Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not click it until you verify it. A message claiming to be from WordPress is credible only after you check its complete sender domain, authentication details, destination links and requested action. The WordPress Security Team says it will never ask ordinary site administrators to install a plugin or theme or to disclose an administrator username and password. Those requests are strong signs of a scam.

First, identify who supposedly sent the message

Not every email mentioning WordPress comes from the WordPress project. Your hosting company, a plugin developer, WooCommerce or your own site can send legitimate notices from different domains. Apply the strict @wordpress.org and @wordpress.net checks only when the message claims to be from WordPress itself.

Check the complete sender address

Ignore the display name and logo. Expand the sender details and inspect the address after the @. For a WordPress-project message, the official guidance says the sender should use wordpress.org or wordpress.net. Look for the email authentication detail “Signed by: wordpress.org”. A lookalike domain, extra words before the real domain, spelling changes or a different top-level domain is not the same thing.

Understand lookalike domains

The official plugin directory is wordpress.org/plugins. A URL that merely contains the word “wordpress” is not official. For example, en-wordpress.org is a separate domain, not a WordPress.org subdomain. Localized WordPress.org sites can use subdomains, where a dot appears before wordpress.org.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect links without opening them

  1. Hover over each link on a computer, or press and hold it on a phone, without selecting it.
  2. Read the destination domain, not the text shown in the email. Watch for misspellings, extra words, deceptive subdomains and URL-shortening services.
  3. Do not sign in through the email. Type the known address yourself, use a trusted bookmark or open the WordPress dashboard directly.

A padlock or https only encrypts the connection; it does not prove that the site belongs to WordPress.

Look at what the email asks you to do

Requests that conflict with WordPress policy

In a December 4, 2023 warning, the WordPress Security Team stated: “The WordPress Security Team will never email you requesting that you install a plugin or theme on your site, and will never ask for an administrator username and password.” An unsolicited “security patch” plugin, emergency theme, administrator login or password request should therefore be treated as phishing.

Pressure is a warning sign

Threats that your site will be deleted, suspended or blacklisted unless you act immediately are designed to bypass verification. Stop, close the message and investigate through a trusted route instead of following its deadline.

Verify the claim independently

  1. Open your site’s dashboard by entering its address yourself and check updates, users, security notices and activity logs.
  2. Visit the known official WordPress news or security pages directly, or use the vendor’s established support portal, to look for the same announcement.
  3. For a hosting, plugin or WooCommerce notice, sign in through that provider’s normal website rather than the email link.
  4. If the message remains suspicious, report it to your email provider and preserve the original message and headers.

Legitimate WordPress emails that can look alarming

Plugin-release security reviews

The WordPress Developer Resources handbook describes an automated security-review workflow for plugin releases. Since June 2026, releases pass through a cooldown before distribution by the WordPress.org update API. If a release is blocked, all plugin committers can receive an email describing findings, risk scores and affected files or lines. This notice concerns contributors to that plugin, not an ordinary site administrator being told to install an emailed patch.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

WordPress also cautions that a high risk score measures risk, not malicious intent, and automated reviews can produce false positives.

Messages to plugin contributors

The Plugin Team may contact plugin support staff, owners and contributors from [email protected]. It does not directly email a plugin’s users with instructions to install a security plugin.

Unexpected password-reset messages

WordPress documentation explains that a reset email can be triggered whenever someone visits a site’s public password-reset page. Completing the reset still requires access to the relevant mailbox. As the documentation puts it, “Your password can be reset only by those who can read your email.” An unexpected reset message alone does not prove that the WordPress account was compromised. Do not use its link; check the account through a known route and secure the mailbox if necessary.

What to do with a suspected scam

  • Do not click, download, install or reply to the message.
  • Do not provide administrator credentials, recovery codes, payment details or other secrets.
  • Report the message using your email provider’s phishing or spam function.
  • Keep the original email and its full headers if your host, provider or an incident responder needs to examine it.
  • Change credentials only through a trusted, independently opened login page, and avoid reusing passwords.

An alarming email is not proof that your site was hacked

Investigate the website separately. WordPress.org’s hacked-site guidance lists independent indicators such as:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • search-engine blacklisting or malware warnings;
  • hosting suspension or a host’s abuse notification;
  • antivirus complaints from visitors;
  • reports that the site is attacking other systems;
  • unauthorized users, unfamiliar administrator accounts or other unexpected account activity;
  • unexplained redirects, altered pages, injected content or other visible changes.

Record what happened and when, contact the hosting provider and preserve relevant logs. Scanning is only one part of the investigation: application-based scanners inspect the site from inside WordPress, while remote crawlers inspect what is reachable from outside. WordPress documentation names Wordfence and Sucuri as examples of application-based tools, and VirusTotal and Sucuri SiteCheck as examples of remote resources. It does not establish that one is universally best, and a clean scan does not authenticate an email or guarantee that a site is safe.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Optional account hardening after verification

Two-factor authentication protects an account; it does not tell you whether a particular email is genuine. WordPress.org documents security keys, TOTP authenticator apps and backup codes for its own account.

Method Phishing resistance Practical considerations
Hardware security key Strong; WordPress.org says supported keys are not vulnerable to phishing attacks Compatibility varies by account and device. Keep multiple keys so one can be used if another is lost.
TOTP authenticator app Stronger than a password alone, but codes can still be entered into a phishing site Protect the phone and plan how you will restore access.
Backup codes Recovery method, not a routine sign-in defense Generate them in advance and store them securely. Losing the primary device or key without a backup can lock you out.

A USB security key such as a YubiKey can be a useful optional safeguard where the account supports it. It strengthens login protection but cannot validate an email’s sender or link.

Quick decision checklist

  • Sender: Does a WordPress-project claim use @wordpress.org or @wordpress.net, with “Signed by: wordpress.org”?
  • Destination: Does the actual link lead to the expected official or vendor domain?
  • Request: Is it asking for a plugin, theme, administrator password or urgent login? Stop if so.
  • Context: Are you a plugin contributor who could receive a release-review notice, or did someone simply trigger a password-reset page?
  • Independent evidence: Does the dashboard, host or official support site show the same issue?
  • Site symptoms: Are there concrete signs of compromise separate from the email?

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.