• This plugin was randomly installed and activated on every single WordPress site hosted at Siteground. Siteground customers did not consent to the installation of this plugin, nor was the action disclosed by Siteground. The software was added automatically – with AI connectivity – which means it has the ability to perform a stunning amount of damage to individual sites, shared servers, and the Siteground ecosystem as a whole.

    Considering AI was not invented by Siteground, that also means it has the ability to contact remote servers controlled by third-parties. The plugin obnoxiously inserts itself into every page on the frontend AND admin panel of every site for administrators – breaking layouts, accessibility, and causing undue hardship to every customer who has to manually purge this MALWARE.

    All of this information is factual. Now, read how Cisco – an enterprise leader in IT – says the following classes of malware are DEFINED:

    Viruses

    A computer virus is a type of malware that propagates by inserting a copy of itself into and becoming part of another program. It spreads from one computer to another, leaving infections as it travels. Viruses can range in severity from causing mildly annoying effects to damaging data or software and causing denial-of-service (DoS) conditions. […] Normally, the host program keeps functioning after it is infected by the virus. However, some viruses overwrite other programs with copies of themselves, which destroys the host program altogether. Viruses spread when the software or document they are attached to is transferred from one computer to another using the network, a disk, file sharing, or infected email attachments.

    Cisco

    Let’s see if any of that applies to this plugin, shall we? Here we go:

    • Propagates by inserting a copy of itself and becoming part of another program? ✅ Yes.
    • Did it spread from one computer/server to another, leaving infections as it went? ✅ Yes.
    • Did it cause mildly annoying effects, damage data, or cause a denial-of-service? ✅ Yes.
    • Does the AI in this plugin have the ability to overwrite or destroy other programs? ✅ Yes.

    Okay, so the plugin – at the very least – loosely fits the definition of a virus. Let’s move on to the next one:

    Worms

    Computer worms are similar to viruses in that they replicate functional copies of themselves and can cause the same type of damage. In contrast to viruses, which require the spreading of an infected host file, worms are standalone software and do not require a host program or human help to propagate. To spread, worms either exploit a vulnerability on the target system or use some kind of social engineering to trick users into executing them. A worm enters a computer through a vulnerability in the system and takes advantage of file-transport or information-transport features on the system, allowing it to travel unaided. More advanced worms leverage encryption, wipers, and ransomware technologies to harm their targets.

    Cisco

    Okay, more specific… but let’s do the comparison, anyway:

    • Similar to a virus because it replicated itself and can cause the same type of damage? ✅ Yes.
    • Did the plugin run without requiring the host program or human help to propagate? ✅ Yes.
    • Did the plugin exploit a Siteground vulnerability or trick users into executing it? ✅ Yes.
    • Did the plugin take advantage of the system’s file-transport features to travel unaided? ✅ Yes.

    Not looking good. That said, we have more definitions to cover because it’s ✨Siteground✨ who will surely be allowed to continue this behavior:

    Trojans

    A Trojan is another type of malware named after the wooden horse that the Greeks used to infiltrate Troy. It is a harmful piece of software that looks legitimate. Users are typically tricked into loading and executing it on their systems. After it is activated, it can achieve any number of attacks on the host, from irritating the user (popping up windows or changing desktops) to damaging the host (deleting files, stealing data, or activating and spreading other malware, such as viruses). Trojans are also known to create backdoors to give malicious users access to the system. Unlike viruses and worms, Trojans do not reproduce by infecting other files nor do they self-replicate. Trojans must spread through user interaction such as opening an email attachment or downloading and running a file from the Internet.

    Cisco

    Let’s see if the good people of Sparta recognize this plugin:

    • Harmful piece of software that looks legitimate? — It certainly harmed some users. ✅ Yes.
    • Did Siteground trick users into loading and executing it on their systems? ✅ Yes.
    • Is the plugin’s AI able to achieve any number of attacks on the host after activating? ✅ Yes.
    • Does the plugin have the potential to give malicious users access to the system? ✅ Yes.
    • Does the plugin fit the Trojan definition of being unable to self-replicate? 🚫 No.

    Phew… close one — the plugin almost fit the definition of a Trojan there. Good thing it has the ability to self-replicate by infecting other files and systems autonomously.

    WORDPRESS — DO THE RIGHT THING AND REMOVE THIS PLUGIN FROM THE REPOSITORY. It provides NO value-added after Siteground customers run out of their sample credits. It’s an involuntary cash-grab that doesn’t benefit any WordPress users outside of Siteground’s ecosystem — and even the idea of it offering anything beneficial is highly questionable.

    Shame on you, Siteground.

Viewing 2 replies - 1 through 2 (of 2 total)
  • Hi @phvntom,

    We hear your frustration, and because your post makes a number of serious claims about the plugin and how it was introduced, we’d like to address them directly.

    All affected customers received advance email notifications about the upcoming AI Agent installation, and websites operating under our White Label functionality, where customers manage WordPress sites on behalf of their own clients, were proactively excluded from the rollout entirely. Additionally, any customer who reached out after receiving the notification and requested to opt out was excluded before the installation took place.

    As a managed hosting provider for WordPress, part of the service we provide is developing, integrating, and rolling out tools intended to make WordPress easier to use and manage. WordPress 7.0 introduced a standardized AI framework for the platform, and alongside that release, we enabled SiteGround AI Studio as the default AI connector and activated the SiteGround AI Agent for eligible customers.

    Our goal was to make those new capabilities immediately useful, without requiring customers to research, configure API keys, install additional plugins, or connect an AI provider themselves.

    We also want to be clear about the repeated characterization of the plugin as malicious – those descriptions are factually incorrect, and we’d like to address the technical points directly:

    • The plugin is a standard WordPress plugin. It is not a Must-Use (MU) plugin and can be deactivated or deleted from the WordPress dashboard at any time without affecting the hosting service.

    • It does not self-replicate, infect files, copy itself between websites or servers, or propagate autonomously. The installation was carried out by SiteGround’s engineering team as part of a managed-service rollout. That is fundamentally different from software spreading itself.

    • The plugin does not create a backdoor, exploit any vulnerability, or involve malicious code of any kind. It connects exclusively to AI Studio – SiteGround’s own AI service, included free across all hosting plans, and all communication is initiated by the user, never autonomously.

    • Its AI functionality does not independently modify websites. Site-management actions require and are initiated through user interaction with the AI Agent. Simply having the plugin installed does not result in AI activity. If the AI Assistant is never used, the plugin remains functionally inert. It does not invoke an AI model or transmit website content to AI services unless a logged-in administrator explicitly initiates a request.

    • The plugin is available at no additional cost and includes a free monthly allocation of 20,000 AI tokens, which automatically resets every month, allowing customers to explore and use its AI capabilities without requiring a paid subscription.

    • The presence of the plugin across multiple SiteGround-hosted websites is not evidence of replication or infection. It reflects a centrally managed deployment by the hosting provider.

    We also recognize that some customers would have preferred the plugin not to be pre-installed, and we have taken that feedback into account. If you experienced any layout or compatibility issues as a result, our support team is available 24/7 and will be happy to investigate and help.

    Customers are also able to deactivate or remove the plugin from their WordPress dashboard at any time should they decide not to use it, and for anyone who would prefer, our team will gladly remove it on their behalf.

    We trust the points above address the concerns raised and provide a clearer picture of how the plugin was introduced and how it works.

    Best regards,
    Svetoslav Vasev

    Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    Side note: I removed the forum topic. It’s a duplicate and the feedback is here where it belongs.

    I do want to weigh in on this part.

    WORDPRESS — DO THE RIGHT THING AND REMOVE THIS PLUGIN FROM THE REPOSITORY.

    The complaint is that the host provider installed this and activated it without consent on their customer’s WordPress installations. That’s not nice but nowhere in the Detailed Plugin Guidelines is that a concern for the WordPress Plugin Repository.

    I’m not putting in the link, links do not belong in reviews. You can look it up but don’t post a link.

    But! Fear not. It is a legitimate thing to leave a review when the developer does that with their plugin.

    • This is a Siteground plugin.
    • The host provider (also Sitegound) installed and activated this plugin without the users choosing to opt-in.
    • That was really not cool.
    • Thus these reviews are legitimate.

    Had another host provider done that, and people punished the developer and the developer had no connection at all to that host provider then all of those reviews would be removed. We don’t punish developers for what other people do with their code.

    Has more coffee, so good.

    In this case? Yeah. It’s all Siteground so… carry on.

    • This reply was modified 3 weeks, 5 days ago by Jan Dembowski. Reason: Grammar
Viewing 2 replies - 1 through 2 (of 2 total)

You must be logged in to reply to this review.