Linux 软件免费装
Banner图

OwnerTrail - Ownership & Supply Chain Monitor

开发者 kaustav790
更新时间 2026年10月10日 23:27
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

monitoring plugin security ownership supply chain abandoned plugins

下载

1.2.0

详情介绍:

Who owns the plugins on your site today? Not who wrote them - who controls them right now, and who committed to them last week. WordPress.org does not review plugin ownership transfers. When a plugin is sold, the new owner inherits commit access, their first release is unaudited, and nobody is notified. In April 2026 the WordPress Plugins Team closed 31 plugins at once after a single buyer acquired the portfolio through Flippa and planted a backdoor across all of them. It had been sitting there since August 2025. We replayed OwnerTrail's committer checks against the public commit history of those 31 plugins. Every one would have raised a high "new committer" warning, a median of 139 days before the backdoor switched on. The backdoor itself was in the official releases, so file checksums alone would not have caught it; the change of hands is the signal. This is a known gap, not an accusation: WordPress meta ticket #5509, "Notify users of changes to plugin ownership", is open and unresolved. OwnerTrail reads the public WordPress.org plugin directory and the public plugin SVN repository, builds a record of who has committed to each of your installed plugins, and tells you the moment that record changes. You can do this by hand: open a plugin's directory page, read the listed author and contributors, open its SVN development log, and compare the committer names against what you saw last time. That works for one plugin, once. This does it for every plugin on your site, every day, and stays quiet until something actually changes. What it detects Each plugin gets a trust score from 0 to 100. Findings you have reviewed can be acknowledged, and plugins you do not care about can be muted, so the plugin stays quiet until something genuinely changes. Is your code genuine? Every day OwnerTrail compares WordPress core and every plugin from wordpress.org with the official fingerprint of each file, and themes, other plugins, must-use plugins and drop-ins with the copy it first saw. A changed file, an unexpected PHP file (including any in the uploads folder) or a changed wp-config.php is reported on the Code screen and, when email alerts are on, emailed within the hour. Only file names are sent; wp-config.php's contents are never read into a finding or an email. Updates installed by WordPress itself never raise a finding. You can open areas to change (for example the theme while a developer works on it); changes there are noted quietly. Code lock On activation, OwnerTrail locks WordPress's built-in plugin, theme and file editors for every user, administrators included. WordPress itself recommends turning these editors off, and code changes made through them are the most common way a site is quietly altered. One click ("Only allow code changes over FTP", on the first-run report or the Code screen) also stops plugins and themes being uploaded, installed or deleted from the admin, including installs other plugins make through WordPress's installer. Updates of installed code keep running. A site owner (the administrator who activated OwnerTrail) can unlock for one hour; it relocks by itself. Deactivating OwnerTrail removes every lock. The Code screen also lists installed plugins that can change code despite the lock (those that install code, run code stored in the database, or write into plugin and theme folders), so you can decide whether you need them. What it does not do It does not block or delay updates, and it is not a malware scanner: it tells you that code changed, not whether the change is malicious. It does not check for known vulnerabilities — use a dedicated vulnerability scanner alongside it. This plugin answers one question that those tools do not: who controls this code now? It also cannot see a compromise that does not involve a change of ownership. In June 2026 ShapedPlugin shipped backdoored Pro updates because its own build pipeline was breached; the committer record looked entirely normal throughout, and nothing here would have flagged it. Provenance monitoring answers one question well and is silent on the rest. Licence and brand The code is GPLv2 or later. Fork it, read it, ship it. The OwnerTrail name, wordmark and logo are not covered by that licence and remain the property of Decodeinfy. A fork is welcome; calling it OwnerTrail is not.

安装:

  1. Install through Plugins > Add New, or upload the folder to /wp-content/plugins/.
  2. Activate it. Activation makes no network request and takes well under a second.
  3. Open OwnerTrail in the admin menu. The first scan runs in the background and builds a committer baseline for every installed plugin, ten at a time.
  4. Nothing is reported on that first pass - a baseline has nothing to compare against yet. Findings appear when something changes afterwards.
Optionally, turn on the email digest under OwnerTrail > Settings. It is off by default and sends nothing until you save a valid address.

屏幕截图:

  • A plugin's page: its facts, its findings, and everyone who has committed to it.
  • The Code screen: Code lock, the plugins that can get around it, who can change the site, and every part of the site checked against wordpress.org.
  • Settings: email alerts, the areas open to change, and the site owners.
  • The dashboard widget's all-clear.
  • Scan now checks one plugin at a time, with a progress bar.

升级注意事项:

1.0.0 Initial release.

常见问题:

Where did the plugin and theme editors go?

OwnerTrail locks them on activation (see Code lock). A site owner can unlock them for an hour on OwnerTrail > Code, or deactivate OwnerTrail to remove every lock.

I can no longer install plugins from the admin.

"Only allow code changes over FTP" is on. A site owner can unlock for an hour on OwnerTrail > Code, or choose "Lock only the editors" to allow installs again.

How do I check who owns a WordPress plugin?

Manually: open the plugin's page on WordPress.org and read the listed author and the contributor list, then open its Development tab and read the SVN log to see which usernames have committed. Compare that against what you recorded last time. There is no notification when any of it changes, which is the gap this plugin fills - it takes that snapshot for every plugin you have installed, re-reads it daily, and tells you only when something differs.

How do I know if a WordPress plugin has changed hands?

The listed author changes, or contributors are added and removed, or an unfamiliar username starts committing. Any of those can be legitimate - plugins are sold and maintainers hand over all the time. The problem is that none of them are announced, so you find out months later or not at all.

How is this different from Wordfence, Patchstack or Sucuri?

They detect known vulnerabilities and malware signatures, which means something harmful has already been written and catalogued. This detects the trust-boundary event - an ownership transfer, a new committer - that usually comes first. Different layer, different failure mode. Run both.

Does a new committer mean the plugin is compromised?

No. Most ownership changes are entirely legitimate. The point is that you get to look, decide, and acknowledge, instead of finding out later.

Does it slow my site down?

Scanning runs on a background schedule, ten plugins at a time by default, and never on a front-end page load. Nothing runs for your visitors.

Why does my premium plugin show as "not monitorable"?

Plugins distributed outside wordpress.org have no public commit history, so ownership changes cannot be detected. Showing that honestly is more useful than showing a passing grade that means nothing.

WP-Cron does not run reliably on my site.

Use the Scan now button, or set up a real server cron calling wp-cron.php. The Settings screen shows when the last full scan completed.

What happens on a multisite network if I uninstall this on one site?

Uninstalling cleans up the current site only: its stored plugin state, events, and settings. On a network with per-site activation, other subsites' OwnerTrail data is left behind.

更新日志:

1.2.0 1.0.0