← Back to speaking

We Built an AI That Finds Vulnerabilities in Plugins. So Can Everyone Else.

Conference TalkWP Future Conclave 2026Kozhikode, Kerala, India
  • AI Security
  • Vulnerability Intelligence
  • Software Supply Chain
  • Open Source Security
  • GRC

Delivered remotely to the venue in Kozhikode.

A field report from building a system that hunts vulnerability variants in WordPress plugins: what it actually was (a retrieval layer over a corpus of real vulnerabilities and proof-of-concepts, structured prompting, adversarial review, and a human at the end), what worked, and what it never managed to do. The honest conclusion is the uncomfortable one — nothing in that stack is exclusive, so anyone can build it, attackers included.

That changes which question matters. With more than 4,100 CVEs published in the WordPress ecosystem in 2024 alone, discovery has stopped being the bottleneck; response is. The talk reframes the problem around three clocks — how fast you know, how fast you decide, and how fast you ship — and lays out five practices that move them: know what you ship, keep a door open for reporters, watch your dependencies, declare a support period, and be able to release quickly.

It closes on why this stops being optional: the EU Cyber Resilience Act’s reporting duties, with their 24-hour, 72-hour and 14-day clocks, and the way European rules travel through contracts into markets that never voted on them.