Measured 2026-09-16 · 58,938 plugins
9.2M WordPress sites are running plugins their authors walked away from
23,362 of the 58,938 plugins in the WordPress directory — 39.6% — have not been updated in over two years. They still install. They still run. Nobody is shipping a fix if one is ever needed.
The uncomfortable part: some of them are security plugins
These were installed specifically to protect a site. They are the plugins a site owner is least likely to audit, because installing them felt like the responsible thing to do.
- Limit Login Attempts300K installs · 3.5y stale
- BackUpWordPress80K installs · 2.4y stale
- Disable REST API80K installs · 3y stale
- Easy SSL Plugin for SAKURA Rental Server50K installs · 6.8y stale
- Login Logo40K installs · 2y stale
- reCAPTCHA for MW WP Form30K installs · 2.4y stale
- Change WordPress Login Logo20K installs · 2.1y stale
The largest abandoned plugins
Ordered by how many sites still run them. “Stale” is time since the last release.
What this does and does not mean
An old plugin is not automatically a vulnerable one. A small plugin that does one narrow thing may genuinely need no changes for years. But it also stops being tested against new WordPress releases, and if a flaw is found, there is no longer anyone obliged to fix it.
The WordPress directory shows a last-updated date on every listing. It does not tell you that 39% of the catalogue crossed the two-year line, or which of the plugins on your site are among them — which is the only version of this question that matters to a site owner.
Source: the official WordPress.org plugin API, read 2026-09-16, covering 58,938 plugins. “Abandoned” here means no release in over 730 days. Active install counts are the directory’s own rounded buckets, so the affected-installs total is an approximation built from those buckets. Figures can be reproduced from the same public API.