AI discovered 300 WordPress plugin zero-days in 72 hours
·2 min read·Intermediate
“
Picture releasing a WordPress plugin only to discover an AI has torn it apart and found 35 critical vulnerabilities in a few days. Not sci-fi—it's what happened to a developer who decided to run his code through an AI security scanner. What he learned next is even more unsettling.
→
💡
What this means for you
If you run a lot of WordPress plugins, understand that your site's security now depends on how fast developers can find their own holes before an AI—or a hacker—finds them first. The arms race between defenders and attackers just got a lot faster, and low-quality plugins are now even riskier.
Thought slapping 'AI' next to a company name guaranteed its stock would soar? Well, the market had a bitter surprise this year.
·1 min·2·Beginner
0101
The experiment that sent shivers down spines
A developer launched his AI chatbot plugin and, before pushing it live, ran a security review. The result? 35 vulnerabilities in his own code. Then things got weird: the same AI model, let loose to scan the broader WordPress plugin ecosystem over 72 hours, found roughly 300 zero-days—unknown security flaws nobody had spotted before. This isn't hyperbole.
0202
What it means for people who actually code
For plugin developers, this is cold water in the middle of summer. If an AI can find hundreds of critical vulnerabilities in a matter of days just scanning publicly available code, anyone with malicious intent could do the same thing. The era of security holes hiding for months or years? Over. The developer admitted his entire mindset about security shifted overnight: running your code past human reviewers isn't enough anymore. You have to assume a smart machine will find problems anyway, and it'll be thorough.
📬 Enjoying this article?
Get the best AI news every week, straight to your inbox.
0303
The paradox of transparency
He started looking at his own code through an AI's eyes: what would it see? Which shortcuts would it exploit? What wrong assumptions would it find? The answer was eye-opening—and sobering. Many vulnerabilities the AI uncovered weren't silly mistakes, but subtle logic flaws, unhandled edge cases, or dangerous configurations that looked harmless at a glance. This completely reshapes how plugin developers think. You can't afford to "hope" nobody finds a hole anymore. An AI will find it.
0404
The arms race in security
This discovery kicks open a debate with no easy answers: AI security scanners are becoming tools for responsible developers, but also weapons in the hands of people with bad intentions. The WordPress community needs to move fast. Either developers adopt these tools to find holes before the bad actors do (and the automated bots that are already out there), or they get hit by attackers who already are. There's no comfortable gray zone left to hang out in.
While the tech world was buzzing about OpenAI, Anthropic made its move. They just dropped Opus 5, a model they claim is almost as good as their legendary Fable 5.