惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
博客园 - 司徒正美
大猫的无限游戏
大猫的无限游戏
Last Week in AI
Last Week in AI
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
小众软件
小众软件
宝玉的分享
宝玉的分享
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队
WordPress大学
WordPress大学
博客园 - 聂微东
人人都是产品经理
人人都是产品经理
罗磊的独立博客
The Cloudflare Blog
V
V2EX
月光博客
月光博客
有赞技术团队
有赞技术团队
Y
Y Combinator Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
GbyAI
GbyAI
博客园 - 【当耐特】
T
Tailwind CSS Blog

Hacker News: Show HN

PurrrrrFocus: Pomodoro Timer App - App Store Workflow Engine — Multi-Step Orchestration for Bun RapidPhoto: Pro Photo Editor App - App Store GitHub - DheerG/swarms: Achieve extraordinary results with claude code across a variety of tasks SPICE simulation → oscilloscope → verification with Claude Code — Lucas Gerads Show HN: VCoding – A 5 MB native Windows IDE with no dynamic dependencies Show HN: LLMs don't hallucinate because they're bad at math, it's the format GitHub - Agent-FM/agentfm-core: AgentFM is a peer-to-peer network that turns everyday computers into a decentralized AI supercomputer. AgentFM lets you run massive AI workloads directly across a global mesh of idle CPUs and GPUs. Show HN: Tracking Top US Science Olympiad Alumni over Last 25 Years GitHub - Potarix/agent-hub: One place to talk to all your agents Show HN: Runtime security for AI agents(injection,tool abuse, data exfiltration) GitHub - dubeyKartikay/lazyspotify: Terminal Spotify client for macOS and Linux GitHub - the-banana-tool/king-louie: Easy to use GUI Personal AI Assistant. Win/Linux/Mac. Show HN I made my vacation rental bookable by AI agents–no Airbnb, 0% commission GitHub - basteez/jsf-autoreload: maven plugin to enable hot reload on jsf projects uvm32/hosts/host-gdbstub at main · ringtailsoftware/uvm32 GitHub - labsai/EDDI: Config-driven engine that turns JSON into production-grade AI agents. Multi-agent orchestration, 12+ LLM providers, MCP/A2A protocols, RAG, persistent memory, and enterprise compliance (EU AI Act, GDPR, HIPAA). Built on Quarkus. GitHub - glitchnsec/fortyone-oss: AI Executive Assistant Platform Quickstart | Alien GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. GitHub - ocrbase-hq/ocrbase: 📄 PDF/IMG ->.MD/JSON Document OCR API for PaddleOCR and GLMOCR. Self-hostable. GitHub - impactjo/home-memory: MCP server that lets your AI assistant remember everything about your home. GitHub - Sets88/dbcls: DbCls is a powerful terminal database client that supports various databases GitHub - neptun2000/heor-agent-mcp GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh RollQuation: Math Puzzles - Apps on Google Play GitHub - dropbox/witchcraft Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis GitHub - opentalon/opentalon: OpenTalon is an open-source platform built from the ground up in Go as a robust alternative to OpenClaw LinkedIn™ 职位抓取工具 - Chrome 应用商店
WordPress Plugin Graveyard | Vimsy
Vimsy · 2026-06-14 · via Hacker News: Show HN

47

Have active vulnerabilities

Updated 2026-06-14 · Refreshes automatically on the 1st of every month

Why does an unmaintained plugin put your site at risk?

WordPress plugins are code running on your server. When a developer stops releasing updates:

  • Security vulnerabilities are discovered but never patched
  • The plugin falls out of compatibility with newer versions of WordPress and PHP
  • Hackers specifically target abandoned plugins because they know fixes won't come

The plugins in this directory haven't received an update in over 12 months. Many have known, publicly documented security vulnerabilities — meaning exploit code already exists.

If your site runs any of these, the risk is real and the fix is straightforward: remove or replace the plugin.

Get help removing abandoned plugins →

Browse the directory

Showing 90 of 90 plugins

Plugin Risk Level Last Update Sites Running It View Plugin

Limit Login Attempts

limit-login-attempts

CRITICAL (4)2023-04-04300K+WP.org ↗

Search & Replace

search-and-replace

CRITICAL (3)2024-08-26100K+WP.org ↗

YARPP – Yet Another Related Posts Plugin

yet-another-related-posts-plugin

CRITICAL (10)2024-11-11100K+WP.org ↗

OptionTree

option-tree

CRITICAL (5)2019-05-1950K+WP.org ↗

WP-Polls

wp-polls

CRITICAL (9)2025-01-1840K+WP.org ↗

Temporary Login

temporary-login

CRITICAL (1)2024-11-2640K+WP.org ↗

String locator

string-locator

HIGH (4)2025-01-15100K+WP.org ↗

CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress

advanced-nocaptcha-recaptcha

HIGH (7)2025-06-11100K+WP.org ↗

Custom Product Tabs for WooCommerce

yikes-inc-easy-custom-woocommerce-product-tabs

HIGH (3)2025-04-1280K+WP.org ↗

Facebook Chat Plugin – Live Chat Plugin for WordPress

facebook-messenger-customer-chat

HIGH (6)2022-07-0580K+WP.org ↗

Duplicate Page and Post

duplicate-wp-page-post

HIGH (6)2024-09-2380K+WP.org ↗

WP fail2ban – Advanced Security

wp-fail2ban

HIGH (8)2025-04-2960K+WP.org ↗

Web Stories

web-stories

HIGH (3)2025-05-1560K+WP.org ↗

Simple Sitemap – Create a Responsive HTML Sitemap

simple-sitemap

HIGH (8)2025-05-2060K+WP.org ↗

Add From Server

add-from-server

HIGH (4)2020-12-1160K+WP.org ↗

WP-DBManager

wp-dbmanager

HIGH (7)2024-11-2460K+WP.org ↗

Blogger Importer

blogger-importer

HIGH (1)2024-10-2160K+WP.org ↗

CMS Tree Page View

cms-tree-page-view

HIGH (8)2024-04-1250K+WP.org ↗

WP Extra File Types

wp-extra-file-types

HIGH (1)2023-10-2840K+WP.org ↗

User Profile Picture

metronet-profile-picture

HIGH (4)2024-07-1840K+WP.org ↗

Cornerstone

cornerstone

HIGH (4)2024-07-1630K+WP.org ↗

Template Kit – Import

template-kit-import

MEDIUM (1)2024-08-01400K+WP.org ↗

Health Check & Troubleshooting

health-check

MEDIUM (11)2024-07-25300K+WP.org ↗

WP Sitemap Page

wp-sitemap-page

MEDIUM (1)2025-04-15200K+WP.org ↗

Table of Contents Plus

table-of-contents-plus

MEDIUM (7)2024-11-21200K+WP.org ↗

PHP Compatibility Checker

php-compatibility-checker

MEDIUM (1)2023-12-14200K+WP.org ↗

WooSidebars

woosidebars

MEDIUM (1)2024-04-03100K+WP.org ↗

WP Downgrade | Specific Core Version

wp-downgrade

MEDIUM (1)2023-05-08100K+WP.org ↗

LuckyWP Table of Contents

luckywp-table-of-contents

MEDIUM (6)2025-04-16100K+WP.org ↗

BackUpWordPress

backupwordpress

MEDIUM (4)2024-04-2490K+WP.org ↗

Hotjar

hotjar

MEDIUM (1)2023-10-2570K+WP.org ↗

Async JavaScript

async-javascript

MEDIUM (7)2023-06-2270K+WP.org ↗

WP Show Posts

wp-show-posts

MEDIUM (4)2024-04-1670K+WP.org ↗

Better Font Awesome

better-font-awesome

MEDIUM (3)2025-02-1270K+WP.org ↗

Enhanced Media Library

enhanced-media-library

MEDIUM (1)2024-07-1560K+WP.org ↗

Dynamic Conditions

dynamicconditions

MEDIUM (1)2025-02-1160K+WP.org ↗

A2 Optimized WP – Turbocharge and secure your WordPress site

a2-optimized-wp

MEDIUM (1)2025-02-1060K+WP.org ↗

All In One Favicon

all-in-one-favicon

MEDIUM (2)2023-08-0860K+WP.org ↗

Sydney Toolbox

sydney-toolbox

MEDIUM (5)2024-12-1750K+WP.org ↗

If Menu – Visibility control for Menus

if-menu

MEDIUM (2)2024-12-0550K+WP.org ↗

Image Hover Effects – Elementor Addon

image-hover-effects-addon-for-elementor

MEDIUM (6)2024-07-1240K+WP.org ↗

WP Edit

wp-edit

MEDIUM (1)2018-10-1540K+WP.org ↗

underConstruction

underconstruction

MEDIUM (5)2024-03-0840K+WP.org ↗

FancyBox for WordPress

fancybox-for-wordpress

MEDIUM (4)2025-05-0730K+WP.org ↗

Enhanced Text Widget

enhanced-text-widget

MEDIUM (7)2024-07-1730K+WP.org ↗

DethemeKit for Elementor

dethemekit-for-elementor

MEDIUM (14)2025-03-1330K+WP.org ↗

Adapta RGPD

adapta-rgpd

No vuln (3)2025-06-1740K+WP.org ↗

WP-PageNavi

wp-pagenavi

No vuln2024-12-19500K+WP.org ↗

AMP

amp

No vuln2025-04-10400K+WP.org ↗

WooCommerce Legacy REST API

woocommerce-legacy-rest-api

No vuln2025-01-23400K+WP.org ↗

Child Theme Configurator

child-theme-configurator

No vuln2025-06-10300K+WP.org ↗

Really Simple CAPTCHA

really-simple-captcha

No vuln2025-02-01300K+WP.org ↗

Layout Grid Block

layout-grid

No vuln2023-07-11200K+WP.org ↗

Easy Google Fonts

easy-google-fonts

No vuln2021-07-23100K+WP.org ↗

Simple Custom CSS Plugin

simple-custom-css

No vuln2025-03-11100K+WP.org ↗

Edit Author Slug

edit-author-slug

No vuln2025-05-27100K+WP.org ↗

AddQuicktag

addquicktag

No vuln2021-05-20100K+WP.org ↗

Local Google Fonts

local-google-fonts

No vuln2025-05-01100K+WP.org ↗

Disable REST API

disable-json-api

No vuln2023-09-1490K+WP.org ↗

Widget CSS Classes

widget-css-classes

No vuln2024-11-1290K+WP.org ↗

Invisible reCaptcha for WordPress

invisible-recaptcha

No vuln2020-04-0780K+WP.org ↗

Fixed Widget and Sticky Elements for WordPress

q2w3-fixed-widget

No vuln2023-03-3080K+WP.org ↗

PHP Code Widget

php-code-widget

No vuln2022-03-3080K+WP.org ↗

Display Posts – Easy lists, grids, navigation, and more

display-posts-shortcode

No vuln2024-10-1480K+WP.org ↗

Heartbeat Control

heartbeat-control

No vuln2023-08-3180K+WP.org ↗

Advanced Excerpt

advanced-excerpt

No vuln2024-01-1980K+WP.org ↗

Title Remover

title-remover

No vuln2021-06-0370K+WP.org ↗

Brazilian Market on WooCommerce

woocommerce-extra-checkout-fields-for-brazil

No vuln2024-02-1770K+WP.org ↗

Easy Theme and Plugin Upgrades

easy-theme-and-plugin-upgrades

No vuln2022-04-2070K+WP.org ↗

Column Shortcodes

column-shortcodes

No vuln2022-10-1160K+WP.org ↗

HTML Editor Syntax Highlighter

html-editor-syntax-highlighter

No vuln2024-03-1650K+WP.org ↗

ActiveCampaign Postmark for WordPress

postmark-approved-wordpress-plugin

No vuln2024-11-1850K+WP.org ↗

Easy SSL Plugin for SAKURA Rental Server

sakura-rs-wp-ssl

No vuln2019-11-2550K+WP.org ↗

Categories to Tags Converter

wpcat2tag-importer

No vuln2024-10-2150K+WP.org ↗

Contact Form 7 add confirm

contact-form-7-add-confirm

No vuln2018-02-2750K+WP.org ↗

Portfolio Post Type

portfolio-post-type

No vuln2020-08-2950K+WP.org ↗

Clear Cache for Me

clear-cache-for-widgets

No vuln2025-06-0940K+WP.org ↗

Revision Control

revision-control

No vuln2018-04-0140K+WP.org ↗

Hide Page And Post Title

hide-page-and-post-title

No vuln2024-09-2340K+WP.org ↗

Increase Maximum Upload File Size

upload-max-file-size

No vuln2023-08-1440K+WP.org ↗

Login Logo

login-logo

No vuln2024-09-1140K+WP.org ↗

Disable Google Fonts

disable-google-fonts

No vuln2019-02-2440K+WP.org ↗

Really Simple CSV Importer

really-simple-csv-importer

No vuln2017-11-2840K+WP.org ↗

Schema

schema

No vuln2025-06-1440K+WP.org ↗

Disable Search

disable-search

No vuln2025-04-1440K+WP.org ↗

Export Media Library

export-media-library

No vuln2023-04-0530K+WP.org ↗

Hide Title

hide-title

No vuln2019-05-2230K+WP.org ↗

reCAPTCHA for MW WP Form

recaptcha-for-mw-wp-form

No vuln2024-05-0930K+WP.org ↗

Display PHP Version

display-php-version

No vuln2023-05-1630K+WP.org ↗

Elementor Beta (Developer Edition)

elementor-beta

No vuln2025-03-0430K+WP.org ↗

Frequently Asked Questions

According to Vimsy's Plugin Graveyard (updated June 2026), 90 WordPress plugins with 1,000+ active installations have not received a security or maintenance update in over 12 months. Of these, 47 have at least one known vulnerability documented in the Wordfence Intelligence database, affecting an estimated 4.2 million WordPress installations. Vulnerability severity is measured using the CVSS standard: 6 plugins carry critical-severity ratings, 15 carry high-severity ratings.

A plugin is listed here if it has not received a code update in 12 or more months. This is the point at which security researchers consider a plugin at elevated risk — enough time for unpatched vulnerabilities to be discovered and exploited.

No. Unmaintained does not mean immediately compromised. It means the risk is elevated and growing. A plugin with no known vulnerabilities but no recent updates is a lower-risk concern than one with a documented CVE. This directory shows both, clearly labelled.

Deactivate and delete the plugin immediately if there's a known vulnerability. If there's no documented vulnerability but the plugin is abandoned, assess whether you still need it — if so, find a maintained alternative. If you're not sure, a WordPress site audit will tell you exactly what to do.

Vulnerability information comes from Wordfence Intelligence, one of the most comprehensive WordPress security databases. Install counts and plugin metadata come from the WordPress.org API. Data refreshes automatically on the 1st of each month.

"Working" and "safe" are different things. A plugin can function correctly while containing a security vulnerability that allows an attacker to access your site. Hackers don't break your site — they quietly use it.

If you believe a plugin has been incorrectly listed (e.g. it received an update not yet reflected in the data), email [email protected]. Data refreshes monthly but we'll review urgent corrections manually.