WordPress has formalized a new effort called the Core Security Initiative, a response to a sharp, sustained rise in vulnerability reports that the project says AI tools are largely driving.

What happened

Automattic engineer Rudy Faile announced the initiative on the Making WordPress Secure blog on August 28. He wrote that the project has seen “a substantial increase in the volume of incoming security reports” over the past year, much of it from frontier AI models that can now analyze code for vulnerabilities far faster than before. WordPress’s own numbers back that up: reports through its HackerOne bug bounty program held at roughly 20 to 30 a month for a decade, then jumped to 450 a month by July 2026, a trend we covered as it happened.

The initiative organizes the response around three parts. The first is a tighter, more automated security release process with better end-to-end testing, so fixes ship more reliably. The second is adding more team members and volunteers to clear the backlog of open reports down toward zero. The third is using AI-assisted scanning to find vulnerabilities proactively, before outside researchers or attackers do.

Faile framed the surge as a good problem: more scrutiny makes WordPress safer, but it means the security team has to scale how it triages, validates, and resolves what comes in. The announcement doesn’t name a lead for the effort or set a timeline, and it follows a run of unusually frequent core security releases this year.

What this means for your site

The initiative itself doesn’t require you to do anything today. But it signals WordPress core will likely keep shipping security releases more often than in past years. Keep automatic background updates turned on, and don’t delay when a security release lands.


End of article