Abandoned WordPress plugins still in use

As of October 2026, about 1,012 WordPress.org plugins have had no update in two years and still show 1,000+ active installs.

We measured this with the public WordPress.org plugin API. 35,493 plugins (47.6% of the directory) were past the two-year mark. In a sample of 5,050 of those abandoned plugins, 2.9% had 1,000+ active installs. Scaled to the full abandoned set, that is about 1,012.

Thresholds, method, limitations, and the sample table are in the WordPress Plugin Abandonment Report. Raw data: latest.json.

Why installs beat “half the directory”

A big share of untouched directory listings is a curiosity. It is not the same as risk on the sites you maintain. Roughly a thousand widely installed, unmaintained plugins is the practical problem: code with no maintainer, still sitting on real traffic.

Even then, age alone does not decide the work order. WP Triage answers the next question: given everything on this site, what should you fix first? See the scoring methodology.

Credit

Sampling and binary search follow the approach in WPPoland’s plugin abandonment measurement. Our figures are an independent run. This page is not a republish of their article.

Is any of this on your client sites?

This page cannot tell you that. Create an account and connect installs to see which unmaintained plugins matter on your portfolio.

FAQ

How many abandoned WordPress plugins are still widely used?

As of October 2026, about 1,012 WordPress.org plugins had no update for two years and still showed 1,000 or more active installs. That comes from a sample of 5,050 abandoned plugins, then scaled to the full abandoned set.

Why focus on installs instead of the directory percentage?

Unused listings in the directory do not hurt anyone. Plugins with no maintainer and a large active-install base do, because they sit on real traffic with nobody shipping fixes.

How do I know if my sites run any of these?

Connect sites to WP Triage. Each install gets a score that ranks unmaintained plugins with vulnerabilities and PHP lifecycle risk, so you see what to fix first on your portfolio rather than a global directory list.