Skip to content

How to deal with abandoned and closed WordPress plugins

Security1 min readFixes 2 checks wp-plugin-closed, wp-plugin-abandoned

A plugin without updates for two years, or one closed on wordpress.org, will not receive security fixes. Replace it before it becomes the way in.

Step by step, with screenshots: Abandoned and closed WordPress plugins: how to find safe replacements →

Check your own site

Runs these 2 checks and the other 185, free, in about 45 seconds.

What a passing site looks like

  • No detected plugin has been closed on wordpress.orgfail · −6 ptseffort M
  • Every detected plugin has a recent updatewarning · −1.5 ptseffort M

1. Plugins closed on wordpress.org

Why it matters. wordpress.org closes plugins for unfixed security issues or guideline violations. A closed plugin gets no updates and often has a known vulnerability.

How to fix it.
  1. Replace the plugin now; the reason shown by wordpress.org tells you how urgent it is.
  2. Until then, keep the site behind a firewall plugin and check the vulnerability databases for the plugin name.

2. Abandoned plugins

Why it matters. A plugin nobody maintains will not get security fixes and eventually breaks with a WordPress update. Two years without a release is the usual sign that it is abandoned.

How to fix it.
  1. Look for a maintained alternative with the same feature and replace the plugin; test on staging first.
  2. If it is essential and small, consider paying a developer to take it over.

Filed under WordPress & WooCommerce. Copy is generated from the same catalogue that scores every report, so what you read here is what the report says.