Each plugin submitted to woocommerce.com store has to pass their malware detection which is just php-malware-finder with some custom YARA rules.

You can easily check your plugin violations with following command:

docker run --rm $(pwd):/data ghcr.io/jvoisin/php-malware-finder

Custom rules from Automattic can be found in their GitHub repository1.


  1. https://github.com/Automattic/php-malware-finder â†Šī¸Ž