Usually, the service distributing JavaScript is expected to ensure that the site is secure. However, any compromise on the service impacts thousands of websites using the code. In the case of WordPress, supply chain attacks become easier because a single hack can attack numerous WordPress plugins simultaneously.