
Originally Posted by
Jeffro
Based on what I see here, this is a bad way of handling the situation. You should be told just as WordPress does explicitly what the security implications are and if possible, a fix to those security concerns. Instead, you've been told that he said she said and the plugin has security concerns. If the plugin truly has a security vulnerability then it's good that it was taken down but to not tell the plugin author what the vulnerability is or what to look for is pretty bad.