If WordPress eventually has leadership that doesn’t treat the real security issues with WordPress plugins as being “hypothetical” as they currently do, there is a lot that could be done to improve the situation. One area would be to look at ways to make it easier to inform developers of security issues in their plugins that are hosted on the

