Banish Spam hackers to the 9 level of Dante’s hell. Plugin Pulse: WP Plugins A to Z Unplugged #11

WordPress Plugins from A to Z42mApril 20, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Banish Spam hackers to the 9 level of Dante’s hell. Plugin Pulse: WP Plugins A to Z Unplugged #11” inside PodZeus.

AI-Generated Summary

In this episode of 'WordPress Plugins A to Z', host John dives into a critical security alert involving supply-side hacks in WordPress plugins. He details a recent incident where a developer sold 31 plugins for a million dollars, then inserted a backdoor that redirected traffic to spam sites—only activated months later with a misleading update note. John shares his personal experience with the compromised Countdown Timer plugin, explaining how he reverted to a clean backup and plans to fork the plugin for future development. He emphasizes the importance of vigilance, regular updates, and proactive monitoring, highlighting tools like Advanced Database Cleaner Pro and the need to avoid bulk plugin updates. The episode also features a review of his own lightweight plugin, WP Pro A to Z CPT Selector, a tip on using Elementor instead of Gutenberg for MailPoet forms, and a strong recommendation against bulk updates due to the risk of undetected breakage. John concludes with a call for community support through time, talent, and treasure, promoting the show's newsletter, live streams, and donation options.

Key Takeaways
1

Avoid bulk plugin updates—update one at a time to prevent undetected breakage.

2

Always maintain clean backups before updating plugins, especially after a sale or compromise.

3

Use tools like Advanced Database Cleaner Pro to remove orphaned data from deactivated plugins.

4

Consider forking clean, compromised plugins to maintain functionality and improve them.

5

Use Elementor’s form widget instead of Gutenberg for better control when integrating with MailPoet.

…and 3 more takeaways available in PodZeus

Chapters
0:00
5 min

The Spam Hacker Crisis: A Warning from the Ninth Circle

Banish spam hackers to the ninth level of Dante's hell.

Highlight
5:00
10 min

Personal Experience with the Countdown Timer Hack

I reverted back to that old plugin and then marked it as no longer available for update.

Highlight
15:00
15 min

Security Best Practices and the Reality of Supply Chain Attacks

John discusses the broader context of WordPress security, including the Patchstack report on a trojanized copy of While Shipping Pro. He stresses the importance of staying informed, using monitoring tools, and maintaining a clean database to prevent vulnerabilities.

30:00
15 min

Introducing the WP Pro A to Z CPT Selector Plugin

John reviews his own lightweight plugin, WP Pro A to Z CPT Selector, designed to help Elementor users generate dynamic lists from custom post types. He gives it a 5 Dragon Rating and shares his vision for future improvements.

45:00
20 min

The Tip of the Day: Avoid Gutenberg, Use Elementor for MailPoet Forms

When you think something's not working, just do a little research and you'll find out you most likely can do it.

Highlight
High-Impact Quotes
Banish spam hackers to the ninth level of Dante's hell.
John0:18
Viral: 85.0
Don't bulk update. Whatever you do, just do one at a time and take those extra few minutes.
John38:30
Viral: 80.0
I reverted back to that old plugin and then marked it as no longer available for update.
John6:33
Viral: 75.0
Speakers

Host

John
Topics Discussed
WordPress Security95%Plugin Supply Chain Attacks90%Bulk Plugin Updates85%Database Cleanup80%Plugin Forking and Maintenance75%Elementor vs Gutenberg70%Community Support and Donations65%Custom Post Types60%
People & Brands

John

person

15xNeutral

Elementor

other

8xPositive

Countdown Timer

other

7xNeutral

Gutenberg

other

6xNegative

WP Pro A to Z CPT Selector

other

5xPositive

Advanced Database Cleaner Pro

other

4xPositive

MailPoet

product

4xPositive

Amber

person

3xNeutral

While Shipping Pro

other

2xNeutral

Patchstack

organization

2xNeutral

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Banish Spam hackers to the 9 level of Dante’s hell. Plugin Pulse: WP Plugins A to Z Unplugged #11” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime