Abandoned WordPress Plugins: How to Spot Them and What to Do

An unmaintained plugin does not announce itself. It just sits there, working fine, until a vulnerability is found and never patched. Here is how to recognise an abandoned plugin and replace it before it becomes the way in.

By Nathan Cross, Co-Founder, Network & Security Engineering·

What abandoned WordPress plugins actually are

Abandoned WordPress plugins are plugins whose developer has stopped maintaining them: no bug fixes, no compatibility updates, and crucially no security patches. The plugin usually keeps working, which is exactly the problem. Nothing breaks, so nobody notices, and the code quietly drifts further behind current WordPress and PHP versions.

This matters because of where WordPress risk actually lives. Plugins account for roughly 96% of WordPress vulnerabilities; only a handful are ever in core (Patchstack). The platform itself is well looked after. The danger is almost always in the third-party code you bolted on, and an abandoned plugin is third-party code with nobody minding it.

The volume keeps climbing, too. Patchstack recorded nearly 8,000 new WordPress vulnerabilities in 2024, about a 34% rise on the year before (Patchstack, via SecurityWeek). When a new flaw is found in a maintained plugin, a patch ships and you update. When it is found in an abandoned one, there is no patch coming. You are left running known-vulnerable code with no fix on the horizon.

Why an abandoned plugin is a live security risk

An abandoned plugin is not dangerous because it is old. It is dangerous because attackers know exactly which versions are exploitable, and those versions never change. Once a vulnerability for a specific plugin version is published, automated scanners sweep the web looking for sites still running it. A maintained plugin closes that window with an update within days. An abandoned one leaves it open indefinitely.

These attacks are not hand-picked. They are bulk, automated, and they hit small businesses hardest. In Verizon's 2025 DBIR, ransomware or extortion appeared in 88% of breaches at small and medium businesses, versus 39% at larger organizations (Verizon 2025 DBIR). A neglected plugin on a small-business site is precisely the kind of soft target that volume-driven attacks are built to find.

The frustrating part is that the warning signs are usually visible long before anything goes wrong. You just have to know where to look.

How to spot abandoned WordPress plugins

You can assess most plugins in a couple of minutes from the WordPress.org plugin directory and your own dashboard. No single signal is conclusive, but several together paint a clear picture.

  • Last updated date: open the plugin's page on WordPress.org and check "Last updated". If it has been more than a year, treat it as a warning sign. More than two years, treat it as abandoned until proven otherwise.
  • "Tested up to" version: if the plugin has not been tested against a recent WordPress release, the developer has not touched it through several core updates.
  • Closed for review: the most serious flag. If WordPress.org shows the plugin has been closed or removed from the directory, you cannot install or update it any more, and it was often pulled for an unfixed security issue. Existing installs keep running, which is the trap.
  • Support forum activity: a wall of unanswered support threads going back months means nobody is home.
  • Active installs trending down: a once-popular plugin shedding installs often signals that users have already moved on for a reason.
  • Developer silence: no changelog entries, no response to compatibility reports, a website or company that has gone dark.

What to do about it

Once you have flagged a plugin, work through it in order rather than panic-deleting. The goal is to remove the risk without breaking your site.

First, decide whether you still need it. A surprising number of abandoned plugins are doing a job that core WordPress, your theme, or a feature you already pay for now handles natively. If you can delete it outright, that is the cleanest fix. Deactivating is not enough on its own, because deactivated plugin files still sit on the server and can still be exploited; remove the files entirely.

If you still need the function, find a maintained replacement. Look for an actively updated plugin with a recent "Last updated" date, a large and stable install base, and a responsive support forum. Migrate carefully on a staging copy if you can, test, then remove the old plugin.

If you genuinely cannot replace it right now, treat it as a known risk: document it, restrict it where possible, and put a date in the calendar to revisit. Running known-vulnerable code should always be a temporary, deliberate decision, never the default you forgot about.

Catching abandoned plugins before they bite

Auditing every plugin by hand is fine once. The hard part is doing it consistently, across every site, forever, especially when a plugin can be perfectly healthy today and pulled from the directory tomorrow.

A free BadgerScan external scan reads what is publicly detectable from the outside, including known CVEs for versions it can see, and our WordPress vulnerability scanner checks publicly-known plugin flaws. To see the exact plugin and theme versions installed on your site, plus whether any have been abandoned or pulled for review, the read-only Pro plugin scans from the inside and flags abandoned plugins directly. It is the same scanner: inside and outside findings fuse into one plain-English grade and one fix-list. The plugin is read-only: it reads versions and configuration, it never penetration-tests your site.

For the bigger picture on why plugins dominate WordPress risk, see our deep dive on WordPress plugin vulnerabilities, and for the wider hardening checklist, the WordPress security guide.

Find out if you are running abandoned plugins

Run a free BadgerScan to see what is exposed from the outside, then add the read-only Pro plugin to see the exact plugin versions inside your site and get every abandoned or pulled plugin flagged in one plain-English fix-list.

Run a free security scan

Frequently asked questions

Is a plugin abandoned just because it has not been updated in a while?

Not necessarily, but it is a strong warning sign. Some simple, stable plugins genuinely need few updates. Weigh the last-updated date alongside other signals: whether it was tested against a recent WordPress version, whether the support forum gets answered, and especially whether it has been closed for review on WordPress.org. If several signals point the same way, treat it as abandoned.

What does "closed for review" mean on WordPress.org?

It means WordPress.org has removed the plugin from the directory, so you can no longer install or update it. Plugins are often closed because of an unpatched security issue or a guideline violation. The catch is that existing installs keep running the vulnerable code with no update path, so a closed plugin already on your site is one of the more urgent things to replace.

Is deactivating an abandoned plugin enough?

No. A deactivated plugin still has its files on your server, and some vulnerabilities can be triggered even when the plugin is not active. If you no longer need the plugin, delete it completely so the files are gone. If you still need its function, replace it with a maintained alternative rather than leaving the deactivated files in place.

How do I find a safe replacement plugin?

Look for an actively maintained plugin with a recent last-updated date, a large and stable number of active installs, compatibility with the current WordPress version, and a support forum where the developer actually replies. Test the replacement on a staging copy where you can, confirm it covers what you need, then remove the old plugin entirely.

Keep reading

Sources

  1. Patchstack, State of WordPress Security
  2. SecurityWeek, 8,000 New WordPress Vulnerabilities Reported in 2024
  3. Verizon, 2025 Data Breach Investigations Report

More from CyberBadger

BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.

Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.