CMS pluginWordPress

Every WordPress plugin update ships new PHP onto a public web server.

WordPress plugins run PHP on a public web server, so a compromised update can add a rogue administrator, drop a webshell, or start injecting SEO spam. Extuno diffs every release and reads the new PHP with static and AI analysis, then runs the plugin in a segmented sandbox to watch what it does at runtime.

In shortTo check a WordPress extension for supply-chain risk, scan the published artifact, not just the source, and compare each new version against the last. Extuno runs static analysis, a dynamic sandbox, and AI review across every WordPress release, then reports evidence on every finding.
WordPress - live inspectionexample
acme-social-share 4.4.7
WordPress plugin
4.4.6->4.4.7
Static
Dynamic
AI
Analyzing update
What Extuno catches in WordPress

Every finding is backed by evidence.

Each finding names the change, why it is dangerous, and the recommended action.

Diff finding

Rogue administrator

The sandbox watches the plugin create a hidden admin account at runtime and mail the credentials out.

Critical
Diff finding

Injected webshell

A file gains an eval() over request data, a remote-controlled shell.

Critical
Diff finding

SEO-spam injection

The plugin starts appending hidden links to the site footer.

Review
See it on a poisoned update

A benign plugin poisoned in a later version

Extuno diffs the update, reads the new PHP, and flags the code that creates a hidden admin.

  • + Vulnerability and secret-leak testing on every version
  • + Static analysis reads the code without running it
  • + Dynamic sandbox runs it live and records behavior
  • + AI code analysis reads the full source and correlates the change against prior versions
How it works
your-site
acme-contact-form 5.9
acme-commerce 8.6
acme-seo-tools 22.0
acme-social-share 4.4.6upgrader_process_complete
acme-social-sharewp-cdn-stats.net

Scan your first WordPress extension free.

5 free credits on signup. One credit per scan, no card required.

FAQ

Common questions

Does Extuno support WordPress?

Yes. Extuno scans WordPress with static analysis, a dynamic sandbox, and AI code analysis, and diffs every version to catch one that was clean but poisoned through an update.

How does Extuno scan WordPress?

Extuno acquires the published WordPress artifact, reads it statically with 1100+ rules, runs it in a network-segmented sandbox, reviews the source with AI, and diffs it against the prior version. The finding names the file, the change, why it is dangerous, and the fix.

What does Extuno catch in WordPress?

Leaked secrets, obfuscated or malicious code, dangerous permissions and APIs, exfiltration and command-and-control behavior, and the headline signal: a version that turns malicious after an update.