Your website depends on a reliable stream of updates. Whether you use one BdThemes plugin or several, each update should be easy to obtain, simple to install and supported by careful release controls.
This update explains how you can keep your plugins up to date in WordPress and what we have strengthened behind the scenes to support a more reliable release process. You will also find practical actions you can take to keep your WordPress site well maintained.
Keeping Your BdThemes Plugins Updated
Keeping your BdThemes plugins up to date helps you receive the latest improvements through the official WordPress update channel.
To update a plugin, open the Plugins page in your WordPress dashboard and select Update now when an update is available. You can also use the official WordPress.org plugin directory to make sure you download the official release.
Our focus is simple: giving you a reliable update path while continuously improving the controls behind each release.
How Your Updates Are Protected
When you install a BdThemes update, it goes through strengthened processes for code inspection, build verification and publishing access.
We have expanded our internal security and code-audit capabilities. Before publication, releases undergo static and dynamic code analysis, dependency checks and targeted security testing. These steps help identify unexpected behavior and outdated dependencies earlier in development.
Release builds are prepared in an isolated environment. Publishing requires approval from more than one authorized team member and hardware-based multi-factor authentication. Automated vulnerability scanning and cryptographic build checks add further safeguards to the release process.
We also schedule independent external security assessments for current and future releases. When an assessment identifies an issue, our development team resolves it before the affected code is released.
We also learned from other notable attacks that affected millions of users
Security research benefits the entire WordPress community. By following responsibly published technical reports, we can learn practical lessons that help strengthen how we review code, manage dependencies, control releases and support users.
The following references concern independent products and separate events. They are included as broader ecosystem context. They do not indicate a shared cause or common WordPress.org status.
- Elementor Pro (more than 6 million active installations). Reference
- All-in-One WP Migration and Backup (more than 5 million active installations). Reference
- Gravity Forms (more than 1 million active installations). Reference
- Avada Builder (estimated 1 million active installations). Reference
- TranslatePress (more than 400,000 active installations). Reference
- Happy Addons for Elementor (400,000 active installations). Reference
- WPMU DEV Dashboard (estimated 350,000 active installations). Reference
- Ninja Forms File Upload extension (estimated 50,000 active installations). Reference
- Super Forms (estimated 13,000 active installations). Reference
- FlyWP (infrastructure matter affecting more than 700 customer servers). Reference
What these reports taught us
Each report covers a different product, cause, response and time frame. Together, they reinforce several practical lessons that guide how we strengthen BdThemes releases.
Treat every file upload as a high-risk boundary
File upload features need strict allowlists, server-side file inspection and safe storage that prevents uploaded files from being executed. Validation must remain reliable even when forms accept multiple files, arrays or chunked uploads. This lesson appears across the Elementor Pro, Gravity Forms, Ninja Forms File Upload and Super Forms reports.
Treat stored and delayed data as untrusted input
Data that appears harmless when first received can become dangerous later in a migration, restore or processing workflow. Import and restore features need careful validation, parameterized queries and controls that protect secrets throughout every stage of the process. All-in-One WP Migration and Backup
Protect authentication and recovery flows with clear server-side checks.
Password-reset links, SSO payloads and signed requests need unambiguous handling from start to finish. Sensitive tokens must not be exposed through related features and every privileged action needs a clear authorization check. TranslatePress and WPMU DEV Dashboard
Apply least privilege throughout the product
Access controls should be checked for every sensitive action. Features that work with files, database data or content editing need strict permission validation and careful handling of user-supplied paths or identifiers. The Avada Builder and Happy Addons reports show why recurring checks for authorization, information exposure, SQL injection and cross-site scripting matter.
Security also depends on operational controls
Privileged access should be reviewed regularly and removed promptly when it is no longer needed. Credentials should be scoped to the minimum access required. Backups need the same protection as production systems. Clear activity logs, monitoring and tested response procedures help teams investigate unexpected activity quickly. FlyWP
A patch needs complete verification
Fast remediation is important but it must be paired with regression testing that confirms the full issue is resolved. This includes testing edge cases, reviewing related code paths and checking that partial fixes do not leave another route open.
For BdThemes, these lessons reinforce our focus on thorough code review, dependency checks, controlled release access, isolated builds and independent security assessments. They help us keep improving the processes that support your plugins and your website.
Our Commitment to You
Your website and its visitors rely on dependable software. That responsibility guides how we prepare updates and the time we invest in code checks, build verification and controlled publishing.
You can help by keeping your BdThemes plugins, WordPress installation and other site components up to date through official channels. We will keep strengthening our release practices as tools and expectations evolve.
If you need help checking a plugin version, installing an update or maintaining your site, BdThemes Support is ready to assist.


