Title: OwnerTrail &#8211; Ownership &amp; Supply Chain Monitor
Author: Kaustav Sengupta
Published: <strong>10. októbra 2026</strong>
Last modified: 10. októbra 2026

---

Vyhľadať plugin

![](https://ps.w.org/ownertrail/assets/banner-772x250.png?rev=3738233)

![](https://ps.w.org/ownertrail/assets/icon-256x256.png?rev=3738233)

# OwnerTrail – Ownership & Supply Chain Monitor

 Od [Kaustav Sengupta](https://profiles.wordpress.org/kaustav790/)

[Stiahnuť](https://downloads.wordpress.org/plugin/ownertrail.1.2.0.zip)

 * [Podrobnosti](https://sk.wordpress.org/plugins/ownertrail/#description)
 * [Recenzie](https://sk.wordpress.org/plugins/ownertrail/#reviews)
 *  [Inštalácia](https://sk.wordpress.org/plugins/ownertrail/#installation)
 * [Vývoj](https://sk.wordpress.org/plugins/ownertrail/#developers)

 [Podpora](https://wordpress.org/support/plugin/ownertrail/)

## Popis

**Who owns the plugins on your site today?** Not who wrote them – who controls them
right now, and who committed to them last week.

WordPress.org does not review plugin ownership transfers. When a plugin is sold,
the new owner inherits commit access, their first release is unaudited, and nobody
is notified. In April 2026 the WordPress Plugins Team closed 31 plugins at once 
after a single buyer acquired the portfolio through Flippa and planted a backdoor
across all of them. It had been sitting there since August 2025.

We replayed OwnerTrail’s committer checks against the public commit history of those
31 plugins. Every one would have raised a high „new committer“ warning, a median
of 139 days before the backdoor switched on. The backdoor itself was in the official
releases, so file checksums alone would not have caught it; the change of hands 
is the signal.

This is a known gap, not an accusation: WordPress meta ticket #5509, „Notify users
of
 changes to plugin ownership“, is open and unresolved.

OwnerTrail reads the public WordPress.org plugin directory and the public plugin
SVN repository, builds a record of who has committed to each of your installed plugins,
and tells you the moment that record changes.

You can do this by hand: open a plugin’s directory page, read the listed author 
and contributors, open its SVN development log, and compare the committer names 
against what you saw last time. That works for one plugin, once. This does it for
every plugin on your site, every day, and stays quiet until something actually changes.

#### What it detects

 * **Ownership change** — the listed author or the contributor list changed.
 * **New committer** — somebody with no prior history in that plugin has committed
   for the first time. This is the signal that precedes the attack.
 * **Dormant then active** — a plugin silent for six months suddenly ships a release.
 * **Abandoned or withdrawn** — no update in over a year, or removed from the directory
   entirely.
 * **Not monitorable** — premium or custom plugins that wordpress.org knows nothing
   about, named honestly rather than quietly ignored.

Each plugin gets a trust score from 0 to 100. Findings you have reviewed can be 
acknowledged, and plugins you do not care about can be muted, so the plugin stays
quiet until something genuinely changes.

#### Is your code genuine?

Every day OwnerTrail compares WordPress core and every plugin from wordpress.org
with the official fingerprint of each file, and themes, other plugins, must-use 
plugins and drop-ins with the copy it first saw. A changed file, an unexpected PHP
file (including any in the uploads folder) or a changed wp-config.php is reported
on the Code screen and, when email alerts are on, emailed within the hour. Only 
file names are sent; wp-config.php’s contents are never read into a finding or an
email. Updates installed by WordPress itself never raise a finding. You can open
areas to change (for example the theme while a developer works on it); changes there
are noted quietly.

#### Code lock

**On activation, OwnerTrail locks WordPress’s built-in plugin, theme and file editors
for every user**, administrators included. WordPress itself recommends turning these
editors off, and code changes made through them are the most common way a site is
quietly altered.

One click („Only allow code changes over FTP“, on the first-run report or the Code
screen) also stops plugins and themes being uploaded, installed or deleted from 
the admin, including installs other plugins make through WordPress’s installer. 
Updates of installed code keep running. A site owner (the administrator who activated
OwnerTrail) can unlock for one hour; it relocks by itself. Deactivating OwnerTrail
removes every lock.

The Code screen also lists installed plugins that can change code despite the lock(
those that install code, run code stored in the database, or write into plugin and
theme folders), so you can decide whether you need them.

#### What it does not do

It does not block or delay updates, and it is not a malware scanner: it tells you
that code changed, not whether the change is malicious. It does not check for known
vulnerabilities — use a dedicated vulnerability scanner alongside it. This plugin
answers one question that those tools do not: who controls this code now?

It also cannot see a compromise that does not involve a change of ownership. In 
June 2026 ShapedPlugin shipped backdoored Pro updates because its own build pipeline
was breached; the committer record looked entirely normal throughout, and nothing
here would have flagged it. Provenance monitoring answers one question well and 
is silent on the rest.

#### Licence and brand

The code is GPLv2 or later. Fork it, read it, ship it.

The OwnerTrail name, wordmark and logo are not covered by that licence and remain
the property of [Decodeinfy](https://decodeinfy.in). A fork is welcome; calling 
it OwnerTrail is not.

### External services

This plugin contacts three wordpress.org services to do its work. The only information
sent to them is the slug of each installed plugin, plus its version number for the
checksum service (and, for the WordPress core check, your WordPress version and 
language).

 1. **wordpress.org Plugin Information API** — `https://api.wordpress.org/plugins/info/
    1.2/`. Used to read each plugin’s listed author, contributors, last update date,
    and install count. A plugin slug is sent with each request. Terms: https://wordpress.
    org/about/privacy/ Privacy: https://wordpress.org/about/privacy/
 2. **wordpress.org Plugin SVN repository** — `https://plugins.svn.wordpress.org/`.
    Used to read the public commit history for each plugin, which is how committer 
    changes are detected. A plugin slug is sent with each request. Terms: https://wordpress.
    org/about/privacy/ Privacy: https://wordpress.org/about/privacy/
 3. **wordpress.org plugin checksums** — `https://downloads.wordpress.org/plugin-checksums/`.
    Used by the daily code check to read the official fingerprint of every file in 
    each directory plugin’s installed version. A plugin slug and version number are
    sent with each request. The WordPress core fingerprints come from `https://api.
    wordpress.org/core/checksums/1.0/` (the same service as item 1), with your WordPress
    version and language sent. No file contents ever leave your site: files are compared
    on your own server. Terms: https://wordpress.org/about/privacy/ Privacy: https://
    wordpress.org/about/privacy/

#### Email digest

This plugin can also email you when it finds something. This is **off by default**.
Turning on „Email alerts“ on the OwnerTrail Settings screen makes your site email
plugin findings — including plugin slugs, severities, finding descriptions, and 
your site’s name — to the address you configure there (or, if that is blank, your
site’s administration email): serious findings within the hour, at most one email
an hour, plus a daily digest. A separate **Weekly summary** setting, also off by
default, sends a short all-clear every Monday morning with plugin counts and updates
waiting. The first-run panel on the Overview screen offers a one-click „Email me
when something needs attention“, which turns on the same „Email alerts“ setting.
All of this is sent using your own site’s outgoing mail (`wp_mail()`); it is not
a wordpress.org service and does not involve any other third party.

Nothing else leaves your site. There is no telemetry, no analytics, and no tracking
of any kind beyond what is described above.

## Obrázky

[⌊Your site at a glance: every plugin checked, and one click to allow code changes
only over FTP.⌉⌊Your site at a glance: every plugin checked, and one click to allow
code changes only over FTP.⌉[

Your site at a glance: every plugin checked, and one click to allow code changes
only over FTP.

[⌊A plugin's page: its facts, its findings, and everyone who has committed to it.⌉⌊
A plugin's page: its facts, its findings, and everyone who has committed to it.⌉[

A plugin’s page: its facts, its findings, and everyone who has committed to it.

[⌊The Code screen: Code lock, the plugins that can get around it, who can change
the site, and every part of the site checked against wordpress.org.⌉⌊The Code screen:
Code lock, the plugins that can get around it, who can change the site, and every
part of the site checked against wordpress.org.⌉[

The Code screen: Code lock, the plugins that can get around it, who can change the
site, and every part of the site checked against wordpress.org.

[⌊Settings: email alerts, the areas open to change, and the site owners.⌉⌊Settings:
email alerts, the areas open to change, and the site owners.⌉[

Settings: email alerts, the areas open to change, and the site owners.

[⌊The dashboard widget's all-clear.⌉⌊The dashboard widget's all-clear.⌉[

The dashboard widget’s all-clear.

[⌊Scan now checks one plugin at a time, with a progress bar.⌉⌊Scan now checks one
plugin at a time, with a progress bar.⌉[

Scan now checks one plugin at a time, with a progress bar.

## Inštalácia

 1. Install through Plugins > Add New, or upload the folder to `/wp-content/plugins/`.
 2. Activate it. Activation makes no network request and takes well under a second.
 3. Open **OwnerTrail** in the admin menu. The first scan runs in the background and
    builds a committer baseline for every installed plugin, ten at a time.
 4. Nothing is reported on that first pass – a baseline has nothing to compare against
    yet. Findings appear when something changes afterwards.

Optionally, turn on the email digest under OwnerTrail > Settings. It is off by default
and sends nothing until you save a valid address.

## Časté otázky

### Where did the plugin and theme editors go?

OwnerTrail locks them on activation (see Code lock). A site owner can unlock them
for an hour on OwnerTrail > Code, or deactivate OwnerTrail to remove every lock.

### I can no longer install plugins from the admin.

„Only allow code changes over FTP“ is on. A site owner can unlock for an hour on
OwnerTrail > Code, or choose „Lock only the editors“ to allow installs again.

### How do I check who owns a WordPress plugin?

Manually: open the plugin’s page on WordPress.org and read the listed author and
the contributor list, then open its Development tab and read the SVN log to see 
which usernames have committed. Compare that against what you recorded last time.
There is no notification when any of it changes, which is the gap this plugin fills–
it takes that snapshot for every plugin you have installed, re-reads it daily, and
tells you only when something differs.

### How do I know if a WordPress plugin has changed hands?

The listed author changes, or contributors are added and removed, or an unfamiliar
username starts committing. Any of those can be legitimate – plugins are sold and
maintainers hand over all the time. The problem is that none of them are announced,
so you find out months later or not at all.

### How is this different from Wordfence, Patchstack or Sucuri?

They detect known vulnerabilities and malware signatures, which means something 
harmful has already been written and catalogued. This detects the trust-boundary
event – an ownership transfer, a new committer – that usually comes first. Different
layer, different failure mode. Run both.

### Does a new committer mean the plugin is compromised?

No. Most ownership changes are entirely legitimate. The point is that you get to
look, decide, and acknowledge, instead of finding out later.

### Does it slow my site down?

Scanning runs on a background schedule, ten plugins at a time by default, and never
on a front-end page load. Nothing runs for your visitors.

### Why does my premium plugin show as „not monitorable“?

Plugins distributed outside wordpress.org have no public commit history, so ownership
changes cannot be detected. Showing that honestly is more useful than showing a 
passing grade that means nothing.

### WP-Cron does not run reliably on my site.

Use the Scan now button, or set up a real server cron calling wp-cron.php. The Settings
screen shows when the last full scan completed.

### What happens on a multisite network if I uninstall this on one site?

Uninstalling cleans up the current site only: its stored plugin state, events, and
settings. On a network with per-site activation, other subsites‘ OwnerTrail data
is left behind.

## Recenzie

Pre tento plugin nie sú žiadne recenzie.

## Prispievatelia a vývojári

“OwnerTrail – Ownership & Supply Chain Monitor” je softvér s otvoreným zdrojovým
kódom. Do tohto pluginu prispeli nasledujúci ľudia.

Prispievatelia

 *   [ Kaustav Sengupta ](https://profiles.wordpress.org/kaustav790/)

[Preložiť „OwnerTrail – Ownership & Supply Chain Monitor“ do vašho jazyka.](https://translate.wordpress.org/projects/wp-plugins/ownertrail)

### Máte záujem o vývoj?

[ Prehľadávajte zdrojový kód](https://plugins.trac.wordpress.org/browser/ownertrail/),
preskúmajte [SVN repozitár](https://plugins.svn.wordpress.org/ownertrail/), alebo
sa prihláste na odber [vývojárskeho logu](https://plugins.trac.wordpress.org/log/ownertrail/)
cez [RSS](https://plugins.trac.wordpress.org/log/ownertrail/?limit=100&mode=stop_on_copy&format=rss).

## Zoznam zmien

#### 1.2.0

 * New: „Your site at a glance“, a first-run report with next steps and one-click
   email alerts.
 * New: the dashboard widget leads with the week’s all-clear.
 * New: optional weekly summary email (off by default).
 * New: serious findings are emailed within the hour when email alerts are on.
 * New: Scan now shows a progress bar and checks one plugin at a time.
 * New: Code lock. The built-in code editors are locked on activation; one click
   also stops plugin and theme uploads, installs and deletes from the admin. Only
   a site owner can unlock, for an hour at a time.
 * New: the code check also covers must-use plugins, drop-ins, loose PHP in wp-content
   and the site’s configuration files, and lists the plugins that can change code
   despite Code lock.
 * New: daily code integrity check. WordPress core and every directory plugin are
   compared with wordpress.org’s official file fingerprints; themes and other plugins
   with the copy OwnerTrail first saw; PHP files in uploads are flagged. A change
   is named by file on the new Code screen and, outside the areas you open to change,
   emailed within the hour.
 * New: a plugin wordpress.org has closed is flagged with the date and reason, even
   when it was closed before OwnerTrail was installed (it was shown as „not monitorable“
   before).
 * New: when a plugin changes hands or is closed and WordPress would update it by
   itself, its page offers one click to turn auto-updates off, and the urgent email
   says so.
 * New: when email alerts are on, the owners are emailed if OwnerTrail is switched
   off: who did it and when.
 * Fix: a plugin removed since the last scan no longer counts in the Scan now progress
   or stays on the Code screen.
 * Fix: „findings to review“ no longer counts plugins that simply cannot be checked.
 * New: beside a serious finding, a short note on what OwnerTrail Pro would have
   done about it (only while Pro is not installed; dismissible), and a line in the
   weekly summary when there is something to count.
 * New: a code finding whose files are later put back as they were says so („Since
   put back as it was“), and still waits for you to acknowledge it.
 * Fix: editing a file again while an earlier change to it is still unacknowledged
   is now a new finding, not a silent repeat.
 * Fix: uninstalling now also removes the per-user settings OwnerTrail stores.
 * Fix: Hello Dolly, which ships with WordPress as hello.php, is read under its 
   wordpress.org name, so its ownership is monitored instead of shown as „cannot
   be checked“.

#### 1.0.0

 * Initial release.

## Meta

 *  Verzia **1.2.0**
 *  Posledná aktualizácia **Pred 1 deň**
 *  Aktívne inštalácie **Menej než 10**
 *  Verzia WordPress ** 6.2 alebo novšia **
 *  Testované do verzie **7.1.3**
 *  Verzia PHP ** 7.4 alebo novšia **
 *  Jazyk
 * [English (US)](https://wordpress.org/plugins/ownertrail/)
 * Značky
 * [abandoned plugins](https://sk.wordpress.org/plugins/tags/abandoned-plugins/)
   [monitoring](https://sk.wordpress.org/plugins/tags/monitoring/)[ownership](https://sk.wordpress.org/plugins/tags/ownership/)
   [plugin security](https://sk.wordpress.org/plugins/tags/plugin-security/)[supply chain](https://sk.wordpress.org/plugins/tags/supply-chain/)
 *  [Rozšírené zobrazenie](https://sk.wordpress.org/plugins/ownertrail/advanced/)

## Hodnotenia

Zatiaľ neboli odoslané žiadne recenzie.

[Your review](https://wordpress.org/support/plugin/ownertrail/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/ownertrail/reviews/)

## Prispievatelia

 *   [ Kaustav Sengupta ](https://profiles.wordpress.org/kaustav790/)

## Podpora

Máte čo povedať? Potrebujete pomoc?

 [Zobraziť fórum podpory](https://wordpress.org/support/plugin/ownertrail/)