# Plugin and theme component signing

**URL:** <https://meta.discourse.org/t/plugin-and-theme-component-signing/374817>\
**Category:** Feature\
**Created:** [July 18, 2025, 3:59pm UTC](https://meta.discourse.org/t/plugin-and-theme-component-signing/374817 "2025-07-18T15:59:25Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)\
**Post date:** [July 18, 2025, 7:53pm UTC](https://meta.discourse.org/t/plugin-and-theme-component-signing/374817/4 "2025-07-18T19:53:05Z")

</div>

I think this makes great sense. We have SRI for Javascript, MS Authenticode for Windows.  
There have been a lot of supply chain attacks on for instance NPM and RubyGems.

The only thing that worries me is that there would be a barrier for people to get their plugin or theme component “accepted”, like how Microsoft Smartscreen prevents users from running less known software from single developers.

---

_[View the full topic](https://meta.discourse.org/t/plugin-and-theme-component-signing/374817)._
