How to deal with abandoned and closed WordPress plugins
A plugin without updates for two years, or one closed on wordpress.org, will not receive security fixes. Replace it before it becomes the way in.
Step by step, with screenshots: Abandoned and closed WordPress plugins: how to find safe replacements →
Check your own site
Runs these 2 checks and the other 185, free, in about 45 seconds.
What a passing site looks like
- No detected plugin has been closed on wordpress.orgfail · −6 ptseffort M
- Every detected plugin has a recent updatewarning · −1.5 ptseffort M
1. Plugins closed on wordpress.org
Why it matters. wordpress.org closes plugins for unfixed security issues or guideline violations. A closed plugin gets no updates and often has a known vulnerability.
- Replace the plugin now; the reason shown by wordpress.org tells you how urgent it is.
- Until then, keep the site behind a firewall plugin and check the vulnerability databases for the plugin name.
2. Abandoned plugins
Why it matters. A plugin nobody maintains will not get security fixes and eventually breaks with a WordPress update. Two years without a release is the usual sign that it is abandoned.
- Look for a maintained alternative with the same feature and replace the plugin; test on staging first.
- If it is essential and small, consider paying a developer to take it over.