Who owns the plugins on your site today? Not who wrote them - who controls them right now, and who committed to them last week.
WordPress.org does not review plugin ownership transfers. When a plugin is sold, the new owner inherits commit access, their first release is unaudited, and nobody is notified. In April 2026 the WordPress Plugins Team closed 31 plugins at once after a single buyer acquired the portfolio through Flippa and planted a backdoor across all of them. It had been sitting there since August 2025.
We replayed OwnerTrail's committer checks against the public commit history of those 31 plugins. Every one would have raised a high "new committer" warning, a median of 139 days before the backdoor switched on. The backdoor itself was in the official releases, so file checksums alone would not have caught it; the change of hands is the signal.
This is a known gap, not an accusation: WordPress meta ticket #5509, "Notify users of
changes to plugin ownership", is open and unresolved.
OwnerTrail reads the public
WordPress.org plugin directory and the public plugin SVN repository, builds a record of who has committed to each of your installed plugins, and tells you the moment that record changes.
You can do this by hand: open a plugin's directory page, read the listed author and contributors, open its SVN development log, and compare the committer names against what you saw last time. That works for one plugin, once. This does it for every plugin on your site, every day, and stays quiet until something actually changes.
What it detects
- Ownership change — the listed author or the contributor list changed.
- New committer — somebody with no prior history in that plugin has committed for the first time. This is the signal that precedes the attack.
- Dormant then active — a plugin silent for six months suddenly ships a release.
- Abandoned or withdrawn — no update in over a year, or removed from the directory entirely.
- Not monitorable — premium or custom plugins that wordpress.org knows nothing about, named honestly rather than quietly ignored.
Each plugin gets a trust score from 0 to 100. Findings you have reviewed can be acknowledged, and plugins you do not care about can be muted, so the plugin stays quiet until something genuinely changes.
Is your code genuine?
Every day OwnerTrail compares WordPress core and every plugin from
wordpress.org with the official fingerprint of each file, and themes, other plugins, must-use plugins and drop-ins with the copy it first saw. A changed file, an unexpected PHP file (including any in the uploads folder) or a changed wp-config.php is reported on the Code screen and, when email alerts are on, emailed within the hour. Only file names are sent; wp-config.php's contents are never read into a finding or an email. Updates installed by WordPress itself never raise a finding. You can open areas to change (for example the theme while a developer works on it); changes there are noted quietly.
Code lock
On activation, OwnerTrail locks WordPress's built-in plugin, theme and file editors for every user, administrators included. WordPress itself recommends turning these editors off, and code changes made through them are the most common way a site is quietly altered.
One click ("Only allow code changes over FTP", on the first-run report or the Code screen) also stops plugins and themes being uploaded, installed or deleted from the admin, including installs other plugins make through WordPress's installer. Updates of installed code keep running. A site owner (the administrator who activated OwnerTrail) can unlock for one hour; it relocks by itself. Deactivating OwnerTrail removes every lock.
The Code screen also lists installed plugins that can change code despite the lock (those that install code, run code stored in the database, or write into plugin and theme folders), so you can decide whether you need them.
What it does not do
It does not block or delay updates, and it is not a malware scanner: it tells you that code changed, not whether the change is malicious. It does not check for known vulnerabilities — use a dedicated vulnerability scanner alongside it. This plugin answers one question that those tools do not: who controls this code now?
It also cannot see a compromise that does not involve a change of ownership. In June 2026 ShapedPlugin shipped backdoored Pro updates because its own build pipeline was breached; the committer record looked entirely normal throughout, and nothing here would have flagged it. Provenance monitoring answers one question well and is silent on the rest.
Licence and brand
The code is GPLv2 or later. Fork it, read it, ship it.
The OwnerTrail name, wordmark and logo are not covered by that licence and remain the property of
Decodeinfy. A fork is welcome; calling it OwnerTrail is not.
- Install through Plugins > Add New, or upload the folder to
/wp-content/plugins/.
- Activate it. Activation makes no network request and takes well under a second.
- Open OwnerTrail in the admin menu. The first scan runs in the background and builds a committer baseline for every installed plugin, ten at a time.
- Nothing is reported on that first pass - a baseline has nothing to compare against yet. Findings appear when something changes afterwards.
Optionally, turn on the email digest under OwnerTrail > Settings. It is off by default and sends nothing until you save a valid address.