WordPress · Plugins · Small Business
Someone Bought 30 WordPress Plugins and Hacked Every Site Running Them.
A buyer picked up more than 30 WordPress plugins on Flippa, then shipped a backdoor to every site running them. It sat quiet for 8 months. Nobody got a letter.

Bob picked his plugins in 2019. He read the reviews, checked the install counts, looked at who made them. Then he did what any sane person does. He stopped thinking about it and went back to work.
Here's what he didn't know. A plugin is a business, and businesses get sold. Somebody can buy the one on his site, and the only thing that changes on his screen is a number in the update list.
That's not a maybe. It happened in 2026. A buyer bought a stack of more than 30 WordPress plugins on Flippa, then used the official update pipe to push a backdoor into all of them. WordPress.org shut 31 of them down in one day.
A plugin is a business. It keeps turning after somebody else buys it.
The bad code came in through an update you were told to install.
Not a hack. A handoff.
TL;DR (the short answer)
Yes, a WordPress plugin can be sold to somebody new and turned against your site, and you get no notice when it happens. In 2026 a buyer acquired the Essential Plugin portfolio on Flippa for a six figure sum, then shipped hidden code through the official WordPress.org plugin directory. The code first landed in Countdown Timer Ultimate version 2.6.7 on August 8, 2025, under a note saying it was checking WordPress compatibility, and it did nothing at all until April 5, 2026. WordPress.org permanently closed 31 of those plugins on April 7, 2026 for a security issue. A week later it closed a separate plugin running on more than 100,000 sites.
3 Things to Remember
Your Plugins Can Be Sold. Nobody Sends You the Paperwork.

A plugin is somebody's business, and any business can change hands. That is the whole idea Bob was never told.
Think about what that actually means. A person you never met wrote code that runs on your site. That person can sell the code, the name, and the keys to the update pipe to a second person you have also never met. Your site keeps pulling updates from that pipe either way.
The people who built and sold this portfolio didn't do a thing wrong. Building something and selling it is the goal. Bob is trying to do the same thing with his own shop one day. The problem is not the sale. The problem is that nothing in WordPress tells you it happened.
The mistake: thinking you vetted your plugins once and the job is done.
The fix: get it in writing who checks your plugin list, and how often.
The payoff: somebody is actually watching, and it isn't you at 10pm.
The Update Note Said It Was a Compatibility Check. It Was 191 Lines.

The backdoor shipped in Countdown Timer Ultimate version 2.6.7 on August 8, 2025, and the note attached to that update said it was checking compatibility with WordPress version 6.8.2. (Anchor Host, 2026)
That's the whole disguise. One boring line of housekeeping. The kind of update you approve without reading, because you approve forty of them a year and they're all that dull.
Underneath the boring line, that update dropped 191 new lines of code into one file. The file went from 473 lines to 664. (Anchor Host, 2026)
Countdown Timer Ultimate runs on more than 10,000 sites. Its page on WordPress.org now reads "This plugin has been closed as of April 7, 2026 and is not available for download. This closure is permanent. Reason: Security Issue." You can go read it yourself right now. (WordPress.org, 2026)
lines of code arrived in one update. The changelog for that update said it was checking compatibility with a WordPress version. Nothing on Bob's screen said anything else. (Anchor Host, 2026)
I've told you for years that the danger is the plugin pile you can't safely remove, and that Wordfence logs hundreds of WordPress holes in a single week. This one is different, and it's worse. Those are mistakes. This was on purpose, and it came down the same pipe as every fix you've ever installed.
Eight months of nothing to see. Every scan came back clean.
It Slept for 8 Months. That's the Part That Should Bother You.

The code shipped on August 8, 2025 and did absolutely nothing until April 5, 2026. (Anchor Host, 2026)
Run that against your calendar. Labor Day. The whole busy season. Thanksgiving, Christmas, New Year's, tax time, spring. Eight months of a site that scanned clean, loaded fine, and showed a green checkmark next to that plugin the entire time.
Every piece of security advice you've ever gotten is built on the idea that bad things look bad. Scan your site. Watch for weird behavior. Check your files. All of it assumes there's something to see.
There was nothing to see. The plugin worked. The countdown timer counted down. Then one day in April, on somebody else's schedule, it woke up.
Here Is Everything WordPress Tells You When a Plugin Changes Hands.

Nothing. There is no notice, no email, and no flag anywhere in your dashboard. Here is the whole list, and it is short.
- No email when a plugin you run is sold to a new owner.
- No notice in your dashboard. The update screen looks identical.
- No warning that an update is the new owner's first one.
- No alert on your site when WordPress.org closes a plugin you have installed.
- One thing works: the plugin's own page on WordPress.org shows a red closure bar with the date and the reason. You have to go look. (WordPress.org, 2026)
That last one matters more than it sounds. When WordPress.org closes a plugin, it stops being available to download. It does not vanish off your site. If you had it, you still have it, running, today, unless somebody went in and pulled it out by hand.
The mistake: assuming a plugin problem shows up on your screen.
The fix: pull your plugin list and check every one against its page on WordPress.org. It takes about ten minutes.
The payoff: you find out from a page, not from a customer.
A Site With No Plugins Can't Inherit Somebody Else's Owner.

The reason my builds don't have this problem is boring. There is no update pipe pointed at your site from software somebody else controls.
A WordPress site is a pile of other people's code, running live, updating on their schedule. Fifteen plugins means fifteen businesses that can be sold, folded, or handed to a new owner without a word to you.
The sites I build are already built. The pages are finished files sitting on a fast network. Nothing on your site phones home to a stranger's server asking what to run next.
That's not me being clever. It's fewer moving parts, and fewer parts nobody can sell out from under you. That is the whole idea behind the 100K Website, and it is why I say the old machine is done for real business sites.
And when something needs watching, that's my job. You go run your business.
Nothing bolted on. Nothing anybody can sell out from under you.
I Didn't Just Write About It. I Left.
This isn't a number off somebody's chart. I moved 1,300+ of my own posts off a dying WordPress stack. I've built more than 10,000 sites in 25 years, and I've pulled dead and abandoned plugins out of enough of them to know how the phone call starts.
You're reading one of those rebuilt pages right now. It doesn't have a plugin on it that anybody could buy.
Where WordPress Actually Did Its Job.
I'll give WordPress real credit here, and you should weigh it before you take my side.
The plugin review team caught this and closed 31 plugins on April 7, 2026, two days after the code woke up. (WordPress.org, 2026) A week later they closed another one, Widget Logic, sitting on more than 100,000 sites. (WordPress.org, 2026) Most software you install has no version of that at all. Nobody is reviewing the app on your phone after the fact and yanking it in an afternoon.
And the honest part: almost every plugin sale is boring and fine. Somebody builds a thing, gets tired, sells it to somebody who wants to keep it alive. That is a good outcome, and it happens hundreds of times a year without a single problem.
Now the turn. The catch is not that plugins change hands. The catch is that Bob has no way to know when one of his does, and the only defense on offer is somebody else noticing in time. It worked this April. It worked in two days. It also took eight months to get there.
You Shouldn't Have to Track Who Owns Your Website's Parts.
You didn't get into business to keep a list of which strangers currently control which pieces of your site. You got into it to do the work and get paid.
Let me show you what a site with nothing to sell out from under you actually feels like, built on your own market.
You get a real look at your own market. No obligation, and nothing to cancel.
Want the whole playbook first? Plan your attack. Balls Out Marketing.
FAQ
Yes. In 2026 a buyer picked up a portfolio of more than 30 WordPress plugins on Flippa and pushed a backdoor to all of them through the official WordPress.org plugin directory. WordPress.org closed 31 of those plugins on April 7, 2026. Buying a plugin business is legal and normal. The problem is that nothing tells you when it happens.
It's when the bad code arrives through an update you trust instead of through a hole in your site. The attacker gets control of the plugin itself, then ships the code to every site running it as a normal update. Your password, your firewall, and your host never see anything wrong, because the update is signed off by the real plugin.
WordPress.org permanently closed 31 plugins from the Essential Plugin portfolio on April 7, 2026 for a security issue. Countdown Timer Ultimate, on more than 10,000 sites, was the plugin the code first shipped in. A week later, on April 14, 2026, WordPress.org also closed Widget Logic, which ran on more than 100,000 sites.
About 8 months. The code shipped in Countdown Timer Ultimate version 2.6.7 on August 8, 2025 and did nothing at all until April 5, 2026. Every scan, every update check, and every security plugin saw a normal, up to date plugin the whole time.
No. There is no notice, no email, and no flag in your dashboard when a plugin gets sold to a new owner. The update screen looks the same the day before the sale and the day after. You would have to go read the plugin's page on WordPress.org yourself and notice the developer name changed.
Open wordpress.org/plugins/ and add the plugin's slug to the end of the address. A closed plugin shows a red bar at the top with the closure date and the reason. Do this for every plugin on your site, and do it again every few months, because a closed plugin does not disappear from your site on its own.
This is post 2 in a run on WordPress security. Post 1 covered the July 2026 hole in WordPress core that needed no password. That one was a mistake in the software. This one was somebody's plan.
Check Out My Last 3 Builds
Real sites, built with this exact system. Tap any one and poke around.