Small Business SEO904-447-0750Take a Test Drive
About100K AI WebsiteGuidesBlogReviewsFAQsContact904-447-0750Take a Test Drive

WordPress · Plugins · Small Business

Someone Bought 30 WordPress Plugins and Hacked Every Site Running Them.

A buyer picked up more than 30 WordPress plugins on Flippa, then shipped a backdoor to every site running them. It sat quiet for 8 months. Nobody got a letter.

I haul a giant red wrecking ball painted HACK up out of a cardboard box stamped 30 WEBSITE PLUGINS SOLD while three lit panels behind me show roofer, plumber and HVAC websites cracking under red warning triangles, an armoured WordPress robot at the edge and a Barred Rock hen pulling on the rope. Someone bought 30 WordPress plugins and hacked every site running them.

Bob picked his plugins in 2019. He read the reviews, checked the install counts, looked at who made them. Then he did what any sane person does. He stopped thinking about it and went back to work.

Here's what he didn't know. A plugin is a business, and businesses get sold. Somebody can buy the one on his site, and the only thing that changes on his screen is a number in the update list.

That's not a maybe. It happened in 2026. A buyer bought a stack of more than 30 WordPress plugins on Flippa, then used the official update pipe to push a backdoor into all of them. WordPress.org shut 31 of them down in one day.

A plugin is a business. It keeps turning after somebody else buys it.

The bad code came in through an update you were told to install.

Not a hack. A handoff.

TL;DR (the short answer)

Yes, a WordPress plugin can be sold to somebody new and turned against your site, and you get no notice when it happens. In 2026 a buyer acquired the Essential Plugin portfolio on Flippa for a six figure sum, then shipped hidden code through the official WordPress.org plugin directory. The code first landed in Countdown Timer Ultimate version 2.6.7 on August 8, 2025, under a note saying it was checking WordPress compatibility, and it did nothing at all until April 5, 2026. WordPress.org permanently closed 31 of those plugins on April 7, 2026 for a security issue. A week later it closed a separate plugin running on more than 100,000 sites.

3 Things to Remember

1
Plugins get bought and sold like used trucks. Your dashboard never mentions it.
2
The bad code arrived as a normal update. Updating fast would have gotten it to you sooner, not later.
3
It slept for 8 months. Every scan and every checkup during that stretch came back clean.

Your Plugins Can Be Sold. Nobody Sends You the Paperwork.

I hold open a black mailbox stamped YOUR NOTICE with a Barred Rock hen standing inside it, next to a giant plugin ownership certificate where OLD OWNER: You is struck through and NEW OWNER is stamped in red, a black WordPress robot holding a gold key behind it. Your plugins can be sold. Nobody sends you the paperwork.

A plugin is somebody's business, and any business can change hands. That is the whole idea Bob was never told.

Think about what that actually means. A person you never met wrote code that runs on your site. That person can sell the code, the name, and the keys to the update pipe to a second person you have also never met. Your site keeps pulling updates from that pipe either way.

The people who built and sold this portfolio didn't do a thing wrong. Building something and selling it is the goal. Bob is trying to do the same thing with his own shop one day. The problem is not the sale. The problem is that nothing in WordPress tells you it happened.

The mistake: thinking you vetted your plugins once and the job is done.

The fix: get it in writing who checks your plugin list, and how often.

The payoff: somebody is actually watching, and it isn't you at 10pm.

The Update Note Said It Was a Compatibility Check. It Was 191 Lines.

I peel back a huge sheet of paper under a WordPress badged inspection lamp to reveal a masked thief's face drawn entirely out of dense lines of code, a Barred Rock hen pecking at the edge of the sheet. The update note said it was a compatibility check. It was 191 lines.

The backdoor shipped in Countdown Timer Ultimate version 2.6.7 on August 8, 2025, and the note attached to that update said it was checking compatibility with WordPress version 6.8.2. (Anchor Host, 2026)

That's the whole disguise. One boring line of housekeeping. The kind of update you approve without reading, because you approve forty of them a year and they're all that dull.

Underneath the boring line, that update dropped 191 new lines of code into one file. The file went from 473 lines to 664. (Anchor Host, 2026)

Countdown Timer Ultimate runs on more than 10,000 sites. Its page on WordPress.org now reads "This plugin has been closed as of April 7, 2026 and is not available for download. This closure is permanent. Reason: Security Issue." You can go read it yourself right now. (WordPress.org, 2026)

0

lines of code arrived in one update. The changelog for that update said it was checking compatibility with a WordPress version. Nothing on Bob's screen said anything else. (Anchor Host, 2026)

I've told you for years that the danger is the plugin pile you can't safely remove, and that Wordfence logs hundreds of WordPress holes in a single week. This one is different, and it's worse. Those are mistakes. This was on purpose, and it came down the same pipe as every fix you've ever installed.

0
plugins shut down in a single day. WordPress.org closed all of them on April 7, 2026, and the notice on each one says the same two words: Security Issue. (WordPress.org, 2026)
0
new lines of code in one update. The note on that update said it was checking compatibility with a WordPress version. (Anchor Host, 2026)
0
months it sat there doing nothing at all. It shipped August 8, 2025 and didn't move until April 5, 2026. (Anchor Host, 2026)
0
days later, a different plugin running on 100,000+ sites got closed too. April 14, 2026. Different owner, same story. (WordPress.org, 2026)

Eight months of nothing to see. Every scan came back clean.

It Slept for 8 Months. That's the Part That Should Bother You.

I slam down the bar of a giant black alarm clock whose face reads 8 MONTHS over a glowing red HACK orb tucked under a blanket on a pillow, a Barred Rock hen perched on one bell and a small armoured WordPress robot beside it. It slept for 8 months. That's the part that should bother you.

The code shipped on August 8, 2025 and did absolutely nothing until April 5, 2026. (Anchor Host, 2026)

Run that against your calendar. Labor Day. The whole busy season. Thanksgiving, Christmas, New Year's, tax time, spring. Eight months of a site that scanned clean, loaded fine, and showed a green checkmark next to that plugin the entire time.

Every piece of security advice you've ever gotten is built on the idea that bad things look bad. Scan your site. Watch for weird behavior. Check your files. All of it assumes there's something to see.

There was nothing to see. The plugin worked. The countdown timer counted down. Then one day in April, on somebody else's schedule, it woke up.

Here Is Everything WordPress Tells You When a Plugin Changes Hands.

I strain to hold up an enormous empty glass speech bubble in front of a huge chrome WordPress robot head with its mouth hanging open, a Barred Rock hen pecking the floor between us. Here is everything WordPress tells you when a plugin changes hands.

Nothing. There is no notice, no email, and no flag anywhere in your dashboard. Here is the whole list, and it is short.

  • No email when a plugin you run is sold to a new owner.
  • No notice in your dashboard. The update screen looks identical.
  • No warning that an update is the new owner's first one.
  • No alert on your site when WordPress.org closes a plugin you have installed.
  • One thing works: the plugin's own page on WordPress.org shows a red closure bar with the date and the reason. You have to go look. (WordPress.org, 2026)

That last one matters more than it sounds. When WordPress.org closes a plugin, it stops being available to download. It does not vanish off your site. If you had it, you still have it, running, today, unless somebody went in and pulled it out by hand.

The mistake: assuming a plugin problem shows up on your screen.

The fix: pull your plugin list and check every one against its page on WordPress.org. It takes about ten minutes.

The payoff: you find out from a page, not from a customer.

Do it yourself

Find Out Who Owns the Plugins on Your Site

Open your WordPress dashboard, go to Plugins, and copy the list. Paste it in the prompt and hit a button. Claude or ChatGPT checks each one against its page on WordPress.org and hands you back a table, plus the questions to ask your web guy. Takes about two minutes.

Prompt · Who owns my plugins now
You are a plain-talking website helper. Here is the list of plugins running on my WordPress site: [PASTE YOUR PLUGIN LIST]. For each one, do this and show me a simple table. 1) Give me the plugin's page address on WordPress.org. 2) Tell me if that page shows a red closure notice, and if it does, give me the closure date and the reason word for word. 3) Tell me the last date the plugin was updated and how many sites run it. 4) Tell me who the listed author is now and whether that name has changed in the last two years. 5) Flag any plugin that hasn't been updated in over a year. Then give me one short list of the plugins I should ask my website person about first, worst first, and the exact question to ask about each one. Short sentences. No jargon. If you can't confirm something, say you can't confirm it instead of guessing.

Paste your plugin names where it says PASTE YOUR PLUGIN LIST. Names are enough, versions help.

A Site With No Plugins Can't Inherit Somebody Else's Owner.

I brace a blue lit steel cabinet labelled MYBUSINESS.COM roofing plumbing HVAC away from a black WordPress robot reaching for it, a Barred Rock hen standing on a rolled out contract stamped NEW OWNER. A site with no plugins can't inherit somebody else's owner.

The reason my builds don't have this problem is boring. There is no update pipe pointed at your site from software somebody else controls.

A WordPress site is a pile of other people's code, running live, updating on their schedule. Fifteen plugins means fifteen businesses that can be sold, folded, or handed to a new owner without a word to you.

The sites I build are already built. The pages are finished files sitting on a fast network. Nothing on your site phones home to a stranger's server asking what to run next.

That's not me being clever. It's fewer moving parts, and fewer parts nobody can sell out from under you. That is the whole idea behind the 100K Website, and it is why I say the old machine is done for real business sites.

And when something needs watching, that's my job. You go run your business.

Nothing bolted on. Nothing anybody can sell out from under you.

I Didn't Just Write About It. I Left.

This isn't a number off somebody's chart. I moved 1,300+ of my own posts off a dying WordPress stack. I've built more than 10,000 sites in 25 years, and I've pulled dead and abandoned plugins out of enough of them to know how the phone call starts.

You're reading one of those rebuilt pages right now. It doesn't have a plugin on it that anybody could buy.

Where WordPress Actually Did Its Job.

I'll give WordPress real credit here, and you should weigh it before you take my side.

The plugin review team caught this and closed 31 plugins on April 7, 2026, two days after the code woke up. (WordPress.org, 2026) A week later they closed another one, Widget Logic, sitting on more than 100,000 sites. (WordPress.org, 2026) Most software you install has no version of that at all. Nobody is reviewing the app on your phone after the fact and yanking it in an afternoon.

And the honest part: almost every plugin sale is boring and fine. Somebody builds a thing, gets tired, sells it to somebody who wants to keep it alive. That is a good outcome, and it happens hundreds of times a year without a single problem.

Now the turn. The catch is not that plugins change hands. The catch is that Bob has no way to know when one of his does, and the only defense on offer is somebody else noticing in time. It worked this April. It worked in two days. It also took eight months to get there.

You Shouldn't Have to Track Who Owns Your Website's Parts.

You didn't get into business to keep a list of which strangers currently control which pieces of your site. You got into it to do the work and get paid.

Let me show you what a site with nothing to sell out from under you actually feels like, built on your own market.

Take a Test Drive →

You get a real look at your own market. No obligation, and nothing to cancel.

Want the whole playbook first? Plan your attack. Balls Out Marketing.

FAQ

Can someone buy a WordPress plugin and put bad code in it?

Yes. In 2026 a buyer picked up a portfolio of more than 30 WordPress plugins on Flippa and pushed a backdoor to all of them through the official WordPress.org plugin directory. WordPress.org closed 31 of those plugins on April 7, 2026. Buying a plugin business is legal and normal. The problem is that nothing tells you when it happens.

What is a WordPress supply chain attack?

It's when the bad code arrives through an update you trust instead of through a hole in your site. The attacker gets control of the plugin itself, then ships the code to every site running it as a normal update. Your password, your firewall, and your host never see anything wrong, because the update is signed off by the real plugin.

Which WordPress plugins were backdoored in 2026?

WordPress.org permanently closed 31 plugins from the Essential Plugin portfolio on April 7, 2026 for a security issue. Countdown Timer Ultimate, on more than 10,000 sites, was the plugin the code first shipped in. A week later, on April 14, 2026, WordPress.org also closed Widget Logic, which ran on more than 100,000 sites.

How long was the WordPress plugin backdoor hidden?

About 8 months. The code shipped in Countdown Timer Ultimate version 2.6.7 on August 8, 2025 and did nothing at all until April 5, 2026. Every scan, every update check, and every security plugin saw a normal, up to date plugin the whole time.

Does WordPress tell me when a plugin changes owners?

No. There is no notice, no email, and no flag in your dashboard when a plugin gets sold to a new owner. The update screen looks the same the day before the sale and the day after. You would have to go read the plugin's page on WordPress.org yourself and notice the developer name changed.

How do I check if a plugin on my site was closed?

Open wordpress.org/plugins/ and add the plugin's slug to the end of the address. A closed plugin shows a red bar at the top with the closure date and the reason. Do this for every plugin on your site, and do it again every few months, because a closed plugin does not disappear from your site on its own.

This is post 2 in a run on WordPress security. Post 1 covered the July 2026 hole in WordPress core that needed no password. That one was a mistake in the software. This one was somebody's plan.

Check Out My Last 3 Builds

Real sites, built with this exact system. Tap any one and poke around.

Two Men and a Truck
Moving company
See it live →
Learn Euphoria
Education & courses
See it live →
SoFresh
Fast-casual food
See it live →
Small Business SEO · Jacksonville, FL · Go Balls Out.

Get 2 Must-Read Resources Every Week

No spam. No pitch. Just 2 Must Read Resources a Week.

By downloading, you agree to our Privacy Policy. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.