
Refonte
La Refonte insights
Understand GPL licensing for WordPress plugins, distinguish redistribution from modified files, and check the source, updates and security before installation.


Refonte

WordPress

SEO
A WordPress GPL plugin is an extension distributed under the GNU General Public License or a compatible licence. WordPress core is released under GPLv2 or later. The WordPress project regards plugins and themes derived from its code as inheriting this licence, while recognising some legal interpretation around what constitutes a derivative work.
The GPL protects the freedom to run, study, modify and redistribute software. 'Free software' does not necessarily mean free of charge: the Free Software Foundation confirms that copies may be sold. Redistribution must comply with licensing and corresponding-source requirements.
An SME must therefore separate two questions. Does the licence permit the intended use? Is the received file authentic, maintained and safe? A positive answer to the first proves nothing about the second. Trademarks, cloud accounts, API keys, updates and support services may also have separate terms.
GPLv2+
WordPress core licence according to WordPress.org
4 freedoms
Run, study, modify and redistribute free software
1 review
Initial submission manually reviewed before entering the WordPress.org directory
0 warranty
The GPL guarantees no support, updates or security
The GPL permits charging for a software copy. It chiefly requires recipients to retain the freedoms granted by the licence. A publisher can therefore sell a plugin while licensing its code under the GPL, and charge separately for support, documentation, updates, hosted services or server-side features.
A licence key does not automatically make code proprietary. It may control updates or a commercial API. Conversely, removing a check from a file grants no right to a trademark, customer account or external service. Read the plugin licence, included-resource notices and service terms separately.
The real cost of a third-party channel lies in operation: who verifies the ZIP's origin, reports releases, tests compatibility and responds to vulnerabilities? If nobody owns these tasks, a low price merely transfers work to your team. Documented WordPress maintenance must assign them.
| Criterion | Third-party redistributed file | Author's channel or WordPress.org |
|---|---|---|
| Right to copy | Possible when the licence and obligations are respected | Provided under the published licence |
| Provenance | Must be demonstrated by the distributor | Identified author or repository |
| Updates | Depend on the third party or manual monitoring | Channel stated by the author or WordPress.org |
| Support | Variable; check the contract | According to the author's offer |
| ZIP integrity | Difficult to compare without a published reference | Reference file provided directly |
| Trademarks and services | GPL does not automatically grant trademarks, keys or APIs | Access defined by the author and its terms |
| Operational risk | Harder to assign and track | Responsible party and correction channel identifiable |

Étape 1
Read the plugin header, licence file and notices for included libraries. Establish who built the ZIP and answers for changes. A GPL label without an author or history is insufficient.
Étape 2
Compare version number, date, PHP and WordPress requirements with the author's page. Search security notices and any directory closure. A difference does not prove infection, but needs an explanation.
Étape 3
Diff the redistribution against an archive obtained from the author. Inspect added files, network calls, created accounts and scheduled tasks. Functions such as eval() or base64_decode() merit review, but alone do not prove malware.
Étape 4
Use several scanning engines if policy permits, then install on a copy containing no real personal data. Check errors, outbound requests, new administrators, cron tasks and modified files. A clean scan is not a guarantee.
Étape 5
Decide who monitors versions, the response time for an alert and how to restore the previous version. WordPress supports automatic updates, but a third-party channel may not. Back up and test before sensitive deployment.
Begin with WordPress.org or the author's site. WordPress.org manually reviews the initial submission and requires a GPL-compatible licence. This reduces uncertainty around identity and distribution without guaranteeing that no vulnerability will arise. Developers remain responsible for their code, and the directory may close a plugin after a security report.
For premium extensions, buy from the publisher or an explicitly authorised reseller if you want its update channel and support. Third-party redistribution may comply with the GPL, but should explain provenance, modifications, licensing duties and correction process. Avoid catalogues hiding distributor identity or promising access to services they cannot provide.
Agencies and freelance teams should maintain a register of name, slug, author, source URL, version, licence, last review, owner, update method and removal procedure. This protects clients and speeds responses to security notices. Our WordPress team uses this inventory for audits and maintenance.
Security audits, extension inventories and proactive maintenance reduce risks from undocumented third-party files.
Last updated: 11 August 2026
Keep exploring



A project in mind?
Start with a free audit grounded in your goals, website and data.
Discutons de votre projet
30 min · Google Meet
Choisissez le créneau qui vous convient dans notre calendrier. On analyse votre situation avant l’appel pour aller droit au but.
Finding available times...