EssentialPlugin backdoor, replayed: 31 of 31 warned

Thirty-one plugins, one backdoor, eight months of silence. We replayed Touchstone's rules against what was public at the time, week by week, to see when it would have spoken up.

A chart of thirty-one rows, one per closed plugin. Each row starts with a blue dot on the day Touchstone would have warned and runs to a dark bar on the right, the day the backdoor switched on. Most dots sit months before the bar.

The short answer: yes, on all 31. Every plugin would have raised Touchstone's high-severity “new committer” finding, naming the account that shipped the backdoor, within a week of that account's first commit. The warning would have arrived 41 to 321 days before the backdoor switched on, with a median of 139 days.

60 seconds, silent and captioned: how Touchstone would have warned, and what you can do.

This page shows how we tested that, what Touchstone would and would not have done, and the limits of the claim.

What happened

  • Around May 2025 a buyer acquired a portfolio of more than thirty WordPress plugins on Flippa for a reported six-figure sum, and with it their commit access.
  • The new owner's first release, on 8 August 2025, carried a backdoor. It did nothing for eight months.
  • Around 5 April 2026 it switched on: it rewrote wp-config.php and injected spam pages and redirects across roughly 400,000 declared installs.
  • On 7 April 2026 the WordPress Plugins Team closed all 31 plugins in a single day.

WordPress.org checks that the old owner agreed to a transfer. It does not vet the buyer, review the new owner's first release, or tell anyone running the plugin that it changed hands. That gap is documented and still open.

How we replayed it

  • The data: each plugin's full commit history from plugins.svn.wordpress.org, fetched with the same request Touchstone makes. It is still public after the closure.
  • The site: Touchstone installed on 6 January 2025, scanning once a week. It actually scans daily, so weekly is the cautious case.
  • The rules: two of Touchstone's detection rules, unchanged in their logic: a first commit by an account not seen before (high severity), and a release after 180 or more days without commits (medium).
  • Not replayed: the change of listed author and contributors, because the directory data for closed plugins is gone. Real installs would have had that signal too.

What it found

SignalPluginsWhen
New committer, the account that shipped the backdoor (high)31 of 3118 on 17 November 2025; the rest between May 2025 and February 2026
Released again after a long silence (medium), first10 of 31January to May 2025, around the handover
Earliest warning111 August 2025, three days after the backdoored release
Warned before the backdoor switched on31 of 3141 to 321 days ahead, median 139

In the picture at the top of this page, each row is one plugin. The blue dot is the week Touchstone would have warned; the dark bar on the right is the day the backdoor switched on. The long grey lines are the months a site owner would have had to look, decide, and act.

What Touchstone would, and would not, have done

  • The free plugin would have raised the finding, dropped the plugin's trust score, put it at the top of the list, and emailed the owner within the hour if email alerts were on. Since 1.2.0 it also offers one click to stop WordPress auto-updating a plugin that changed hands.
  • Touchstone Pro would have held the update of a plugin with that open finding until someone approved that exact version, and listed the new web addresses and risky calls in the release before it installed.
  • Its code check would not have caught the backdoor itself. The bad code was inside the official releases, so it matched WordPress.org's own fingerprints. The code check would have caught what the backdoor did next: the rewrite of wp-config.php, within a day in the free plugin and within fifteen minutes in Pro.

A new committer is not proof of harm. Most plugin sales are honest, and a new maintainer is often good news. Touchstone's job is to make the handover visible, so that a person decides rather than an automatic update.

The honest limits

  • This is a replay, not a live catch. Nobody ran Touchstone on these sites at the time.
  • A warning only helps if someone reads it. That is why Touchstone emails within the hour, keeps a finding open until it is acknowledged, and in Pro can hold the update until a person decides.
  • It would not have caught the separate ShapedPlugin compromise, where the existing owner's build pipeline was turned against them and nothing about who held control changed.

Check your own site

You can read any plugin's history by hand: its directory page lists the author and contributors, and its SVN log names everyone who ever committed. Here is how, step by step. Doing it every week for every plugin on every site you run is the part nobody manages, which is why the backdoor sat there for eight months.

Related: the 2026 supply-chain attacks, dated and sourced and every way a plugin can change hands.