WordPress.org is introducing stricter requirements around AI-generated code disclosure, plugin ethics, and quality signals. For agencies managing multiple client sites, these changes redefine what responsible plugin vetting looks like, which plugins belong on a fleet, and how to set clear expectations with clients going forward.
WordPress.org’s plugin review team is moving toward requiring plugins to disclose when their code was substantially generated or assisted by AI tools. The standards also tighten expectations around licensing clarity, data handling declarations, and removal of deceptive patterns. Plugins that fail these requirements face closer scrutiny or rejection during the review process.
Yes. The directory’s review process is a baseline, not a comprehensive gate. Agencies running multiple client sites need their own vetting layer that checks for AI disclosure, declared third-party dependencies, and code-level red flags before any plugin reaches a fleet. The new standards give agencies sharper criteria to use in that internal review.
Run a structured audit: list every active plugin across the fleet, check each one for AI disclosure and maintenance status, and categorize plugins into replace, review further, or accept documented risk. The goal is not to remove everything at once but to make a documented, repeatable decision for each plugin under the new criteria.
Use the directory changes as an opportunity to share your agency’s plugin policy in plain terms: what you vet for, how clients request new plugins, and what happens if a plugin on their site fails a review. Clients with professional-tier relationships expect a clear answer to these questions. Raising the topic proactively positions the agency as the party in control of site quality.
The plugin review team has been signaling and implementing stricter standards, but the exact enforcement timeline and scope continue to evolve. Agencies should treat AI disclosure as a required check in their own vetting process regardless of where the directory’s formal policy lands, because the underlying risk of undisclosed AI-generated code is real whether or not the directory has formally rejected a plugin for it.
1,000 free credits. Just describe what you need.
See It In ActionNew to WPOS? Learn what WPOS is and how agencies use it to build and operate client WordPress sites with AI agents.
Part of our guide: WordPress Security for Agency Fleets.