8.4% of WordPress sites among the 500,000 most visited websites, about one in twelve, load a plugin that has not been updated in two years or that WordPress.org has closed for a security issue. The average WordPress homepage loads 5.2 plugins, and the security plugin most sites show is Really Simple SSL, installed on nearly all of the 11.4% that show one.
Analysis of 38,976 popular WordPress homepages and 4,945,342 WordPress homepages web-wide · the public HTTP Archive crawl and the WordPress.org plugin directory, September 2026
Key Findings
- 1.8.4% of popular WordPress sites, about one in twelve, run a plugin that has not been updated in two years or has been closed for a security issue.
- 2.4% of popular WordPress sites, 1,570 homepages, still load a plugin that WordPress.org has closed for a security issue, and 4.8% load one abandoned for two years.
- 3.The most common abandoned WordPress plugin, a sticky sidebar widget, still loads on 212 popular WordPress sites, and the most common closed one, a social login and sharing plugin, on 95.
- 4.The average WordPress homepage loads code from 5.2 plugins, and 15.1% of WordPress homepages load 10 or more.
- 5.The 10,000 most visited WordPress sites load an average of 2.91 plugins on their homepage, against 5.47 for WordPress sites ranked 100k to 500k, nearly twice as many.
- 6.11.4% of WordPress homepages show a security plugin, and without Really Simple SSL & Security the share falls to 0.58%.
Summary
Years ago, someone installed a small plugin to keep a sidebar box in place while visitors scroll. Then one for a posts grid, one for a slider, one for a cookie banner. Each took a minute. Since then the sidebar plugin's developer has stopped releasing updates, and when the next flaw in it is found, no fix is coming. The site still loads it on every page, and nothing in WordPress tells the owner.
A WordPress plugin is an add-on that gives a site a feature WordPress does not have by default. Each one is written by a different developer, needs its own updates and often adds scripts to every page. Plugins listed in the WordPress.org directory, the official catalogue, show when they were last updated, and WordPress.org closes a plugin, removing it from the directory, when a security problem is reported and not fixed. Sites that already run a closed plugin keep running it.
These are not neglected corners of the web. Among WordPress sites in the 500,000 most visited websites, 8.4% load a plugin that is abandoned or closed. The average homepage runs code from 5.2 plugins, the most visited sites run about half as many, and the security plugin most WordPress sites show was built to fix a padlock warning, not to act as a firewall.
What we measured
We used the public HTTP Archive crawl of September 2026, which records the plugins it recognises on WordPress homepages. For the 38,976 WordPress homepages among the 500,000 most visited websites, ranked by Google's Chrome UX Report, we counted the distinct plugins each homepage loads code from and checked the 1,864 most common plugins against the WordPress.org directory. For security plugins we used all 4,945,342 WordPress homepages, counting those that show any of ten common security plugins, and grouped them by popularity.
A plugin is abandoned when it is still listed on WordPress.org but was last updated before September 24, 2024, two years before our check. A plugin is closed when WordPress.org has closed it for a security issue, as listed on September 24, 2026. A homepage "shows" a security plugin when the plugin leaves a recognisable trace on the public page, such as a file or a code comment. "The top 10,000" are the 10,000 most visited WordPress sites in Chrome's ranking.
One in twelve popular WordPress sites runs abandoned or closed code
Abandoned plugins are the larger group. 1,877 WordPress homepages, 4.8%, load at least one of 73 plugins that have not been updated in two years. An abandoned plugin may still work, but nobody is fixing it: when a flaw is found, or a WordPress update changes something the plugin relies on, no patch is coming.
Closed plugins are the bigger worry. 1,570 homepages, 4%, load a plugin WordPress.org has pulled for a security issue. A closure usually follows a reported vulnerability that was not fixed in time, and WordPress itself usually does not tell site owners when a plugin they run has been closed, so unless someone checks the directory or runs a security scanner, the site keeps it.
Source: Suff Digital analysis of 38,976 popular WordPress homepages and 4,945,342 WordPress homepages web-wide · the public HTTP Archive crawl and the WordPress.org plugin directory, September 2026
The most common abandoned plugins are small utilities
The abandoned plugins that load on the most popular WordPress sites are small helpers: a sticky sidebar widget on 212 sites, a posts grid on 166, a grid columns helper on 72 and a site search add-on on 71. They were most likely installed once for a single feature and forgotten, which is why nobody noticed their developers moving on.
Source: Suff Digital analysis of 38,976 popular WordPress homepages and 4,945,342 WordPress homepages web-wide · the public HTTP Archive crawl and the WordPress.org plugin directory, September 2026
The closed list is more concerning in kind. It includes social login and sharing, comment subscription, lightbox, slider and captcha plugins, several of which handle what visitors type or upload. Plugins that take user input are the ones where a security flaw does the most damage, and a captcha plugin is meant to be a security feature itself.
The average WordPress homepage loads 5.2 plugins
Most WordPress homepages are moderate: one in five loads a single plugin, and 46.6% load three or fewer. The average of 5.2, against a median of 4, is pulled up by a long tail. More than a quarter load seven or more, 1.4% load 20 or more, 35 homepages load 30 or more, and the single highest count was 67 plugins on one homepage.
Source: Suff Digital analysis of 38,976 popular WordPress homepages and 4,945,342 WordPress homepages web-wide · the public HTTP Archive crawl and the WordPress.org plugin directory, September 2026
The count matters because every plugin is another developer who can stop releasing updates. The 5,869 homepages that load 10 or more plugins carry the heaviest update load: more release notes to read, more updates that can conflict, and more chances that one of their plugins joins the abandoned list above.
The most visited WordPress sites run the leanest homepages
WordPress sites among the 10,000 most visited average 2.91 plugins on the homepage. WordPress sites ranked 100k to 500k average 5.47, nearly twice as many. Larger sites tend to build features into custom themes maintained by their own developers, instead of adding a plugin for each one, which keeps the number of outside developers they depend on low.
Source: Suff Digital analysis of 38,976 popular WordPress homepages and 4,945,342 WordPress homepages web-wide · the public HTTP Archive crawl and the WordPress.org plugin directory, September 2026
The same split shows in security. 5.7% of the 10,000 most visited WordPress sites show a security plugin, half the 11.9% rate of WordPress sites outside the top 10 million. Larger sites often handle security at the server or network level, with a hosting firewall or a content delivery network, while smaller sites on shared hosting install a plugin because it is the easiest option they have.
| WordPress site popularity | WordPress homepages showing a security plugin |
|---|---|
| Top 10,000 | 5.7% |
| 10k to 100k | 5.4% |
| 100k to 1 million | 7.9% |
| 1 million to 10 million | 11.1% |
| Beyond the top 10 million | 11.9% |
| All WordPress sites | 11.4% |
Nearly every visible security plugin is Really Simple SSL
11.4% of WordPress homepages, 565,327 sites, show a security plugin, and nearly all of them run Really Simple SSL & Security. Take it out and the share falls to 0.58%, 28,439 homepages, 25,290 of them running Sucuri. Wordfence, Solid Security and the other dedicated security plugins together show on 3,154 WordPress homepages, 0.06%.
Really Simple SSL's reach comes from where it started: a plugin to switch WordPress sites to HTTPS, a job almost every site needed when browsers began marking plain HTTP pages "Not secure". It later added security features, but many of the sites running it installed it to fix a padlock, not to set up a firewall. That matters on a platform where 8.4% of popular sites run abandoned or closed plugins and, in a separate Suff Digital study, 44.5% of WordPress sites are not on the current WordPress release line: a firewall and malware scanning are the layer that blocks known attacks on a site that has fallen behind.
What this means for WordPress site owners
List every plugin on your site and open its page on WordPress.org. If the page shows a closure notice, replace the plugin now. If it has not been updated in two years, plan a replacement. Remove anything inactive, anything that duplicates a feature your theme already provides and anything nobody can explain; deactivate first, check the site, then delete. Many small utilities, such as accordions, grids and columns, can now be built with WordPress's own blocks.
Then check what protection the site actually runs. A complete setup has four parts: a firewall, login protection such as two-factor authentication, regular malware scanning, and backups stored away from the site's own server. If Really Simple SSL is your only security plugin, open its settings, see which features are switched on and add what is missing.
Plugins are abandoned gradually, so repeat the check every few months. Our wordpress maintenance services review every plugin on a site at each visit, remove what the site no longer needs and replace abandoned or closed plugins before they become a security problem.
Embed this research
Paste this on your site to embed the charts. It links back to the source automatically.
<iframe id="sd-abandoned-wordpress-plugins" src="https://www.suffdigital.com/embed/data-studies/abandoned-wordpress-plugins" width="100%" height="600" style="width:100%;border:1px solid #E5E7EB;border-radius:12px" loading="lazy" title="8.4% of Popular WordPress Sites Run a Plugin That Is Abandoned or Pulled for Security - Suff Digital"></iframe>
<script>window.addEventListener("message",function(e){if(e&&e.data&&e.data.sdEmbed==="abandoned-wordpress-plugins"&&e.data.height){var f=document.getElementById("sd-abandoned-wordpress-plugins");if(f){f.style.height=e.data.height+"px";}}});</script>
<p style="font:14px/1.5 system-ui,sans-serif">Source: <a href="https://www.suffdigital.com/resources/data-studies/abandoned-wordpress-plugins">8.4% of Popular WordPress Sites Run a Plugin That Is Abandoned or Pulled for Security - Suff Digital</a></p>
Cite this study
Suff Digital. (2026). 8.4% of Popular WordPress Sites Run a Plugin That Is Abandoned or Pulled for Security. https://www.suffdigital.com/resources/data-studies/abandoned-wordpress-plugins
8.4% of Popular WordPress Sites Run a Plugin That Is Abandoned or Pulled for Security - Suff Digital - https://www.suffdigital.com/resources/data-studies/abandoned-wordpress-plugins
Frequently asked questions
Related studies
- Website Maintenance44.5% of WordPress Sites Are Behind the Latest Release, and Popular Sites Barely Do Better
- Web DesignHello Elementor, a Nearly Blank Theme, Runs 9.6% of WordPress Sites, More Than Any Other
- Website Maintenance48.1% of Websites That Show Their PHP Version Run One With No Security Fixes
- Website Maintenance58% of Small Websites Have No Web Application Firewall vs 34.4% of the Top 10,000
