We published a small research set on WordPress.org plugin abandonment: how long plugins go without updates, and how many of those abandoned plugins still show large active-install counts. The numbers are from our own API run on 7 October 2026. The measurement idea comes from WPPoland’s August 2026 article, which documented a reproducible WordPress.org API method. Credit to them for publishing something you can check. Our pages are an independent count, not a rewrite of theirs.
Headline from our sample: about 1,012 plugins had no update for two years and still showed 1,000+ active installs (extrapolated from 5,050 plugins in the abandoned tail). Across the full directory of 74,643 plugins, 35,493 (47.6%) had no update in at least two years.
Read the full tables and method in the WordPress Plugin Abandonment Report. If you only want the install-focused number, use abandoned plugins still in use. Raw JSON: latest.json.
Last-updated date is useful maintenance context. It is not a security verdict by itself. A quiet plugin with no attack surface can sit untouched for years. A plugin updated last week can ship a bad release the same day. What matters on a client book is the mix on each site: age, exposure, known vulnerabilities, PHP and WordPress drift, then a fix order.
That site-level ranking is what WP Triage is for. Directory research shows the scale. Connecting installs shows which abandoned plugins are actually on your portfolio.