OwnerTrail – Ownership & Supply Chain Monitor

Descripción

Who owns the plugins on your site today? Not who wrote them – who controls them right now, and who committed to them last week.

WordPress.org does not review plugin ownership transfers. When a plugin is sold, the new owner inherits commit access, their first release is unaudited, and nobody is notified. In April 2026 the WordPress Plugins Team closed 31 plugins at once after a single buyer acquired the portfolio through Flippa and planted a backdoor across all of them. It had been sitting there since August 2025.

We replayed OwnerTrail’s committer checks against the public commit history of those 31 plugins. Every one would have raised a high “new committer” warning, a median of 139 days before the backdoor switched on. The backdoor itself was in the official releases, so file checksums alone would not have caught it; the change of hands is the signal.

This is a known gap, not an accusation: WordPress meta ticket #5509, “Notify users of
changes to plugin ownership”, is open and unresolved.

OwnerTrail reads the public WordPress.org plugin directory and the public plugin SVN repository, builds a record of who has committed to each of your installed plugins, and tells you the moment that record changes.

You can do this by hand: open a plugin’s directory page, read the listed author and contributors, open its SVN development log, and compare the committer names against what you saw last time. That works for one plugin, once. This does it for every plugin on your site, every day, and stays quiet until something actually changes.

What it detects

  • Ownership change — the listed author or the contributor list changed.
  • New committer — somebody with no prior history in that plugin has committed for the first time. This is the signal that precedes the attack.
  • Dormant then active — a plugin silent for six months suddenly ships a release.
  • Abandoned or withdrawn — no update in over a year, or removed from the directory entirely.
  • Not monitorable — premium or custom plugins that wordpress.org knows nothing about, named honestly rather than quietly ignored.

Each plugin gets a trust score from 0 to 100. Findings you have reviewed can be acknowledged, and plugins you do not care about can be muted, so the plugin stays quiet until something genuinely changes.

Is your code genuine?

Every day OwnerTrail compares WordPress core and every plugin from wordpress.org with the official fingerprint of each file, and themes, other plugins, must-use plugins and drop-ins with the copy it first saw. A changed file, an unexpected PHP file (including any in the uploads folder) or a changed wp-config.php is reported on the Code screen and, when email alerts are on, emailed within the hour. Only file names are sent; wp-config.php’s contents are never read into a finding or an email. Updates installed by WordPress itself never raise a finding. You can open areas to change (for example the theme while a developer works on it); changes there are noted quietly.

Code lock

On activation, OwnerTrail locks WordPress’s built-in plugin, theme and file editors for every user, administrators included. WordPress itself recommends turning these editors off, and code changes made through them are the most common way a site is quietly altered.

One click (“Only allow code changes over FTP”, on the first-run report or the Code screen) also stops plugins and themes being uploaded, installed or deleted from the admin, including installs other plugins make through WordPress’s installer. Updates of installed code keep running. A site owner (the administrator who activated OwnerTrail) can unlock for one hour; it relocks by itself. Deactivating OwnerTrail removes every lock.

The Code screen also lists installed plugins that can change code despite the lock (those that install code, run code stored in the database, or write into plugin and theme folders), so you can decide whether you need them.

What it does not do

It does not block or delay updates, and it is not a malware scanner: it tells you that code changed, not whether the change is malicious. It does not check for known vulnerabilities — use a dedicated vulnerability scanner alongside it. This plugin answers one question that those tools do not: who controls this code now?

It also cannot see a compromise that does not involve a change of ownership. In June 2026 ShapedPlugin shipped backdoored Pro updates because its own build pipeline was breached; the committer record looked entirely normal throughout, and nothing here would have flagged it. Provenance monitoring answers one question well and is silent on the rest.

Licence and brand

The code is GPLv2 or later. Fork it, read it, ship it.

The OwnerTrail name, wordmark and logo are not covered by that licence and remain the property of Decodeinfy. A fork is welcome; calling it OwnerTrail is not.

External services

This plugin contacts three wordpress.org services to do its work. The only information sent to them is the slug of each installed plugin, plus its version number for the checksum service (and, for the WordPress core check, your WordPress version and language).

  1. wordpress.org Plugin Information API — https://api.wordpress.org/plugins/info/1.2/. Used to read each plugin’s listed author, contributors, last update date, and install count. A plugin slug is sent with each request. Terms: https://wordpress.org/about/privacy/ Privacy: https://wordpress.org/about/privacy/

  2. wordpress.org Plugin SVN repository — https://plugins.svn.wordpress.org/. Used to read the public commit history for each plugin, which is how committer changes are detected. A plugin slug is sent with each request. Terms: https://wordpress.org/about/privacy/ Privacy: https://wordpress.org/about/privacy/

  3. wordpress.org plugin checksums — https://downloads.wordpress.org/plugin-checksums/. Used by the daily code check to read the official fingerprint of every file in each directory plugin’s installed version. A plugin slug and version number are sent with each request. The WordPress core fingerprints come from https://api.wordpress.org/core/checksums/1.0/ (the same service as item 1), with your WordPress version and language sent. No file contents ever leave your site: files are compared on your own server. Terms: https://wordpress.org/about/privacy/ Privacy: https://wordpress.org/about/privacy/

Email digest

This plugin can also email you when it finds something. This is off by default. Turning on “Email alerts” on the OwnerTrail Settings screen makes your site email plugin findings — including plugin slugs, severities, finding descriptions, and your site’s name — to the address you configure there (or, if that is blank, your site’s administration email): serious findings within the hour, at most one email an hour, plus a daily digest. A separate Weekly summary setting, also off by default, sends a short all-clear every Monday morning with plugin counts and updates waiting. The first-run panel on the Overview screen offers a one-click “Email me when something needs attention”, which turns on the same “Email alerts” setting. All of this is sent using your own site’s outgoing mail (wp_mail()); it is not a wordpress.org service and does not involve any other third party.

Nothing else leaves your site. There is no telemetry, no analytics, and no tracking of any kind beyond what is described above.

Capturas de pantalla

Instalación

  1. Install through Plugins > Add New, or upload the folder to /wp-content/plugins/.
  2. Activate it. Activation makes no network request and takes well under a second.
  3. Open OwnerTrail in the admin menu. The first scan runs in the background and builds a committer baseline for every installed plugin, ten at a time.
  4. Nothing is reported on that first pass – a baseline has nothing to compare against yet. Findings appear when something changes afterwards.

Optionally, turn on the email digest under OwnerTrail > Settings. It is off by default and sends nothing until you save a valid address.

FAQ

Where did the plugin and theme editors go?

OwnerTrail locks them on activation (see Code lock). A site owner can unlock them for an hour on OwnerTrail > Code, or deactivate OwnerTrail to remove every lock.

I can no longer install plugins from the admin.

“Only allow code changes over FTP” is on. A site owner can unlock for an hour on OwnerTrail > Code, or choose “Lock only the editors” to allow installs again.

How do I check who owns a WordPress plugin?

Manually: open the plugin’s page on WordPress.org and read the listed author and the contributor list, then open its Development tab and read the SVN log to see which usernames have committed. Compare that against what you recorded last time. There is no notification when any of it changes, which is the gap this plugin fills – it takes that snapshot for every plugin you have installed, re-reads it daily, and tells you only when something differs.

How do I know if a WordPress plugin has changed hands?

The listed author changes, or contributors are added and removed, or an unfamiliar username starts committing. Any of those can be legitimate – plugins are sold and maintainers hand over all the time. The problem is that none of them are announced, so you find out months later or not at all.

How is this different from Wordfence, Patchstack or Sucuri?

They detect known vulnerabilities and malware signatures, which means something harmful has already been written and catalogued. This detects the trust-boundary event – an ownership transfer, a new committer – that usually comes first. Different layer, different failure mode. Run both.

Does a new committer mean the plugin is compromised?

No. Most ownership changes are entirely legitimate. The point is that you get to look, decide, and acknowledge, instead of finding out later.

Does it slow my site down?

Scanning runs on a background schedule, ten plugins at a time by default, and never on a front-end page load. Nothing runs for your visitors.

Why does my premium plugin show as “not monitorable”?

Plugins distributed outside wordpress.org have no public commit history, so ownership changes cannot be detected. Showing that honestly is more useful than showing a passing grade that means nothing.

WP-Cron does not run reliably on my site.

Use the Scan now button, or set up a real server cron calling wp-cron.php. The Settings screen shows when the last full scan completed.

What happens on a multisite network if I uninstall this on one site?

Uninstalling cleans up the current site only: its stored plugin state, events, and settings. On a network with per-site activation, other subsites’ OwnerTrail data is left behind.

Reseñas

No hay reseñas para este plugin.

Colaboradores & Desarrolladores

“OwnerTrail – Ownership & Supply Chain Monitor” es software de código abierto. Las siguientes personas han contribuido a este plugin.

Colaboradores

Historial de cambios

1.2.0

  • New: “Your site at a glance”, a first-run report with next steps and one-click email alerts.
  • New: the dashboard widget leads with the week’s all-clear.
  • New: optional weekly summary email (off by default).
  • New: serious findings are emailed within the hour when email alerts are on.
  • New: Scan now shows a progress bar and checks one plugin at a time.
  • New: Code lock. The built-in code editors are locked on activation; one click also stops plugin and theme uploads, installs and deletes from the admin. Only a site owner can unlock, for an hour at a time.
  • New: the code check also covers must-use plugins, drop-ins, loose PHP in wp-content and the site’s configuration files, and lists the plugins that can change code despite Code lock.
  • New: daily code integrity check. WordPress core and every directory plugin are compared with wordpress.org’s official file fingerprints; themes and other plugins with the copy OwnerTrail first saw; PHP files in uploads are flagged. A change is named by file on the new Code screen and, outside the areas you open to change, emailed within the hour.

  • New: a plugin wordpress.org has closed is flagged with the date and reason, even when it was closed before OwnerTrail was installed (it was shown as “not monitorable” before).

  • New: when a plugin changes hands or is closed and WordPress would update it by itself, its page offers one click to turn auto-updates off, and the urgent email says so.
  • New: when email alerts are on, the owners are emailed if OwnerTrail is switched off: who did it and when.
  • Fix: a plugin removed since the last scan no longer counts in the Scan now progress or stays on the Code screen.
  • Fix: “findings to review” no longer counts plugins that simply cannot be checked.
  • New: beside a serious finding, a short note on what OwnerTrail Pro would have done about it (only while Pro is not installed; dismissible), and a line in the weekly summary when there is something to count.
  • New: a code finding whose files are later put back as they were says so (“Since put back as it was”), and still waits for you to acknowledge it.
  • Fix: editing a file again while an earlier change to it is still unacknowledged is now a new finding, not a silent repeat.
  • Fix: uninstalling now also removes the per-user settings OwnerTrail stores.
  • Fix: Hello Dolly, which ships with WordPress as hello.php, is read under its wordpress.org name, so its ownership is monitored instead of shown as “cannot be checked”.

1.0.0

  • Initial release.