The BdThemes plugins listed below are available on WordPress.org with updated release builds. If you use one of them, please update it from the Plugins page in your WordPress dashboard.
Following a recent supply-chain security alert, we worked directly with the WordPress.org Security and Plugin Review teams.
We provided the requested code and build information and completed the required checks for the releases now available.
Plugins are available now
The following plugins are available on WordPress.org:
- Element Pack Lite
- Prime Slider Lite
- Ultimate Post Kit
- Live Copy Paste
- AI Image Generator
- Dark Reader
- Website Accessibility
The current versions went through the requested checks. Please install updates through WordPress admin or the official WordPress.org plugin directory so that your site receives the official repository version.
We also learned from major WordPress security incidents
Public security reporting helps the entire WordPress community improve. We regularly study disclosures from researchers and vendors to understand how incidents were handled and what safeguards could reduce similar risks for our users.
The following reports are among those we reviewed. They involve products of different sizes, including several used on millions of WordPress sites.
- Elementor Pro (more than 6 million active installations). Reference
- All-in-One WP Migration and Backup (more than 5 million active installations). Reference
- Gravity Forms (more than 1 million active installations). Reference
- Avada Builder (estimated 1 million active installations). Reference
- TranslatePress (more than 400,000 active installations). Reference
- Happy Addons for Elementor (400,000 active installations). Reference
- WPMU DEV Dashboard (estimated 350,000 active installations). Reference
- Ninja Forms File Upload extension (estimated 50,000 active installations). Reference
- Super Forms (estimated 13,000 active installations). Reference
- FlyWP (an infrastructure incident affecting more than 700 customer servers). Reference
We share these references with respect for the developers and researchers who worked through each case. Every report concerns a different event and should be understood on its own facts. FlyWP reported an infrastructure incident, while the other references concern plugin vulnerabilities; the list does not suggest a shared cause or a common WordPress.org status.
For BdThemes, the value of studying these cases is practical. The lessons have informed the safeguards described below and helped us strengthen how we review code, control releases and respond when a security concern is raised.
What We Have Changed
We have expanded our in-house security and code-audit team. Releases now receive static and dynamic code analysis before publication, along with dependency checks and penetration testing. The people responsible for this work are listed on the BdThemes team page.
Our release builds now run in an isolated environment. Publishing requires approval from more than one person and hardware-based multi-factor authentication. The process also includes automated vulnerability scanning and cryptographic build checks.
We are also scheduling outside security reviews for current and future releases. The development team will address any findings before the next release.
Thank you for your patience while these reviews were underway. If you need help checking a plugin version or updating a site, please contact BdThemes Support.
