This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Free Tool · Updated 1st of Every Month · Data from WordPress.org + Wordfence

WordPress Plugins
No One Is Maintaining Anymore

No update in 12+ months. Known security vulnerabilities. Active install counts. If your site runs any of these, it's a target.

90
Unmaintained plugins
47
Have active vulnerabilities
6
Critical risk
15
High risk
4.2M+
Sites exposed

Updated 2026-06-14 · Refreshes automatically on the 1st of every month

Why does an unmaintained plugin put your site at risk?

WordPress plugins are code running on your server. When a developer stops releasing updates:

  • Security vulnerabilities are discovered but never patched
  • The plugin falls out of compatibility with newer versions of WordPress and PHP
  • Hackers specifically target abandoned plugins because they know fixes won't come

The plugins in this directory haven't received an update in over 12 months. Many have known, publicly documented security vulnerabilities — meaning exploit code already exists.

If your site runs any of these, the risk is real and the fix is straightforward: remove or replace the plugin.

Get help removing abandoned plugins →

Browse the directory

Showing 90 of 90 plugins

Plugin Risk Level Last Update Sites Running It View Plugin
Limit Login Attempts
limit-login-attempts
CRITICAL (4)2023-04-04300K+WP.org ↗
Search & Replace
search-and-replace
CRITICAL (3)2024-08-26100K+WP.org ↗
YARPP – Yet Another Related Posts Plugin
yet-another-related-posts-plugin
CRITICAL (10)2024-11-11100K+WP.org ↗
OptionTree
option-tree
CRITICAL (5)2019-05-1950K+WP.org ↗
WP-Polls
wp-polls
CRITICAL (9)2025-01-1840K+WP.org ↗
Temporary Login
temporary-login
CRITICAL (1)2024-11-2640K+WP.org ↗
String locator
string-locator
HIGH (4)2025-01-15100K+WP.org ↗
CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress
advanced-nocaptcha-recaptcha
HIGH (7)2025-06-11100K+WP.org ↗
Custom Product Tabs for WooCommerce
yikes-inc-easy-custom-woocommerce-product-tabs
HIGH (3)2025-04-1280K+WP.org ↗
Facebook Chat Plugin – Live Chat Plugin for WordPress
facebook-messenger-customer-chat
HIGH (6)2022-07-0580K+WP.org ↗
Duplicate Page and Post
duplicate-wp-page-post
HIGH (6)2024-09-2380K+WP.org ↗
WP fail2ban – Advanced Security
wp-fail2ban
HIGH (8)2025-04-2960K+WP.org ↗
Web Stories
web-stories
HIGH (3)2025-05-1560K+WP.org ↗
Simple Sitemap – Create a Responsive HTML Sitemap
simple-sitemap
HIGH (8)2025-05-2060K+WP.org ↗
Add From Server
add-from-server
HIGH (4)2020-12-1160K+WP.org ↗
WP-DBManager
wp-dbmanager
HIGH (7)2024-11-2460K+WP.org ↗
Blogger Importer
blogger-importer
HIGH (1)2024-10-2160K+WP.org ↗
CMS Tree Page View
cms-tree-page-view
HIGH (8)2024-04-1250K+WP.org ↗
WP Extra File Types
wp-extra-file-types
HIGH (1)2023-10-2840K+WP.org ↗
User Profile Picture
metronet-profile-picture
HIGH (4)2024-07-1840K+WP.org ↗
Cornerstone
cornerstone
HIGH (4)2024-07-1630K+WP.org ↗
Template Kit – Import
template-kit-import
MEDIUM (1)2024-08-01400K+WP.org ↗
Health Check & Troubleshooting
health-check
MEDIUM (11)2024-07-25300K+WP.org ↗
WP Sitemap Page
wp-sitemap-page
MEDIUM (1)2025-04-15200K+WP.org ↗
Table of Contents Plus
table-of-contents-plus
MEDIUM (7)2024-11-21200K+WP.org ↗
PHP Compatibility Checker
php-compatibility-checker
MEDIUM (1)2023-12-14200K+WP.org ↗
WooSidebars
woosidebars
MEDIUM (1)2024-04-03100K+WP.org ↗
WP Downgrade | Specific Core Version
wp-downgrade
MEDIUM (1)2023-05-08100K+WP.org ↗
LuckyWP Table of Contents
luckywp-table-of-contents
MEDIUM (6)2025-04-16100K+WP.org ↗
BackUpWordPress
backupwordpress
MEDIUM (4)2024-04-2490K+WP.org ↗
Hotjar
hotjar
MEDIUM (1)2023-10-2570K+WP.org ↗
Async JavaScript
async-javascript
MEDIUM (7)2023-06-2270K+WP.org ↗
WP Show Posts
wp-show-posts
MEDIUM (4)2024-04-1670K+WP.org ↗
Better Font Awesome
better-font-awesome
MEDIUM (3)2025-02-1270K+WP.org ↗
Enhanced Media Library
enhanced-media-library
MEDIUM (1)2024-07-1560K+WP.org ↗
Dynamic Conditions
dynamicconditions
MEDIUM (1)2025-02-1160K+WP.org ↗
A2 Optimized WP – Turbocharge and secure your WordPress site
a2-optimized-wp
MEDIUM (1)2025-02-1060K+WP.org ↗
All In One Favicon
all-in-one-favicon
MEDIUM (2)2023-08-0860K+WP.org ↗
Sydney Toolbox
sydney-toolbox
MEDIUM (5)2024-12-1750K+WP.org ↗
If Menu – Visibility control for Menus
if-menu
MEDIUM (2)2024-12-0550K+WP.org ↗
Image Hover Effects – Elementor Addon
image-hover-effects-addon-for-elementor
MEDIUM (6)2024-07-1240K+WP.org ↗
WP Edit
wp-edit
MEDIUM (1)2018-10-1540K+WP.org ↗
underConstruction
underconstruction
MEDIUM (5)2024-03-0840K+WP.org ↗
FancyBox for WordPress
fancybox-for-wordpress
MEDIUM (4)2025-05-0730K+WP.org ↗
Enhanced Text Widget
enhanced-text-widget
MEDIUM (7)2024-07-1730K+WP.org ↗
DethemeKit for Elementor
dethemekit-for-elementor
MEDIUM (14)2025-03-1330K+WP.org ↗
Adapta RGPD
adapta-rgpd
No vuln (3)2025-06-1740K+WP.org ↗
WP-PageNavi
wp-pagenavi
No vuln2024-12-19500K+WP.org ↗
AMP
amp
No vuln2025-04-10400K+WP.org ↗
WooCommerce Legacy REST API
woocommerce-legacy-rest-api
No vuln2025-01-23400K+WP.org ↗
Child Theme Configurator
child-theme-configurator
No vuln2025-06-10300K+WP.org ↗
Really Simple CAPTCHA
really-simple-captcha
No vuln2025-02-01300K+WP.org ↗
Layout Grid Block
layout-grid
No vuln2023-07-11200K+WP.org ↗
Easy Google Fonts
easy-google-fonts
No vuln2021-07-23100K+WP.org ↗
Simple Custom CSS Plugin
simple-custom-css
No vuln2025-03-11100K+WP.org ↗
Edit Author Slug
edit-author-slug
No vuln2025-05-27100K+WP.org ↗
AddQuicktag
addquicktag
No vuln2021-05-20100K+WP.org ↗
Local Google Fonts
local-google-fonts
No vuln2025-05-01100K+WP.org ↗
Disable REST API
disable-json-api
No vuln2023-09-1490K+WP.org ↗
Widget CSS Classes
widget-css-classes
No vuln2024-11-1290K+WP.org ↗
Invisible reCaptcha for WordPress
invisible-recaptcha
No vuln2020-04-0780K+WP.org ↗
Fixed Widget and Sticky Elements for WordPress
q2w3-fixed-widget
No vuln2023-03-3080K+WP.org ↗
PHP Code Widget
php-code-widget
No vuln2022-03-3080K+WP.org ↗
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
No vuln2024-10-1480K+WP.org ↗
Heartbeat Control
heartbeat-control
No vuln2023-08-3180K+WP.org ↗
Advanced Excerpt
advanced-excerpt
No vuln2024-01-1980K+WP.org ↗
Title Remover
title-remover
No vuln2021-06-0370K+WP.org ↗
Brazilian Market on WooCommerce
woocommerce-extra-checkout-fields-for-brazil
No vuln2024-02-1770K+WP.org ↗
Easy Theme and Plugin Upgrades
easy-theme-and-plugin-upgrades
No vuln2022-04-2070K+WP.org ↗
Column Shortcodes
column-shortcodes
No vuln2022-10-1160K+WP.org ↗
HTML Editor Syntax Highlighter
html-editor-syntax-highlighter
No vuln2024-03-1650K+WP.org ↗
ActiveCampaign Postmark for WordPress
postmark-approved-wordpress-plugin
No vuln2024-11-1850K+WP.org ↗
Easy SSL Plugin for SAKURA Rental Server
sakura-rs-wp-ssl
No vuln2019-11-2550K+WP.org ↗
Categories to Tags Converter
wpcat2tag-importer
No vuln2024-10-2150K+WP.org ↗
Contact Form 7 add confirm
contact-form-7-add-confirm
No vuln2018-02-2750K+WP.org ↗
Portfolio Post Type
portfolio-post-type
No vuln2020-08-2950K+WP.org ↗
Clear Cache for Me
clear-cache-for-widgets
No vuln2025-06-0940K+WP.org ↗
Revision Control
revision-control
No vuln2018-04-0140K+WP.org ↗
Hide Page And Post Title
hide-page-and-post-title
No vuln2024-09-2340K+WP.org ↗
Increase Maximum Upload File Size
upload-max-file-size
No vuln2023-08-1440K+WP.org ↗
Login Logo
login-logo
No vuln2024-09-1140K+WP.org ↗
Disable Google Fonts
disable-google-fonts
No vuln2019-02-2440K+WP.org ↗
Really Simple CSV Importer
really-simple-csv-importer
No vuln2017-11-2840K+WP.org ↗
Schema
schema
No vuln2025-06-1440K+WP.org ↗
Disable Search
disable-search
No vuln2025-04-1440K+WP.org ↗
Export Media Library
export-media-library
No vuln2023-04-0530K+WP.org ↗
Hide Title
hide-title
No vuln2019-05-2230K+WP.org ↗
reCAPTCHA for MW WP Form
recaptcha-for-mw-wp-form
No vuln2024-05-0930K+WP.org ↗
Display PHP Version
display-php-version
No vuln2023-05-1630K+WP.org ↗
Elementor Beta (Developer Edition)
elementor-beta
No vuln2025-03-0430K+WP.org ↗

Frequently Asked Questions

According to Vimsy's Plugin Graveyard (updated June 2026), 90 WordPress plugins with 1,000+ active installations have not received a security or maintenance update in over 12 months. Of these, 47 have at least one known vulnerability documented in the Wordfence Intelligence database, affecting an estimated 4.2 million WordPress installations. Vulnerability severity is measured using the CVSS standard: 6 plugins carry critical-severity ratings, 15 carry high-severity ratings.

A plugin is listed here if it has not received a code update in 12 or more months. This is the point at which security researchers consider a plugin at elevated risk — enough time for unpatched vulnerabilities to be discovered and exploited.

No. Unmaintained does not mean immediately compromised. It means the risk is elevated and growing. A plugin with no known vulnerabilities but no recent updates is a lower-risk concern than one with a documented CVE. This directory shows both, clearly labelled.

Deactivate and delete the plugin immediately if there's a known vulnerability. If there's no documented vulnerability but the plugin is abandoned, assess whether you still need it — if so, find a maintained alternative. If you're not sure, a WordPress site audit will tell you exactly what to do.

Vulnerability information comes from Wordfence Intelligence, one of the most comprehensive WordPress security databases. Install counts and plugin metadata come from the WordPress.org API. Data refreshes automatically on the 1st of each month.

"Working" and "safe" are different things. A plugin can function correctly while containing a security vulnerability that allows an attacker to access your site. Hackers don't break your site — they quietly use it.

If you believe a plugin has been incorrectly listed (e.g. it received an update not yet reflected in the data), email [email protected]. Data refreshes monthly but we'll review urgent corrections manually.

Know the moment new risks are added

Sent on the 1st of each month. Unsubscribe anytime.

Your site could be running one of these right now and you wouldn't know.

Vimsy audits your WordPress installation, flags every unmaintained or vulnerable plugin, and handles the cleanup. Monthly, automatically.