With great power comes great responsibility. Recently a WordPress plugin with as many as 100,000 installations was taken down from WordPress plugin repository due to a severe vulnerability.
Source: LXer – Contact Form 7 Datepicker Taken down from WordPress Plugin Repository