Abandoned Plugins: The WordPress Risk You Can’t See

WordPress security series · Part 2 of 5

Most hacked small business websites I clean up have something in common. It is rarely a clever attacker. It is usually one or more abandoned WordPress plugins that nobody has touched in years.

How it happens

91%
of WordPress vulnerabilities are in plugins, not WordPress
3x
more known exploited flaws in premium plugins than free ones
12 months
no update from the author is your first warning sign

Your site was built a few years ago. The developer installed 20 or 30 plugins to make it do what you wanted: forms, sliders, galleries, SEO. Then the developer moved on.

Some of those plugins are still maintained. Some are not. Their authors lost interest, sold the product or shut up shop. When a security flaw turns up in an abandoned plugin, nobody fixes it. The hole stays open for as long as the plugin stays installed.

From the front end, you cannot tell. The site looks fine, right up until it redirects your customers to a scam page or starts sending spam in your name.

How to spot one

WordPress.org gives you a free warning sign. Open any plugin’s page in the official directory and look for this notice: “This plugin hasn’t been tested with the latest 3 major releases of WordPress.” That usually means nobody is looking after it.

Other red flags:

  • No update from the author in the last twelve months.
  • Support forum questions going unanswered.
  • The plugin has disappeared from the WordPress.org directory altogether.

Paying for a plugin is no guarantee either. Patchstack’s State of WordPress Security in 2026 found premium components had three times more known exploited vulnerabilities than free ones.

What to do about it

Every abandoned plugin needs one of three decisions: replace it with a maintained alternative, rebuild the feature properly, or remove it. “Leave it and hope” is not a decision. It is a delay.

Deactivating is not enough. A deactivated plugin’s files still sit on the server, and badly written ones can still be reached directly. If you do not use it, delete it.

The question to ask this week

“How many of our plugins have not been updated by their author in the last twelve months?”

The right answer is a number, and a plan for each one.

Next step

A Security Audit (from $1,000 inc GST) lists every plugin on your site, flags the abandoned ones and tells you what to do with each, in plain English. For ongoing cover, see our maintenance plans.

Call 1300 856 393

Common questions

How many plugins is too many?
There is no magic number. Ten well-maintained plugins are safer than five abandoned ones. What matters is whether each one is still looked after.
Is deactivating an old plugin enough?
No. Its files stay on the server and some can still be attacked. Delete plugins you do not use.
Are premium plugins safer than free ones?
Not automatically. Patchstack found premium components had three times more known exploited vulnerabilities than free ones. Check that any plugin, paid or free, is actively maintained.

The five-part series

  1. Five Hours: The Gap Between a WordPress Flaw and an Attack
  2. Abandoned Plugins: The WordPress Risk You Can’t See — you are here
  3. When Your Backup Plugin Becomes the Way In (6 October)
  4. Your Website Isn’t the Target. It’s the Tool. (13 October)
  5. A Hacked Website Is Now a Compliance Problem (27 October)

Based on the full article: Your WordPress Site Is Probably Already a Problem.