Skip to content

Latest commit

 

History

History
199 lines (160 loc) · 9.42 KB

File metadata and controls

199 lines (160 loc) · 9.42 KB
title Abandoned WordPress Plugins with 10,000+ Active Installations: A Reproducible Dataset and Methodology (June 2026 Snapshot)
author
John Bernard (ORCID 0009-0008-4772-9356)
date 2026-06-26
abstract This document describes the methodology and accompanying dataset that identify WordPress plugins distributed through the official WordPress.org Plugin Directory which (a) report at least 10,000 active installations and (b) have not received a release update for two years or more. The dataset is produced from the public WordPress.org Plugin Directory API and is intended to support reproducible research into open-source software abandonment, web security risk, and content-management system ecosystem dynamics. The companion snapshot dated 26 June 2026 contains 176 plugins representing approximately 4.93 million active installations.
keywords
WordPress
plugin abandonment
open-source sustainability
software ecosystem
web security
CMS
software maintenance
geometry margin=1in
fontsize 11pt

1. Introduction

The WordPress content-management system powers a substantial share of the public web, and its extensibility is provided primarily through third-party plugins distributed via the official WordPress.org Plugin Directory. Because plugins execute with the same privileges as the host application, an unmaintained plugin with a large install base represents a persistent supply-chain risk: disclosed vulnerabilities may remain unpatched indefinitely, and compatibility drift accumulates against current PHP and WordPress core releases.

The dataset described here enumerates plugins which meet two simultaneous criteria — material adoption (10,000+ active installs) and absence of release activity (no update in 2+ years) — to support empirical analysis of plugin abandonment in the WordPress ecosystem.

2. Methodology

2.1 Data source

All plugin records are sourced from the WordPress.org Plugin Directory API, specifically the query_plugins action of the version 1.2 endpoint at https://api.wordpress.org/plugins/info/1.2/. This is the same API consumed by the WordPress core update mechanism and by the live "Plugin Graveyard" tool hosted at https://royalplugins.com/plugin-graveyard/.

2.2 Inclusion criteria

A plugin record is included in the snapshot when both of the following conditions hold:

  1. The active_installs field reports a value greater than or equal to 10,000. The API reports active installs in bucketed values (10,000, 20,000, 30,000, 40,000, 50,000, 60,000, 70,000, 80,000, 90,000, 100,000, 200,000, 300,000, 400,000, 500,000, 600,000, 700,000, 800,000, 900,000, 1,000,000+) rather than exact counts.
  2. The last_updated field resolves to a date on or before the snapshot date minus two years. For the 26 June 2026 snapshot the cutoff is 26 June 2024.

2.3 Query procedure

The query enumerates the popular browse endpoint in descending active-install order, requesting 100 plugins per page. Each plugin is evaluated against the inclusion criteria above. Enumeration terminates when three consecutive pages contain no plugins meeting the install threshold, which provides a conservative stopping condition against the non-strict ordering of the upstream endpoint.

The procedure is implemented in the accompanying file query.py and is intended to be executed without authentication. A polite request rate (250 ms between pages) and a descriptive User-Agent header are used.

2.4 Data fields

Each row of the output CSV contains the following fields:

Field Description
slug Plugin slug as registered with WordPress.org
name Display name of the plugin
active_installs Bucketed active install count reported by the API
last_updated Date of the most recent release on WordPress.org (ISO 8601)
days_since_update Integer days between last_updated and the snapshot date
category First tag returned by the API, used as a coarse functional category
rating_percent Mean user rating as a percentage (0–100)
num_ratings Count of user ratings contributing to the mean
author Author string as reported (HTML stripped)
homepage Author-provided plugin homepage URL, if any
wp_org_url Canonical WordPress.org plugin page URL

3. Snapshot summary (26 June 2026)

The 26 June 2026 snapshot contains 176 plugins which together account for approximately 4.93 million active installations.

3.1 Distribution by active install bracket

Install bracket Plugins
100,000–499,999 7
50,000–99,999 23
20,000–49,999 52
10,000–19,999 94

3.2 Distribution by time since last update

Time since last update Plugins
10+ years 2
7–10 years 51
5–7 years 32
3–5 years 44
2–3 years 47

3.3 Largest install bases in the snapshot

Active installs Last update Plugin name
300,000 2023-04-04 Limit Login Attempts
200,000 2023-07-11 Layout Grid Block
200,000 2023-12-14 PHP Compatibility Checker
100,000 2021-05-20 AddQuicktag
100,000 2021-07-23 Easy Google Fonts
100,000 2023-05-08 WP Downgrade | Specific Core Version
100,000 2024-04-03 WooSidebars

4. Limitations

Several caveats apply when using this dataset for inference:

  1. Bucketed install counts. The API exposes active_installs only in coarse buckets. Effective totals computed from this field should be read as lower bounds within each bucket, not exact counts.
  2. Popular-browse enumeration. The query relies on the popular browse endpoint, which is approximately but not strictly ordered by active install count. The three-page termination heuristic may miss a small number of qualifying plugins that fall below the threshold transiently and reappear later in the ordering.
  3. Release activity is not commit activity. last_updated reflects the date of the most recent release published to the WordPress.org Plugin Directory. A plugin may have ongoing development in its source repository that is not reflected in the directory.
  4. Closed plugins. Plugins that have been closed by the directory moderators (for security, guideline, or author-request reasons) may not be returned by the public API, even when they retain active installations on production sites.
  5. Single-snapshot. The accompanying CSV is a single observation. Longitudinal analysis requires repeated execution of query.py and comparison across snapshots.

5. Reproducibility

The dataset can be regenerated from scratch with the following invocation:

python query.py --snapshot-date 2026-06-26 --output plugin-graveyard-2026-06-26.csv

The script depends only on the Python standard library (no third-party packages) and was developed against CPython 3.13. No authentication or API key is required. Execution time is on the order of one minute on a residential broadband connection.

Re-running the script on a different date will produce a different result both because the underlying directory has changed and because the abandonment cutoff moves forward. To exactly reproduce the snapshot described here, use the --snapshot-date 2026-06-26 argument and accept that minor differences may arise where the directory has retroactively modified records since the original collection.

6. License and citation

The dataset and this methodology document are released under the Creative Commons Attribution 4.0 International license (CC-BY-4.0). The query.py script is released under the MIT license.

Suggested citation:

Bernard, J. (2026). Abandoned WordPress Plugins with 10,000+ Active Installations: A Reproducible Dataset and Methodology (June 2026 Snapshot). Zenodo. [DOI assigned on deposit]

7. Related work

A continuously refreshed and browsable version of the underlying tracker is maintained at https://royalplugins.com/plugin-graveyard/. The live tool applies the same inclusion criteria documented here and provides filtering by functional category (security, SEO, forms, performance, ecommerce, media, editor, admin) and sorting by install count, oldest update, or recency of abandonment.

8. References

  1. WordPress.org. Plugin Directory API. https://codex.wordpress.org/WordPress.org_API#Plugins
  2. WordPress Foundation. Plugin Handbook. https://developer.wordpress.org/plugins/
  3. Patchstack. WordPress Vulnerability Statistics — 2025 Annual Report.
  4. Royal Plugins. Plugin Graveyard — Abandoned WordPress Plugins Tracker. https://royalplugins.com/plugin-graveyard/