| title | Abandoned WordPress Plugins with 10,000+ Active Installations: A Reproducible Dataset and Methodology (June 2026 Snapshot) | |||||||
|---|---|---|---|---|---|---|---|---|
| author |
|
|||||||
| date | 2026-06-26 | |||||||
| abstract | This document describes the methodology and accompanying dataset that identify WordPress plugins distributed through the official WordPress.org Plugin Directory which (a) report at least 10,000 active installations and (b) have not received a release update for two years or more. The dataset is produced from the public WordPress.org Plugin Directory API and is intended to support reproducible research into open-source software abandonment, web security risk, and content-management system ecosystem dynamics. The companion snapshot dated 26 June 2026 contains 176 plugins representing approximately 4.93 million active installations. | |||||||
| keywords |
|
|||||||
| geometry | margin=1in | |||||||
| fontsize | 11pt |
The WordPress content-management system powers a substantial share of the public web, and its extensibility is provided primarily through third-party plugins distributed via the official WordPress.org Plugin Directory. Because plugins execute with the same privileges as the host application, an unmaintained plugin with a large install base represents a persistent supply-chain risk: disclosed vulnerabilities may remain unpatched indefinitely, and compatibility drift accumulates against current PHP and WordPress core releases.
The dataset described here enumerates plugins which meet two simultaneous criteria — material adoption (10,000+ active installs) and absence of release activity (no update in 2+ years) — to support empirical analysis of plugin abandonment in the WordPress ecosystem.
All plugin records are sourced from the WordPress.org Plugin Directory API,
specifically the query_plugins action of the version 1.2 endpoint at
https://api.wordpress.org/plugins/info/1.2/. This is the same API consumed
by the WordPress core update mechanism and by the live "Plugin Graveyard"
tool hosted at https://royalplugins.com/plugin-graveyard/.
A plugin record is included in the snapshot when both of the following conditions hold:
- The
active_installsfield reports a value greater than or equal to 10,000. The API reports active installs in bucketed values (10,000, 20,000, 30,000, 40,000, 50,000, 60,000, 70,000, 80,000, 90,000, 100,000, 200,000, 300,000, 400,000, 500,000, 600,000, 700,000, 800,000, 900,000, 1,000,000+) rather than exact counts. - The
last_updatedfield resolves to a date on or before the snapshot date minus two years. For the 26 June 2026 snapshot the cutoff is 26 June 2024.
The query enumerates the popular browse endpoint in descending
active-install order, requesting 100 plugins per page. Each plugin is
evaluated against the inclusion criteria above. Enumeration terminates
when three consecutive pages contain no plugins meeting the install
threshold, which provides a conservative stopping condition against the
non-strict ordering of the upstream endpoint.
The procedure is implemented in the accompanying file query.py and is
intended to be executed without authentication. A polite request rate
(250 ms between pages) and a descriptive User-Agent header are used.
Each row of the output CSV contains the following fields:
| Field | Description |
|---|---|
slug |
Plugin slug as registered with WordPress.org |
name |
Display name of the plugin |
active_installs |
Bucketed active install count reported by the API |
last_updated |
Date of the most recent release on WordPress.org (ISO 8601) |
days_since_update |
Integer days between last_updated and the snapshot date |
category |
First tag returned by the API, used as a coarse functional category |
rating_percent |
Mean user rating as a percentage (0–100) |
num_ratings |
Count of user ratings contributing to the mean |
author |
Author string as reported (HTML stripped) |
homepage |
Author-provided plugin homepage URL, if any |
wp_org_url |
Canonical WordPress.org plugin page URL |
The 26 June 2026 snapshot contains 176 plugins which together account for approximately 4.93 million active installations.
| Install bracket | Plugins |
|---|---|
| 100,000–499,999 | 7 |
| 50,000–99,999 | 23 |
| 20,000–49,999 | 52 |
| 10,000–19,999 | 94 |
| Time since last update | Plugins |
|---|---|
| 10+ years | 2 |
| 7–10 years | 51 |
| 5–7 years | 32 |
| 3–5 years | 44 |
| 2–3 years | 47 |
| Active installs | Last update | Plugin name |
|---|---|---|
| 300,000 | 2023-04-04 | Limit Login Attempts |
| 200,000 | 2023-07-11 | Layout Grid Block |
| 200,000 | 2023-12-14 | PHP Compatibility Checker |
| 100,000 | 2021-05-20 | AddQuicktag |
| 100,000 | 2021-07-23 | Easy Google Fonts |
| 100,000 | 2023-05-08 | WP Downgrade | Specific Core Version |
| 100,000 | 2024-04-03 | WooSidebars |
Several caveats apply when using this dataset for inference:
- Bucketed install counts. The API exposes
active_installsonly in coarse buckets. Effective totals computed from this field should be read as lower bounds within each bucket, not exact counts. - Popular-browse enumeration. The query relies on the
popularbrowse endpoint, which is approximately but not strictly ordered by active install count. The three-page termination heuristic may miss a small number of qualifying plugins that fall below the threshold transiently and reappear later in the ordering. - Release activity is not commit activity.
last_updatedreflects the date of the most recent release published to the WordPress.org Plugin Directory. A plugin may have ongoing development in its source repository that is not reflected in the directory. - Closed plugins. Plugins that have been closed by the directory moderators (for security, guideline, or author-request reasons) may not be returned by the public API, even when they retain active installations on production sites.
- Single-snapshot. The accompanying CSV is a single observation.
Longitudinal analysis requires repeated execution of
query.pyand comparison across snapshots.
The dataset can be regenerated from scratch with the following invocation:
python query.py --snapshot-date 2026-06-26 --output plugin-graveyard-2026-06-26.csv
The script depends only on the Python standard library (no third-party packages) and was developed against CPython 3.13. No authentication or API key is required. Execution time is on the order of one minute on a residential broadband connection.
Re-running the script on a different date will produce a different
result both because the underlying directory has changed and because the
abandonment cutoff moves forward. To exactly reproduce the snapshot
described here, use the --snapshot-date 2026-06-26 argument and accept
that minor differences may arise where the directory has retroactively
modified records since the original collection.
The dataset and this methodology document are released under the
Creative Commons Attribution 4.0 International license (CC-BY-4.0).
The query.py script is released under the MIT license.
Suggested citation:
Bernard, J. (2026). Abandoned WordPress Plugins with 10,000+ Active Installations: A Reproducible Dataset and Methodology (June 2026 Snapshot). Zenodo. [DOI assigned on deposit]
A continuously refreshed and browsable version of the underlying tracker
is maintained at https://royalplugins.com/plugin-graveyard/. The live
tool applies the same inclusion criteria documented here and provides
filtering by functional category (security, SEO, forms, performance,
ecommerce, media, editor, admin) and sorting by install count, oldest
update, or recency of abandonment.
- WordPress.org. Plugin Directory API.
https://codex.wordpress.org/WordPress.org_API#Plugins - WordPress Foundation. Plugin Handbook.
https://developer.wordpress.org/plugins/ - Patchstack. WordPress Vulnerability Statistics — 2025 Annual Report.
- Royal Plugins. Plugin Graveyard — Abandoned WordPress Plugins Tracker.
https://royalplugins.com/plugin-graveyard/