Popular plugins that millions of sites still run — but nobody maintains. Abandoned code is a ticking security bomb.
An estimated 59% of WordPress plugins are abandoned — no longer receiving security patches, compatibility updates, or support. Research by Patchstack found that nearly 1,000 plugins were closed from the WordPress.org repository in a single month, affecting 7.1 million active installations. Many of these outdated WordPress plugins contain known vulnerabilities that attackers actively exploit.
This database tracks abandoned WordPress plugins with 10,000+ active installs that haven't been updated in over 2 years. Search for plugins you use, check their status, and find actively maintained alternatives.
Every Royal Plugin is actively maintained, security-scanned before each release, and tested with the latest WordPress and PHP versions.
Scan your WordPress site in 30 seconds. We'll check for outdated plugins, missing security headers, and common vulnerabilities.
Scan Your Site FreeNo signup required. Results in under 60 seconds.