---
title: "How to Vet a WordPress Plugin Before You Install It"
url: https://nexterwp.com/blog/how-to-vet-a-wordpress-plugin/
date: 2026-08-03
modified: 2026-08-03
author: "Aditya Sharma"
description: "WordPress plugin vulnerabilities caused 91% of all ecosystem vulnerabilities found in 2025. Here are the four fields that actually predict a risky plugin, the trust signals that predict nothing, and a 60 second check to run before you install."
image: https://nexterwp.com/wp-content/uploads/2026/08/gpo2ou-1024x538.jpg
word_count: 2727
---

# How to Vet a WordPress Plugin Before You Install It

## Key Takeaways

- Patchstack’s State of WordPress Security whitepaper reports 11,334 new vulnerabilities in the WordPress ecosystem in 2025, and 91% are in plugins, with only 6 in WordPress core.
- Last updated, vulnerability history, support replies, and download source are the four fields that actually predict plugin risk.
- Patchstack’s database and WPScan’s WordPress Plugin Vulnerabilities index let a reader search a plugin name before installation, and Patchstack lists 50,162 entries.
- WordPress.org support threads and resolved counts show whether anybody is home, but the article says star rating and active install count tell very little on their own.
- The same four checks apply to existing plugins too, because abandoned plugins are often already on the site rather than about to be installed.

#### Key Takeaways
- Patchstack’s State of WordPress Security whitepaper reports 11,334 new vulnerabilities across the WordPress ecosystem in 2025, and 91% of them were in plugins. Only 6 were in WordPress core.- Four fields actually predict trouble: when the plugin was last updated, whether it has a vulnerability history, whether support questions get resolved, and where you downloaded it from.- Star rating and active install count feel reassuring and tell you very little. A 94 rating from 13 reviews is not the same claim as a 94 from 4,967 reviews.- You can check every field in about a minute using the plugin page, the free Patchstack and WPScan vulnerability databases, and the public WordPress.org plugin API.- Vetting is not only a pre-install job. Run the same four checks across the plugins already on your site, because that is where the abandoned ones are hiding.

 

Say you take over a WordPress site you did not build. You open the Plugins screen and there are 34 of them. Three say “Update available.” Two have not shipped a release since 2021. One is called something like *wp-super-slider-pro-final* and does not appear in the WordPress.org directory at all. Nothing is visibly broken, so the temptation is to leave it.

That pile is how most WordPress sites get compromised. Not through a clever attack on WordPress itself, but through a plugin somebody installed once and never looked at again. The good news is that judging a plugin is a short, repeatable check, and most of the signals people rely on are the wrong ones.

This guide covers what to look at, in the order that actually matters, plus how to run the same pass over the plugins you already have.

Table of Contents

## Why Plugins Are Where WordPress Actually Breaks

This is worth grounding in numbers rather than vibes. Patchstack’s [State of WordPress Security](https://patchstack.com/whitepaper/state-of-wordpress-security-in-2026/) whitepaper reports that “11,334 new vulnerabilities were found in the WordPress ecosystem in 2025”, a 42% increase compared to 2024. The split is the part that matters:

| Where the 2025 vulnerabilities were found | Share |
| ----------------------------------------- | ----- |
| Plugins | 91% |
| Themes | 9% |
| WordPress core | 6 vulnerabilities total, described as low priority |
| Rated high severity | 1,966 (17%) |
| Serious enough to need a protection rule | 4,124 (36%) |
Figures for calendar year 2025, published in Patchstack’s State of WordPress Security whitepaper.

![Patchstack State of WordPress Security whitepaper page reporting 11,334 new WordPress ecosystem vulnerabilities found in 2025](https://nexterwp.com/wp-content/uploads/2026/08/5ceTXJoR-xgrorzKqSYfoYN6bHdi2wzg74tL-L8Jy_gTA1bNmuuIHvnn3tN1yDf_KAfxdWosL9xbtx0P0rUIbw-scaled.png)The whitepaper the figures above come from. Note that the report is titled for 2026 but the counts describe 2025.

Two readings follow from that. First, WordPress core is not your problem. Second, your exposure is roughly proportional to how many plugins you run and how carefully each one was chosen. Every plugin is code from a third party running with full access to your database.

Worth saying plainly: this is not an argument for installing nothing. Plugins are the reason WordPress is useful. It is an argument for spending sixty seconds before each one, and for knowing which sixty seconds are well spent.

***Also Read:** [How to Secure a WordPress Website: The 2026 Hardening Checklist](https://nexterwp.com/blog/ultimate-wordpress-security-guide/) puts plugin vetting in the context of the rest of your hardening work.*

## The Four Signals That Actually Predict Risk

Most vetting checklists hand you a dozen things to look at and imply they carry equal weight. They do not. These four are the ones with real predictive value.

### 1. When It Was Last Updated, and What Tested Up To Really Means

This is the single highest signal field on a plugin page. A plugin that shipped a release recently has somebody paying attention to it. A plugin whose last release was three years ago does not, and an unmaintained plugin with a vulnerability never gets a patch.

The related field is **Tested up to**. The WordPress Plugin Handbook defines it as “[The version of WordPress that the plugin has been tested against](https://developer.wordpress.org/plugins/wordpress-org/how-your-readme-txt-works/)”, and notes the field ignores minor versions because plugins should not break on a minor update. Two things to understand about it:

- It is declared by the developer, not verified by anyone. It tells you what the author claims to have tested, which is a signal of diligence rather than a guarantee of compatibility.- Since WordPress 5.8, the handbook notes that readme files are no longer parsed for requirements, so *Requires PHP* and *Requires at least* are read from the plugin’s main PHP file instead.- **Stable tag** trips people up constantly. The handbook is explicit that this is the version of the plugin, not the version of WordPress.

![WordPress Plugin Handbook page defining readme header fields including Tested up to, Stable tag and Requires PHP](https://nexterwp.com/wp-content/uploads/2026/08/RncmenqZiHOQ66nRmhPxOvjgofd8yKGlgiD1V5BN20Ztn4Z1-_rNRTmJXgCsvfSPkvneGoMPKCTf37KjA8m6Bg-scaled.png)The Plugin Handbook page that defines each readme field. Useful when a plugin listing looks ambiguous.

The practical test: if *Tested up to* trails the current WordPress release by two or more major versions, treat that as the author having stopped checking.

### 2. Whether It Has a Vulnerability History

Almost nobody does this check, and it is the one that would catch the most trouble. Two free databases let you search a plugin by name before you install it.

[Patchstack’s database](https://patchstack.com/database/) describes itself as “the leading open source vulnerability database” and currently lists 50,162 entries in total, of which 16,158 have a mitigation rule and 13,196 are marked as having no official patch. It is searchable without an account, and each row names the affected plugin, the vulnerable version range and a CVSS risk score.

![The Patchstack vulnerability database, a free and publicly searchable index of known WordPress plugin vulnerabilities](https://nexterwp.com/wp-content/uploads/2026/08/IkUpg-BWfKN-2J6icwzVDV_VKtjQDboi-DS6akZFZH0j7-H8A5aJbwCXkkbydyDYVHMEG5Tq89WTV9xROzqTsQ-scaled.png)Patchstack’s database is searchable without an account. Look up the plugin slug before you install.

[WPScan’s WordPress Plugin Vulnerabilities index](https://wpscan.com/plugins/) is the other one, browsable alphabetically by plugin name. Between them you get a decent picture of whether a plugin has a history.

![The WPScan WordPress plugin vulnerabilities index listing plugins alphabetically](https://nexterwp.com/wp-content/uploads/2026/08/9LCOhcRBWr9qPZORbg_EbOZwE56G2Mto6D9mzArvLR2OiuClAeAOArLGzmwwPgfjEY3TOyeEJM6ynvt25SWNww-scaled.png)WPScan indexes plugin vulnerabilities alphabetically by plugin name.

Reading the result matters more than the lookup. A past vulnerability is not automatically disqualifying. Widely used plugins get audited more, so they turn up more findings, and a fast patch is evidence of a responsive team. What should worry you is a pattern: repeated findings of the same class, or an entry still marked as having no official patch.

***Also Read:** [Best WordPress Security Plugins: 6 Compared for 2026](https://nexterwp.com/blog/best-wordpress-security-plugins/) covers the tools that scan your installed plugins against these databases automatically.*

### 3. Whether Support Questions Actually Get Answered

Every WordPress.org plugin has a support forum, and the directory tracks how many threads exist and how many are marked resolved. That ratio tells you something a star rating cannot: whether anybody is home. Here is what four plugins looked like when this article was written:

| Plugin | Support threads | Resolved | Last updated | Active installs |
| ------ | --------------- | -------- | ------------ | --------------- |
| Wordfence Security | 141 | 111 | 13 May 2026 | 5,000,000 |
| Contact Form 7 | 41 | 15 | 15 May 2026 | 10,000,000 |
| Classic Editor | 7 | 1 | 28 May 2026 | 9,000,000 |
| Nexter Extension | 4 | 2 | 29 July 2026 | 10,000 |
Values read from the public WordPress.org plugin API on 3 August 2026. Counts move, so check them yourself rather than trusting this snapshot.

Two honest caveats, because this signal is easy to over-read. Small denominators mean very little: a plugin with 4 threads and 2 resolved is not meaningfully different from one with 4 and 3. And context changes the meaning. Classic Editor is maintained by WordPress.org itself and is deliberately feature-frozen, so its thread activity says something different from an actively developed plugin.

Use it as a tiebreaker between two plugins that both pass the first two checks, not as a score.

### 4. Where the Download Came From

A plugin from the WordPress.org directory has been through a review process and arrives through a channel that supports updates. The same plugin from a site offering a “free premium” copy has not, and by definition somebody repackaged it before it reached you.

The problem with a nulled plugin is not that it is unlicensed, it is that you cannot verify what changed inside it, and it will not receive security updates from the developer. You are trusting whoever did the repackaging, and their incentive was not your site’s safety. If the budget for a premium plugin is not there, the free plugin from the official directory is the safer trade every time.

For commercial plugins bought legitimately, the equivalent check is that updates arrive through the vendor’s own licensed channel, so a patch reaches you without you going hunting for it.

## The Trust Signals That Look Reassuring and Predict Nothing

These are the fields most guides tell you to check first, and they are close to noise on their own.

![The Wordfence listing in the WordPress.org plugin directory showing version, last updated date, active installations and tested-up-to fields](https://nexterwp.com/wp-content/uploads/2026/08/qpKYx5tNPfTKTnp0ZvIMl3xrmwmKBkrCmbk0Bgq6PUjtJI4YCHAA3BPm_Q_AmjAosm5x4R_TKtszfwalW4WRzA-scaled.png)A WordPress.org plugin listing. The fields on the right side are the ones worth reading, and the star rating is not among them.

**The star rating.** Ratings compress into a narrow band near the top, so they rarely separate two candidates. Worse, they do not carry their sample size. Our own Nexter Extension currently shows a 94 rating from 13 reviews. Wordfence shows a 94 from 4,967 reviews. Identical number, completely different amount of evidence behind it. Always read the review count next to the score, and if the count is small, ignore the score.

**Active install count.** A big number means popular, which cuts both ways. A widely deployed plugin is a more attractive target and is scanned more aggressively, though it usually also has a real team and faster patches. A small number means unproven, not unsafe. Contact Form 7 has around 10,000,000 active installs and a rating of 80, which is a useful reminder that scale and satisfaction are separate things.

**Polished screenshots and a nice landing page.** Design quality tells you about the marketing budget. It says nothing about code quality or how quickly a reported vulnerability gets patched.

**Claims like 5,000 happy customers.** Unverifiable by construction. Skip them and read the fields the directory generates automatically, because those are the ones the developer cannot write themselves.

## The 60 Second Pre-Install Check

Pulled together, this is the order to run. It takes about a minute and catches almost everything that matters.

- **Confirm the source.** Is it in the WordPress.org directory, or from the developer’s own site? If neither, stop here.- **Read the last updated date.** Recent release means somebody is maintaining it. Years old means nobody is.- **Check Tested up to** against your WordPress version. Trailing two or more major versions is a flag.- **Search Patchstack and WPScan** for the plugin name. You are looking for a pattern of findings or an unpatched entry, not the mere existence of one.- **Glance at the support forum.** Are recent threads getting replies from the developer?- **Only then look at rating and installs**, and only as a tiebreaker with the review count in view.

If you want the underlying data directly, the WordPress.org plugin API is public and returns every one of these fields as JSON for any plugin slug:

`https://api.wordpress.org/plugins/info/1.2/?action=plugin_information&request[slug]=wordfence`

Swap *wordfence* for the slug from the plugin’s directory URL. The response includes *last_updated*, *tested*, *requires_php*, *active_installs*, *support_threads* and *support_threads_resolved* in one place, which is faster than reading the page if you are checking several plugins at once.

One more step before you install anything on a site that matters: install it on a copy first. A [WordPress staging site](https://nexterwp.com/blog/wordpress-staging-site/) costs you a few minutes and turns a plugin conflict into a non-event. Pair that with a current backup from a [WordPress backup plugin](https://nexterwp.com/blog/best-wordpress-backup-plugin/) and the worst case becomes a restore rather than an outage.

## How to Audit the Plugins You Already Have

Every guide on this subject stops at the install button, which leaves out the harder half of the problem. The riskiest plugin on a site is almost never the one somebody is about to add. It is the one added four years ago that nobody has opened since.

Run the same four checks across your existing list, and sort by the two questions that resolve fastest:

- **Is it still maintained?** Sort the Plugins screen and look up the last release date for anything you do not recognise. Anything with no release in two or more years is a candidate for replacement.- **Is it actually being used?** Deactivated plugins still sit on disk. Delete what you are not using rather than leaving it deactivated, because deactivated code can still be reachable in some circumstances.- **Does it have an open vulnerability?** Run your list through Patchstack or WPScan, or let a security plugin do it on a schedule.- **Is anything duplicating another plugin?** Two plugins doing the same job is double the attack surface for one outcome.

Then keep it from drifting again. Turning on [WordPress automatic updates](https://nexterwp.com/blog/wordpress-automatic-updates/) for plugins you trust closes the window between a patch shipping and you applying it, and [keeping plugins and themes updated](https://nexterwp.com/blog/why-update-wordpress-core-themes-and-plugins-to-the-latest-version/) is the single highest-value maintenance habit there is. If something has already gone wrong, [finding and removing malware from WordPress](https://nexterwp.com/blog/remove-malware-from-wordpress/) is the recovery path.

***Also Read:** [How to Change the WordPress Login URL](https://nexterwp.com/blog/change-wordpress-login-url/) is a useful companion once your plugin list is clean, and is honest about what that technique does and does not do.*

## Fewer Plugins Is a Real Answer, but Not a Free One

If 91% of vulnerabilities live in plugins, then running fewer plugins genuinely reduces exposure. That is arithmetic, not marketing. It is why replacing eight single-purpose plugins with one suite that covers the same eight jobs is a legitimate security decision as well as a maintenance one.

That is the shape of Nexter Blocks. Its WordPress.org listing describes “90+ Fastest WordPress Page Builder Blocks”, covering the ground that otherwise takes separate plugins for tables, tabs, accordions, galleries, mega menus, popups, listings and Ajax search.

![The Nexter Blocks listing in the WordPress.org plugin directory published by POSIMYTH, showing 90 plus Gutenberg blocks](https://nexterwp.com/wp-content/uploads/2025/02/kudH8TPNtqW-Uy3k2KUgrYp95v4ZyKf97j4jQmJLJanro8mZsA6a8DzejQYTy0gfokaf68I13HHFgegDRh5n-g.png)The Nexter Blocks listing in the WordPress.org plugin directory. Run the same four checks on it that you would run on anything else.

Nexter Extension covers the site-level equivalent. Its security section groups the hardening toggles most sites end up wanting into one panel rather than one plugin each.

![The Nexter Extension security settings panel in WordPress admin showing toggles for Advanced Security, CAPTCHA, Custom Login URL, SVG Upload, 2-Factor Authentication, Content Protection, Login Email Notification and Limit Login Attempts](https://nexterwp.com/wp-content/uploads/2023/11/nexter-extension-settings-security-new.png)Nexter > Extensions > Security. Eight hardening options in one panel, each off by default until you enable it.

Now the part a product page will not tell you. Consolidation does not delete risk, it moves it. One suite means one larger codebase with broader permissions, and a vulnerability in it reaches everything that suite touches instead of one feature. You are trading many small surfaces for one bigger one, and betting on the maintainer. That bet is only reasonable if the suite passes the same four checks you would apply to anything else, so check ours the same way.

Two more limits worth stating. Nexter Extension is a hardening layer. It is not a firewall and it is not a malware scanner, so it does not replace a dedicated security plugin. And consolidation only helps if you actually remove the plugins it replaced. Installing a suite on top of the eight plugins you already had makes things worse, not better.

[Explore Nexter Blocks](https://nexterwp.com/nexter-blocks/)

## Frequently Asked Questions

### Are WordPress Plugins Safe?

Plugins as a category are safe enough that WordPress does not work without them. Individual plugins vary enormously. The 2025 figures show 91% of ecosystem vulnerabilities were found in plugins, which is a statement about the volume of plugin code in the world rather than a warning to avoid all of them. A maintained plugin from the official directory with no unpatched vulnerability history is a reasonable risk. An abandoned plugin from an unofficial download site is not.

### How Many WordPress Plugins Are Too Many?

There is no threshold number, and any guide quoting one is guessing. Twenty well-maintained plugins that you chose deliberately are safer than six abandoned ones. The useful question is not how many you have but whether you can say what each one does and when it last shipped an update. If you cannot answer that for a plugin, that is the one to look at.

### Do Plugins Slow Down WordPress?

Some do, and it depends far more on what a plugin does than on the count. A plugin loading scripts on every page affects performance more than ten that only run in the admin. Poorly written database queries matter more than either. Judge the individual plugin’s behaviour rather than assuming a plugin total maps to page speed.

### Can I Trust a Plugin With No Reviews?

Sometimes, but you have to lean harder on the other signals. No reviews usually means new or niche rather than bad. Check the release history, whether the developer responds in the support forum, and whether they have other plugins in the directory with a track record. A brand new plugin from a developer with five maintained plugins is a different proposition from a brand new plugin from an unknown account.

## Suggested Reading

- [How to Secure a WordPress Website: The 2026 Hardening Checklist](https://nexterwp.com/blog/ultimate-wordpress-security-guide/)- [Best WordPress Security Plugins: 6 Compared for 2026](https://nexterwp.com/blog/best-wordpress-security-plugins/)- [WordPress Automatic Updates: How to Control Them Without Breaking Your Site](https://nexterwp.com/blog/wordpress-automatic-updates/)- [WordPress Code Snippets Plugin vs Child Theme in Functions.php: What to Use?](https://nexterwp.com/blog/wordpress-code-snippets-plugin-vs-child-theme-in-functions-php/)- [12 Best Gutenberg Plugins for WordPress](https://nexterwp.com/blog/best-gutenberg-plugins/)

#### Stay updated with Helpful WordPress Tips, Insider Insights, and Exclusive Updates – Subscribe now to keep up with Everything Happening on WordPress!

Subscribe