I the only one thinking this is going to create some problems as well? What if there is an urgent bug fix? Welp, you have to wait 24 hours. What if there is a pro version that needs to be available at the same time? Good luck timing that right. Likely other issues.”

Dipak Gajjar wrote, “ A 24 hour buffer on auto updates feels like a smart move for the WordPress ecosystem. It gives security teams and tooling time to flag bad releases while still letting theme and plugin developers catch critical mistakes before code silently rolls out.”

Maciej Bis said, “If AI is already used to validate the logs in Trac, freezing all auto-updates for 24 hours, seems like overkill…”

The WP Week Newsletter

Curated updates for agencies, developers, and serious WordPress users. Delivered weekly.

Leave your comment

Your email address will not be published. Required fields are marked *