← Back to Archive
[WP AUTOPSY]August 3, 2026

43.8% Of The WordPress Plugin Directory Is Dead. You Are Running It Anyway.

Reading Time: 13 minAnger:5/5

Someone finally did the boring work. WP Goldmine crawled the entire WordPress.org plugin directory — 60,257 plugins, install counts, ratings, last-updated dates, support-thread resolution rates, all pulled straight from WordPress.org's own API — and published the numbers on 1 August 2026. They framed it politely as a report on 'plugin opportunities,' because they're selling a newsletter to people who want to build replacements.

Read the same data as a site owner instead of an entrepreneur and it stops being an opportunity report. It's a coroner's inventory.

43.8% of the WordPress plugin directory has not shipped an update in two years. 39.4% has not shipped one in three.

The headline numbers, before the excuses start

Here is the staleness curve, measured across every plugin that reports an update date at all:

  • 6+ months since last update: 62.9% — 37,907 plugins
  • 12+ months: 53.6% — 32,324 plugins
  • 24+ months: 43.8% — 26,387 plugins
  • 36+ months: 39.4% — 23,737 plugins

Look at the shape of that, not just the size. The gap between 24 months and 36 months is tiny — 43.8% down to 39.4%. That tells you something specific and grim: plugins do not gently decay. They stop. Once a plugin has been silent for two years, it is almost never coming back. There is no long tail of slow maintainers. There is a cliff, and then a flat plain of corpses stretching to the horizon.

Twenty-six thousand plugins. All still listed. All still installable. All still one click away from the 'Add New Plugin' screen with a nice big blue Install Now button and absolutely nothing on that screen shouting the only fact that matters: nobody is home.

The directory is a shop where half the shelves are stocked by dead men

This is the part the ecosystem never says out loud. The WordPress plugin directory is presented to non-technical site owners as a curated app store. It looks like one. It has search, ratings, screenshots, install counts, categories, a big friendly button.

It is not an app store. There is no removal process for abandonment. There is no expiry date. There is no red banner. A plugin last touched in February 2018 sits in the same list, with the same install button, at the same visual weight, as one patched last Tuesday. The only warning you get is a small grey line of text — 'Last updated: 5 years ago' — which sits below the fold of the average user's attention span and is written in the same font as everything else.

Compare it to literally any other software distribution channel on earth. Apple culls. Google culls. npm at least shouts about deprecation. WordPress.org quietly keeps handing out expired medication because removing it would make the plugin count go down, and the plugin count is a marketing asset.

Abandonment scales inversely with size, which is exactly the wrong way round

Break it down by install band and the pattern is almost reassuring at first:

  • 1K–10K installs: 24.5% abandoned (1,236 of 5,047)
  • 10K–100K installs: 10.9% abandoned (198 of 1,809)
  • 100K–1M installs: 2.2% abandoned (9 of 402)
  • 1M+ installs: 0% abandoned (0 of 67)

The million-install club is fine. Great. Sixty-seven plugins are maintained. Now do the arithmetic that actually applies to your site: 207 plugins with more than 10,000 active installs each have gone two years or more without a single line of code changing.

Two hundred and seven plugins. Ten thousand sites minimum on each. That is a floor of two million WordPress installations running abandoned code — and that's the conservative floor, because 'Limit Login Attempts' alone carries 300,000+ installs and hasn't shipped since April 2023.

Sit with that one for a second, because it's the funniest and worst entry on the list.

A security plugin, abandoned, on 300,000 sites

The single most-installed abandoned plugin in the directory is a brute-force login protection plugin. Its job is security. Its last update was over three years ago. Its rating is 4.6 out of 5, because ratings measure how people felt in 2019, not whether the code still works in 2026.

That 4.6 is the most dangerous number on the entire page. Every abandoned plugin in the top ten has a rating between 3.5 and 4.8. The stars do not decay. They are a permanent monument to a plugin's best year, sitting directly above a dead last-updated date, and the average site owner reads the stars and ignores the date because that is how human beings read interfaces.

Here's the rest of the wall of shame, and note what kind of plugins these are:

  • Layout Grid Block — 200K+ installs, last updated Jul 2023. Layout. Structural. Rendering your pages.
  • WP Downgrade | Specific Core Version — 100K+ installs, May 2023. A plugin whose entire purpose is holding WordPress core back on an old version. Abandoned. Think about the compounding here.
  • AddQuicktag — 100K+, May 2021.
  • Easy Google Fonts — 100K+, Jul 2021. Still fetching third-party assets on 100,000 sites, unmaintained, in the post-GDPR-fine era.
  • PHP Code Widget — 80K+, Mar 2022. A plugin that exists to execute arbitrary PHP from a widget field. Unmaintained since 2022.
  • Invisible reCaptcha for WordPress — 80K+, Apr 2020. Spam protection, six years cold.
  • Contact Form 7 add confirm — 50K+, Feb 2018. Eight years. It is processing form submissions on fifty thousand websites and it was last touched during the first Trump administration.
  • OptionTree — 50K+, May 2019. Add From Server — 60K+, Dec 2020. Revision Control — 40K+, Apr 2018.

The pattern isn't 'boring little utilities nobody cares about.' The pattern is security, forms, fonts, file handling, code execution, and layout. The load-bearing walls. Nobody abandons the decorative stuff, because nobody installed the decorative stuff in the first place.

The bit nobody wants to say: abandoned isn't neutral, it's an inbound queue

To be fair to the researchers, they were careful. Their methodology explicitly states the rankings are objective measurements, not a security judgement of any listed plugin. Fine. Correct. Responsible.

I'm not a researcher, so I'll say the obvious thing instead.

An abandoned plugin is not code that stopped changing. It is code that stopped defending itself while the entire world around it kept moving.

PHP moved. WordPress core moved — REST API changes, block editor churn, sanitisation helpers deprecated, jQuery migrated, hooks retired. Browsers moved. TLS moved. Attack tooling moved a very long way, and it now includes automated scanners that read the plugin directory's own metadata, sort by installs, filter by last-updated date, and build target lists exactly like the one printed above. That report is free. So is the API it came from. The attackers have the same spreadsheet you do.

And when someone does find something in a plugin with 80,000 installs and no maintainer, there is no patch. There is no CVE response. There is no maintainer email that gets answered. The remediation advice for an abandoned plugin is always the same three words: delete it, urgently. Which is a hell of a thing to discover on a Friday about the plugin that renders your homepage layout.

Now the maintained plugins, which is somehow the more depressing list

You could read all of the above and conclude the fix is discipline: only install big, actively maintained plugins from serious companies. So let's test that theory against the second dataset — plugins with 10,000+ installs and a rating of 3.0 or below from 20+ reviews. All of these are actively maintained. Most shipped an update within the last month.

  • AI Agent by SiteGround — 1M+ installs, 1.4/5, updated Jul 2026. One point four. From a major host. On a million sites.
  • Image Optimization (Compress Images) — 1M+ installs, 1.7/5, Jul 2026.
  • WooCommerce PayPal Payments — 800K+, 2.8/5. This is how people take money.
  • Google for WooCommerce — 800K+, 2.7/5.
  • Web Accessibility (formerly Ally) — 500K+, 2.9/5. Elementor's own accessibility plugin, incidentally.
  • WooCommerce Tax / Shipping — 500K+, 2.0/5. Tax. Two out of five.
  • WooCommerce Legacy REST API — 400K+, 1.5/5, last updated Jan 2025.
  • Meta pixel — 400K+, 2.7/5. Meta for WooCommerce — 400K+, 2.2/5. Pinterest for WooCommerce — 300K+, 2.3/5. TikTok — 200K+, 1.8/5.
  • Gutenberg — 300K+ installs, 2.1/5. The future of WordPress editing, rated worse than the average airport hotel.
  • WooCommerce Square — 80K+, 2.1/5. Razorpay — 100K+, 2.5/5. Klaviyo — 100K+, 2.8/5.

Read that list again and notice who wrote most of it. These aren't hobbyist plugins from a bloke in a bedsit. These are first-party integrations from Automattic, Meta, Google, TikTok, Pinterest, Klaviyo, Square, SiteGround, Elementor. The professionals. The ones with revenue, staff, and roadmaps.

So your two options in the WordPress plugin market are: unmaintained code with good old ratings, or maintained code with terrible current ratings. Pick a lane. Both lanes end in a support ticket.

The WooCommerce pattern is not a coincidence

Count the WooCommerce entries in that low-rating list. Payments, tax, shipping, Google, Meta, Pinterest, Square, Razorpay, Analytics. Nine of the twenty worst-rated large plugins are the plumbing of WooCommerce commerce.

This is what happens when a platform's monetisation strategy is a constellation of separately-maintained bolt-ons, each owned by a different team with a different incentive, held together by hooks and hope. Your checkout is not a product. It is a group project. And the group is not communicating.

If you are running a WooCommerce store today, the objective, publicly-available data says the components handling your money and your tax obligations are rated between 2.0 and 2.8 out of 5 by the people using them. That is not a rounding error. That is a verdict.

And when it breaks, nobody answers

The third dataset is support-thread resolution: plugins with 5,000+ installs and active forums where fewer than 30% of threads get marked resolved.

  • Classic Editor — 9 MILLION+ installs, 4.9/5 rating, 10% of support threads resolved.
  • W3 Total Cache — 900K+ installs, 28% resolved.
  • Polylang — 800K+ installs, 26.7% resolved. Multilingual sites.
  • Kirki — 500K+, 20% resolved.
  • Gutenberg — 300K+, 2.1/5 rating, 20% resolved. It appears on two of the three worst-of lists.
  • The SEO Framework — 200K+, 27.3%. Mollie Payments for WooCommerce — 100K+, 25%.

Classic Editor deserves its own paragraph. Nine million installs. A 4.9-star rating. A ten percent support resolution rate. Nine out of every ten people who ask for help get nothing.

That plugin exists solely because millions of users hated the new editor so much that Automattic had to ship an official escape hatch, then keep extending its end-of-life because the exodus never happened. It is simultaneously the most-loved and least-supported plugin in the ecosystem — a nine-million-install monument to a UX decision the userbase rejected and never got over. And Gutenberg, the thing they were escaping, sits at 2.1 stars with 20% support resolution eight years later.

What a WordPress site owner should actually be worried about

Strip out the commentary. Here is what this data means for you, specifically, today.

1. You do not know what you're running

Go to your plugins page right now and read the last-updated date on every single one. Not the rating. The date. Statistically, if you have twelve plugins installed, five of them haven't been touched in a year and at least four haven't been touched in two. That's not a guess, that's the base rate of the directory you shop in.

2. Ratings are a lagging indicator and they never expire

A 4.7-star plugin abandoned in 2021 will still show 4.7 stars in 2036. Stars measure historical sentiment. Dates measure whether anyone is defending the code. Only one of those two numbers can hurt you, and it's the one in small grey text.

3. Install count is not safety, it's blast radius

People treat 80,000 installs as social proof. To an attacker building a target list, 80,000 installs plus a dead maintenance date is a business case. Popularity is precisely what makes an abandoned plugin worth exploiting.

4. 'Actively maintained' does not mean 'good'

A million sites are running a 1.4-star AI plugin that was updated last month. Maintenance frequency and quality are unrelated variables. Check both, then check the recent one-star reviews specifically, because that's where the current breakage lives.

5. Your dependency count is your real risk number

Every plugin is an independent bet that a stranger will keep caring, indefinitely, for free. The base rate of that bet failing within two years is 43.8%. Twelve plugins is not twelve small bets. It's a compound probability that something in your stack is already unmaintained — and the more of your site's actual function depends on plugins, the closer that probability gets to certainty.

6. Nobody is coming when it breaks

Best case, on a maintained plugin with an active forum, a quarter of support threads get resolved. On an abandoned plugin, the number is zero and there isn't a forum to be sad about. Your support plan is a stranger's goodwill, and the data says the stranger has left.

The uncomfortable conclusion

WordPress's greatest marketing asset has always been the number 60,000. Sixty thousand plugins! Whatever you need, there's a plugin for it! Infinite extensibility!

The data says the honest version of that sentence is: there are roughly 34,000 plugins with a pulse, 26,000 corpses shelved next to them at identical prominence, and the largest and most professionally-maintained integrations in the ecosystem are rated by their own users somewhere between 1.4 and 2.8 out of 5.

That isn't extensibility. That's an unmoderated dependency pile with excellent SEO.

And the joke inside the joke is who commissioned this research. It wasn't a security firm or the WordPress Foundation. It was a company selling weekly leads to developers who want to find abandoned plugins, clone them, and sell the replacement. The abandonment isn't being treated as an ecosystem emergency. It's being treated as a market segment. There is a subscription business built on top of WordPress's rot, and it publishes a newsletter every Wednesday.

Nobody is going to fix this, because nothing about the incentive structure wants it fixed. Removing dead plugins shrinks the headline number. Enforcing maintenance standards shrinks the headline number. Warning users loudly at the point of install reduces installs. The rot is load-bearing.

You were never buying a platform. You were adopting 43.8% of a graveyard and calling it flexibility.

Audit your plugin list this week. Sort by last updated, oldest first, and be honest about what you find. Then ask the harder question: how much of what your site actually does is only possible because of code that a stranger stopped maintaining three years ago — and what, exactly, is your plan for the day that stops working.

Source: WP Goldmine, 'The State of WordPress Plugin Opportunities 2026', data as of 1 August 2026, drawn from the WordPress.org plugin API across 60,257 plugins. The numbers are theirs. The contempt is mine.

Found this useful? Argue with it.

More Heresies →

// The Dispatch

Get the truths
the agencies hide.

No spam. No "10 tips." No webinars. Just brutal pragmatism delivered when there is something worth saying. Unsubscribe in one click.

By subscribing you agree to receive opinions you did not ask for.