Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack
arstechnica.com
arstechnica.com
I worked at Automatic (in Support / Spam blog hunting / Akismet) in 2011 and after some bad plugin updating from various sources Matt asked me to start vetting wporg plugin updates.
I cannot code in PHP. Lots of reading later I could recognise dodgy code, or code that looked odd.
I set up a gmail account where _every_ new plugin commit was sent to, and I create a ton of filters, each looking for certain code. Those filters were then sent to me and were filtered again - think "Nasty, Maybe, Check"
When something bad happened, I'd review the commits, see the nasty, remove it, update the version, commit to the wporg repo and at the same time take over the account. (Again I can't code PHP but I'm listed as a developer in the plugin repo). That way plugin user was protected.
That was 13 years ago .. why the hell doesn't WP have a better system?