Plugins Need Updates: How to Fix Outdated WordPress Plugins
Your BadgerScan scan found one or more WordPress plugins running an older version than what is available. Outdated plugins are the single most common way WordPress sites get compromised, but the fix is quick and safe when you follow the right order. Here is how to update everything correctly and keep it that way.
One free scan, no login. This check runs alongside DNS, email, TLS, headers, exposed files and known CVEs.
What this finding means
Every plugin on your WordPress site is a small piece of software written by someone else. Like any software, plugins get updated over time to add features and, importantly, to patch security holes. When BadgerScan reports that plugins need updates, it means the outside view of your site shows one or more plugins running an older version than the latest one published in the WordPress.org directory.
This matters because when a plugin author fixes a security flaw, the fix and the details of the flaw usually become public at the same time. Anyone can read the changelog and see exactly what was wrong in the older version. On a popular plugin, a working exploit for that flaw often appears within days. Until you install the update, your site is still running the version with the known hole.
BadgerScan is a passive, read-only scanner, so it only looks at what is publicly visible. It does not log into your site or change anything. This finding is a prompt to check your Plugins screen, where the exact list of what needs updating is waiting for you.
Why it is worth fixing
Outdated plugins are the leading cause of WordPress site compromises. That is simply where the easy openings are. Automated tools scan the web for sites still running plugin versions with published flaws, because those take no skill to exploit and a single script can check thousands of sites at once.
The good news is that this is one of the cheapest fixes in security. Updating a plugin usually takes a few clicks and a minute or two. Staying current closes the door before anyone tries the handle, and turning on automatic updates means most of this maintenance happens without you thinking about it.
How to fix it, step by step
Work through these steps in order. The most important rule is to back up your site before you update anything, so you can roll back cleanly if an update ever conflicts with your theme or another plugin. If you want to see the exact list first, you can also run the free scan and then head into your admin.
- Back up your site first. Use your host's backup tool or a backup plugin to save both your files and your database. Do not skip this step, even for a small update.
- Go to your WordPress admin and open
DashboardthenUpdates. This screen lists every plugin (and theme and core file) that has an update available in one place. - Select the plugins you want to update and click
Update Plugins. You can also update them individually from thePluginsscreen, where each outdated plugin shows an update notice with anupdate nowlink (WordPress.org, Managing Plugins). - After updating, load your site's home page and a couple of key pages, and log in to the admin, to confirm everything still works normally.
- Turn on automatic updates for plugins you trust. On the
Pluginsscreen, use theEnable auto-updateslink next to each plugin so future security fixes install on their own. - Remove any plugin you no longer use. Deactivate it, then delete it, so it cannot become an unpatched liability later.
Watch for abandoned plugins
Updating is not always enough. If a plugin has not received an update in two or more years, or it has been removed from the WordPress.org directory, it is effectively abandoned and will never get a security fix. Treat those plugins as a liability no matter how well they seem to work.
The safe move is to replace an abandoned plugin with a maintained alternative that does the same job, then delete the old one. Keeping your plugin list short and current is one of the core habits behind a hardened WordPress site (WordPress.org, Hardening WordPress). When you are done, run the free scan again to confirm the finding has cleared.
Check your plugins in under a minute
Run the free BadgerScan scan to see the outside view of your WordPress site, including whether your plugins are up to date. No login and nothing to install. You get a plain-language report you can act on right away.
Run a free security scanFrequently asked questions
Will updating a plugin break my site?
It rarely does, and that is exactly why you back up first. Most updates are small and safe. If an update ever conflicts with your theme or another plugin, you restore the backup, and you are back where you started with nothing lost.
Should I turn on automatic updates for every plugin?
Turn them on for plugins you trust and that are actively maintained, since automatic security fixes are worth far more than the small risk of a surprise change. For a critical, custom, or heavily customized plugin you may prefer to update it by hand so you can test right after.
What do I do about a plugin that has no update available but is very old?
Check when it was last updated. If it has gone two or more years without an update, or it has been pulled from the WordPress.org directory, it is abandoned and will never be patched. Replace it with a maintained alternative and delete the old one.
How do I confirm the fix worked?
Open Dashboard then Updates in your admin and make sure no plugins are listed as needing an update. Then run the free BadgerScan scan again and check that the plugins finding no longer appears in your results.
Sources
More from CyberBadger
BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.
Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.