惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Spread Privacy
Spread Privacy
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Cyberwarzone
Cyberwarzone
T
Tenable Blog
NISL@THU
NISL@THU
AWS News Blog
AWS News Blog
U
Unit 42
The Hacker News
The Hacker News
V
V2EX
MyScale Blog
MyScale Blog
阮一峰的网络日志
阮一峰的网络日志
L
Lohrmann on Cybersecurity
The GitHub Blog
The GitHub Blog
Vercel News
Vercel News
Y
Y Combinator Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
K
Kaspersky official blog
T
Threat Research - Cisco Blogs
S
Securelist
Simon Willison's Weblog
Simon Willison's Weblog
Jina AI
Jina AI
T
The Exploit Database - CXSecurity.com
B
Blog RSS Feed
WordPress大学
WordPress大学
I
Intezer
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
F
Fortinet All Blogs
W
WeLiveSecurity
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Recorded Future
Recorded Future
小众软件
小众软件
博客园 - Franky
Webroot Blog
Webroot Blog
Microsoft Azure Blog
Microsoft Azure Blog
P
Proofpoint News Feed
P
Privacy & Cybersecurity Law Blog
月光博客
月光博客
爱范儿
爱范儿
The Register - Security
The Register - Security
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Hacker News - Newest:
Hacker News - Newest: "LLM"
Application and Cybersecurity Blog
Application and Cybersecurity Blog
H
Hacker News: Front Page
T
The Blog of Author Tim Ferriss
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Threatpost
P
Palo Alto Networks Blog
S
Schneier on Security
Engineering at Meta
Engineering at Meta
J
Java Code Geeks

Show HN

暂无文章

WordPress Plugin Graveyard | Vimsy
Vimsy · 2026-06-14 · via Show HN

47

Have active vulnerabilities

Updated 2026-06-14 · Refreshes automatically on the 1st of every month

Why does an unmaintained plugin put your site at risk?

WordPress plugins are code running on your server. When a developer stops releasing updates:

  • Security vulnerabilities are discovered but never patched
  • The plugin falls out of compatibility with newer versions of WordPress and PHP
  • Hackers specifically target abandoned plugins because they know fixes won't come

The plugins in this directory haven't received an update in over 12 months. Many have known, publicly documented security vulnerabilities — meaning exploit code already exists.

If your site runs any of these, the risk is real and the fix is straightforward: remove or replace the plugin.

Get help removing abandoned plugins →

Browse the directory

Showing 90 of 90 plugins

Plugin Risk Level Last Update Sites Running It View Plugin

Limit Login Attempts

limit-login-attempts

CRITICAL (4)2023-04-04300K+WP.org ↗

Search & Replace

search-and-replace

CRITICAL (3)2024-08-26100K+WP.org ↗

YARPP – Yet Another Related Posts Plugin

yet-another-related-posts-plugin

CRITICAL (10)2024-11-11100K+WP.org ↗

OptionTree

option-tree

CRITICAL (5)2019-05-1950K+WP.org ↗

WP-Polls

wp-polls

CRITICAL (9)2025-01-1840K+WP.org ↗

Temporary Login

temporary-login

CRITICAL (1)2024-11-2640K+WP.org ↗

String locator

string-locator

HIGH (4)2025-01-15100K+WP.org ↗

CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress

advanced-nocaptcha-recaptcha

HIGH (7)2025-06-11100K+WP.org ↗

Custom Product Tabs for WooCommerce

yikes-inc-easy-custom-woocommerce-product-tabs

HIGH (3)2025-04-1280K+WP.org ↗

Facebook Chat Plugin – Live Chat Plugin for WordPress

facebook-messenger-customer-chat

HIGH (6)2022-07-0580K+WP.org ↗

Duplicate Page and Post

duplicate-wp-page-post

HIGH (6)2024-09-2380K+WP.org ↗

WP fail2ban – Advanced Security

wp-fail2ban

HIGH (8)2025-04-2960K+WP.org ↗

Web Stories

web-stories

HIGH (3)2025-05-1560K+WP.org ↗

Simple Sitemap – Create a Responsive HTML Sitemap

simple-sitemap

HIGH (8)2025-05-2060K+WP.org ↗

Add From Server

add-from-server

HIGH (4)2020-12-1160K+WP.org ↗

WP-DBManager

wp-dbmanager

HIGH (7)2024-11-2460K+WP.org ↗

Blogger Importer

blogger-importer

HIGH (1)2024-10-2160K+WP.org ↗

CMS Tree Page View

cms-tree-page-view

HIGH (8)2024-04-1250K+WP.org ↗

WP Extra File Types

wp-extra-file-types

HIGH (1)2023-10-2840K+WP.org ↗

User Profile Picture

metronet-profile-picture

HIGH (4)2024-07-1840K+WP.org ↗

Cornerstone

cornerstone

HIGH (4)2024-07-1630K+WP.org ↗

Template Kit – Import

template-kit-import

MEDIUM (1)2024-08-01400K+WP.org ↗

Health Check & Troubleshooting

health-check

MEDIUM (11)2024-07-25300K+WP.org ↗

WP Sitemap Page

wp-sitemap-page

MEDIUM (1)2025-04-15200K+WP.org ↗

Table of Contents Plus

table-of-contents-plus

MEDIUM (7)2024-11-21200K+WP.org ↗

PHP Compatibility Checker

php-compatibility-checker

MEDIUM (1)2023-12-14200K+WP.org ↗

WooSidebars

woosidebars

MEDIUM (1)2024-04-03100K+WP.org ↗

WP Downgrade | Specific Core Version

wp-downgrade

MEDIUM (1)2023-05-08100K+WP.org ↗

LuckyWP Table of Contents

luckywp-table-of-contents

MEDIUM (6)2025-04-16100K+WP.org ↗

BackUpWordPress

backupwordpress

MEDIUM (4)2024-04-2490K+WP.org ↗

Hotjar

hotjar

MEDIUM (1)2023-10-2570K+WP.org ↗

Async JavaScript

async-javascript

MEDIUM (7)2023-06-2270K+WP.org ↗

WP Show Posts

wp-show-posts

MEDIUM (4)2024-04-1670K+WP.org ↗

Better Font Awesome

better-font-awesome

MEDIUM (3)2025-02-1270K+WP.org ↗

Enhanced Media Library

enhanced-media-library

MEDIUM (1)2024-07-1560K+WP.org ↗

Dynamic Conditions

dynamicconditions

MEDIUM (1)2025-02-1160K+WP.org ↗

A2 Optimized WP – Turbocharge and secure your WordPress site

a2-optimized-wp

MEDIUM (1)2025-02-1060K+WP.org ↗

All In One Favicon

all-in-one-favicon

MEDIUM (2)2023-08-0860K+WP.org ↗

Sydney Toolbox

sydney-toolbox

MEDIUM (5)2024-12-1750K+WP.org ↗

If Menu – Visibility control for Menus

if-menu

MEDIUM (2)2024-12-0550K+WP.org ↗

Image Hover Effects – Elementor Addon

image-hover-effects-addon-for-elementor

MEDIUM (6)2024-07-1240K+WP.org ↗

WP Edit

wp-edit

MEDIUM (1)2018-10-1540K+WP.org ↗

underConstruction

underconstruction

MEDIUM (5)2024-03-0840K+WP.org ↗

FancyBox for WordPress

fancybox-for-wordpress

MEDIUM (4)2025-05-0730K+WP.org ↗

Enhanced Text Widget

enhanced-text-widget

MEDIUM (7)2024-07-1730K+WP.org ↗

DethemeKit for Elementor

dethemekit-for-elementor

MEDIUM (14)2025-03-1330K+WP.org ↗

Adapta RGPD

adapta-rgpd

No vuln (3)2025-06-1740K+WP.org ↗

WP-PageNavi

wp-pagenavi

No vuln2024-12-19500K+WP.org ↗

AMP

amp

No vuln2025-04-10400K+WP.org ↗

WooCommerce Legacy REST API

woocommerce-legacy-rest-api

No vuln2025-01-23400K+WP.org ↗

Child Theme Configurator

child-theme-configurator

No vuln2025-06-10300K+WP.org ↗

Really Simple CAPTCHA

really-simple-captcha

No vuln2025-02-01300K+WP.org ↗

Layout Grid Block

layout-grid

No vuln2023-07-11200K+WP.org ↗

Easy Google Fonts

easy-google-fonts

No vuln2021-07-23100K+WP.org ↗

Simple Custom CSS Plugin

simple-custom-css

No vuln2025-03-11100K+WP.org ↗

Edit Author Slug

edit-author-slug

No vuln2025-05-27100K+WP.org ↗

AddQuicktag

addquicktag

No vuln2021-05-20100K+WP.org ↗

Local Google Fonts

local-google-fonts

No vuln2025-05-01100K+WP.org ↗

Disable REST API

disable-json-api

No vuln2023-09-1490K+WP.org ↗

Widget CSS Classes

widget-css-classes

No vuln2024-11-1290K+WP.org ↗

Invisible reCaptcha for WordPress

invisible-recaptcha

No vuln2020-04-0780K+WP.org ↗

Fixed Widget and Sticky Elements for WordPress

q2w3-fixed-widget

No vuln2023-03-3080K+WP.org ↗

PHP Code Widget

php-code-widget

No vuln2022-03-3080K+WP.org ↗

Display Posts – Easy lists, grids, navigation, and more

display-posts-shortcode

No vuln2024-10-1480K+WP.org ↗

Heartbeat Control

heartbeat-control

No vuln2023-08-3180K+WP.org ↗

Advanced Excerpt

advanced-excerpt

No vuln2024-01-1980K+WP.org ↗

Title Remover

title-remover

No vuln2021-06-0370K+WP.org ↗

Brazilian Market on WooCommerce

woocommerce-extra-checkout-fields-for-brazil

No vuln2024-02-1770K+WP.org ↗

Easy Theme and Plugin Upgrades

easy-theme-and-plugin-upgrades

No vuln2022-04-2070K+WP.org ↗

Column Shortcodes

column-shortcodes

No vuln2022-10-1160K+WP.org ↗

HTML Editor Syntax Highlighter

html-editor-syntax-highlighter

No vuln2024-03-1650K+WP.org ↗

ActiveCampaign Postmark for WordPress

postmark-approved-wordpress-plugin

No vuln2024-11-1850K+WP.org ↗

Easy SSL Plugin for SAKURA Rental Server

sakura-rs-wp-ssl

No vuln2019-11-2550K+WP.org ↗

Categories to Tags Converter

wpcat2tag-importer

No vuln2024-10-2150K+WP.org ↗

Contact Form 7 add confirm

contact-form-7-add-confirm

No vuln2018-02-2750K+WP.org ↗

Portfolio Post Type

portfolio-post-type

No vuln2020-08-2950K+WP.org ↗

Clear Cache for Me

clear-cache-for-widgets

No vuln2025-06-0940K+WP.org ↗

Revision Control

revision-control

No vuln2018-04-0140K+WP.org ↗

Hide Page And Post Title

hide-page-and-post-title

No vuln2024-09-2340K+WP.org ↗

Increase Maximum Upload File Size

upload-max-file-size

No vuln2023-08-1440K+WP.org ↗

Login Logo

login-logo

No vuln2024-09-1140K+WP.org ↗

Disable Google Fonts

disable-google-fonts

No vuln2019-02-2440K+WP.org ↗

Really Simple CSV Importer

really-simple-csv-importer

No vuln2017-11-2840K+WP.org ↗

Schema

schema

No vuln2025-06-1440K+WP.org ↗

Disable Search

disable-search

No vuln2025-04-1440K+WP.org ↗

Export Media Library

export-media-library

No vuln2023-04-0530K+WP.org ↗

Hide Title

hide-title

No vuln2019-05-2230K+WP.org ↗

reCAPTCHA for MW WP Form

recaptcha-for-mw-wp-form

No vuln2024-05-0930K+WP.org ↗

Display PHP Version

display-php-version

No vuln2023-05-1630K+WP.org ↗

Elementor Beta (Developer Edition)

elementor-beta

No vuln2025-03-0430K+WP.org ↗

Frequently Asked Questions

According to Vimsy's Plugin Graveyard (updated June 2026), 90 WordPress plugins with 1,000+ active installations have not received a security or maintenance update in over 12 months. Of these, 47 have at least one known vulnerability documented in the Wordfence Intelligence database, affecting an estimated 4.2 million WordPress installations. Vulnerability severity is measured using the CVSS standard: 6 plugins carry critical-severity ratings, 15 carry high-severity ratings.

A plugin is listed here if it has not received a code update in 12 or more months. This is the point at which security researchers consider a plugin at elevated risk — enough time for unpatched vulnerabilities to be discovered and exploited.

No. Unmaintained does not mean immediately compromised. It means the risk is elevated and growing. A plugin with no known vulnerabilities but no recent updates is a lower-risk concern than one with a documented CVE. This directory shows both, clearly labelled.

Deactivate and delete the plugin immediately if there's a known vulnerability. If there's no documented vulnerability but the plugin is abandoned, assess whether you still need it — if so, find a maintained alternative. If you're not sure, a WordPress site audit will tell you exactly what to do.

Vulnerability information comes from Wordfence Intelligence, one of the most comprehensive WordPress security databases. Install counts and plugin metadata come from the WordPress.org API. Data refreshes automatically on the 1st of each month.

"Working" and "safe" are different things. A plugin can function correctly while containing a security vulnerability that allows an attacker to access your site. Hackers don't break your site — they quietly use it.

If you believe a plugin has been incorrectly listed (e.g. it received an update not yet reflected in the data), email [email protected]. Data refreshes monthly but we'll review urgent corrections manually.