惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
博客园 - Franky
博客园 - 三生石上(FineUI控件)
爱范儿
爱范儿
博客园 - 司徒正美
博客园 - 叶小钗
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
B
Blog RSS Feed
阮一峰的网络日志
阮一峰的网络日志
宝玉的分享
宝玉的分享
V
Visual Studio Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
IT之家
IT之家
博客园_首页
S
SegmentFault 最新的问题
A
About on SuperTechFans
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
H
Help Net Security
MongoDB | Blog
MongoDB | Blog

Show HN

Show HN: AI agents for UK GDAD PCF roles and their skills The Two Pillars: Mixer Mode and Meta-Software in the Reorganization of Software Work After AI GitHub - JaiCode08/teleport-env What 1,000+ Harness Experiments Taught Me About Self-Improving Agents Show HN: Liiists, a Markdown-first, iOS and CLI list app SwiperTab – Get this Extension for 🦊 Firefox (en-US) GitHub - kouhxp/fftext: Summarize, explain, fact-check, or translate any text, URL, or file. No GPU. No cloud. One command GitHub - sweetpad-dev/sweetpad: Develop Swift/iOS projects using VSCode GitHub - dogmaticdev/IRON: IRON a.k.a. Intermediate Representation Object Notation is a Interpreter/Database that is used to create Programming Languages. GitHub - sjhalani7/vaen: Package your AI coding harness into a portable .agent file, and share it across repos, teams, & the community without ever having to copy-paste instructions, skills, MCP config, or secrets. Show HN: Gandalf the Grader Show HN: Citadeld – replay any CI failure locally from a single file GitHub - tdortman/cuSBF: High-Performance GPU Super Bloom Filter coral-ai/claude-code-token-xray at main · Coral-Bricks-AI/coral-ai GitHub - ulyssestenn/funes: Funes is a Git-based framework for LLM-managed knowledge work: an AI Librarian ingests raw sources, builds an interlinked Markdown knowledge base, and uses it to produce cited reports, analyses, and other outputs. GitHub - ThatXliner/gah: Git Add Hunk, built for agents to use GitHub - harmont-dev/harmont-cli: Command-line client for the Harmont CI platform GitHub - brooksmcmillin/mcp-authflow: OAuth 2.0 Authorization Server framework for MCP servers GitHub - javaid-codes/audit-supply-chain-agents GitHub - amorey/gochan: A small library of common channel architectures for Go, inspired by Rust GitHub - arifozgun/OpenGem: Free, Open-Source AI API Gateway with Gemini, OpenAI & Anthropic Compatibility in 1 file GitHub - Pranesh950/BioPetals: 🌸 Run BIOxAI models at home, BitTorrent-style. Fine-tuning and inference up to 10x faster than offloading GitHub - cnguyen14/bounty-doctor: Diagnose a GitHub bounty issue before you waste hours: detects honeypot scam repos, AI-bot attempt swarms, and stale contests. Show HN: CoreMCP – MCP Server for On-Prem DBs Show HN: KittyHTML – Render HTML/CSS as an inline image in your terminal GitHub - bingud/filemat: Web-based file manager Show HN: TruthLens – Free multi-signal deepfake image detector GitHub - apexlocal-jz/claude-usage-tray: Windows system-tray app showing your Claude Code rate-limit usage at a glance. Zero deps, ~300 lines of PowerShell. Cross-IDE (works regardless of VS Code, Cursor, plain terminal). Release v0.1.2.1 · kouhxp/yapsnap GitHub - noopolis/moltnet: Self-hostable chat network for AI agents. Pre-built bridges for Claude Code, Codex, and the Claws. Rooms, DMs, history. No Slack bots, no Matrix, no glue code.
WordPress Plugin Graveyard | Vimsy
Vimsy · 2026-06-14 · via Show HN

47

Have active vulnerabilities

Updated 2026-06-14 · Refreshes automatically on the 1st of every month

Why does an unmaintained plugin put your site at risk?

WordPress plugins are code running on your server. When a developer stops releasing updates:

  • Security vulnerabilities are discovered but never patched
  • The plugin falls out of compatibility with newer versions of WordPress and PHP
  • Hackers specifically target abandoned plugins because they know fixes won't come

The plugins in this directory haven't received an update in over 12 months. Many have known, publicly documented security vulnerabilities — meaning exploit code already exists.

If your site runs any of these, the risk is real and the fix is straightforward: remove or replace the plugin.

Get help removing abandoned plugins →

Browse the directory

Showing 90 of 90 plugins

Plugin Risk Level Last Update Sites Running It View Plugin

Limit Login Attempts

limit-login-attempts

CRITICAL (4)2023-04-04300K+WP.org ↗

Search & Replace

search-and-replace

CRITICAL (3)2024-08-26100K+WP.org ↗

YARPP – Yet Another Related Posts Plugin

yet-another-related-posts-plugin

CRITICAL (10)2024-11-11100K+WP.org ↗

OptionTree

option-tree

CRITICAL (5)2019-05-1950K+WP.org ↗

WP-Polls

wp-polls

CRITICAL (9)2025-01-1840K+WP.org ↗

Temporary Login

temporary-login

CRITICAL (1)2024-11-2640K+WP.org ↗

String locator

string-locator

HIGH (4)2025-01-15100K+WP.org ↗

CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress

advanced-nocaptcha-recaptcha

HIGH (7)2025-06-11100K+WP.org ↗

Custom Product Tabs for WooCommerce

yikes-inc-easy-custom-woocommerce-product-tabs

HIGH (3)2025-04-1280K+WP.org ↗

Facebook Chat Plugin – Live Chat Plugin for WordPress

facebook-messenger-customer-chat

HIGH (6)2022-07-0580K+WP.org ↗

Duplicate Page and Post

duplicate-wp-page-post

HIGH (6)2024-09-2380K+WP.org ↗

WP fail2ban – Advanced Security

wp-fail2ban

HIGH (8)2025-04-2960K+WP.org ↗

Web Stories

web-stories

HIGH (3)2025-05-1560K+WP.org ↗

Simple Sitemap – Create a Responsive HTML Sitemap

simple-sitemap

HIGH (8)2025-05-2060K+WP.org ↗

Add From Server

add-from-server

HIGH (4)2020-12-1160K+WP.org ↗

WP-DBManager

wp-dbmanager

HIGH (7)2024-11-2460K+WP.org ↗

Blogger Importer

blogger-importer

HIGH (1)2024-10-2160K+WP.org ↗

CMS Tree Page View

cms-tree-page-view

HIGH (8)2024-04-1250K+WP.org ↗

WP Extra File Types

wp-extra-file-types

HIGH (1)2023-10-2840K+WP.org ↗

User Profile Picture

metronet-profile-picture

HIGH (4)2024-07-1840K+WP.org ↗

Cornerstone

cornerstone

HIGH (4)2024-07-1630K+WP.org ↗

Template Kit – Import

template-kit-import

MEDIUM (1)2024-08-01400K+WP.org ↗

Health Check & Troubleshooting

health-check

MEDIUM (11)2024-07-25300K+WP.org ↗

WP Sitemap Page

wp-sitemap-page

MEDIUM (1)2025-04-15200K+WP.org ↗

Table of Contents Plus

table-of-contents-plus

MEDIUM (7)2024-11-21200K+WP.org ↗

PHP Compatibility Checker

php-compatibility-checker

MEDIUM (1)2023-12-14200K+WP.org ↗

WooSidebars

woosidebars

MEDIUM (1)2024-04-03100K+WP.org ↗

WP Downgrade | Specific Core Version

wp-downgrade

MEDIUM (1)2023-05-08100K+WP.org ↗

LuckyWP Table of Contents

luckywp-table-of-contents

MEDIUM (6)2025-04-16100K+WP.org ↗

BackUpWordPress

backupwordpress

MEDIUM (4)2024-04-2490K+WP.org ↗

Hotjar

hotjar

MEDIUM (1)2023-10-2570K+WP.org ↗

Async JavaScript

async-javascript

MEDIUM (7)2023-06-2270K+WP.org ↗

WP Show Posts

wp-show-posts

MEDIUM (4)2024-04-1670K+WP.org ↗

Better Font Awesome

better-font-awesome

MEDIUM (3)2025-02-1270K+WP.org ↗

Enhanced Media Library

enhanced-media-library

MEDIUM (1)2024-07-1560K+WP.org ↗

Dynamic Conditions

dynamicconditions

MEDIUM (1)2025-02-1160K+WP.org ↗

A2 Optimized WP – Turbocharge and secure your WordPress site

a2-optimized-wp

MEDIUM (1)2025-02-1060K+WP.org ↗

All In One Favicon

all-in-one-favicon

MEDIUM (2)2023-08-0860K+WP.org ↗

Sydney Toolbox

sydney-toolbox

MEDIUM (5)2024-12-1750K+WP.org ↗

If Menu – Visibility control for Menus

if-menu

MEDIUM (2)2024-12-0550K+WP.org ↗

Image Hover Effects – Elementor Addon

image-hover-effects-addon-for-elementor

MEDIUM (6)2024-07-1240K+WP.org ↗

WP Edit

wp-edit

MEDIUM (1)2018-10-1540K+WP.org ↗

underConstruction

underconstruction

MEDIUM (5)2024-03-0840K+WP.org ↗

FancyBox for WordPress

fancybox-for-wordpress

MEDIUM (4)2025-05-0730K+WP.org ↗

Enhanced Text Widget

enhanced-text-widget

MEDIUM (7)2024-07-1730K+WP.org ↗

DethemeKit for Elementor

dethemekit-for-elementor

MEDIUM (14)2025-03-1330K+WP.org ↗

Adapta RGPD

adapta-rgpd

No vuln (3)2025-06-1740K+WP.org ↗

WP-PageNavi

wp-pagenavi

No vuln2024-12-19500K+WP.org ↗

AMP

amp

No vuln2025-04-10400K+WP.org ↗

WooCommerce Legacy REST API

woocommerce-legacy-rest-api

No vuln2025-01-23400K+WP.org ↗

Child Theme Configurator

child-theme-configurator

No vuln2025-06-10300K+WP.org ↗

Really Simple CAPTCHA

really-simple-captcha

No vuln2025-02-01300K+WP.org ↗

Layout Grid Block

layout-grid

No vuln2023-07-11200K+WP.org ↗

Easy Google Fonts

easy-google-fonts

No vuln2021-07-23100K+WP.org ↗

Simple Custom CSS Plugin

simple-custom-css

No vuln2025-03-11100K+WP.org ↗

Edit Author Slug

edit-author-slug

No vuln2025-05-27100K+WP.org ↗

AddQuicktag

addquicktag

No vuln2021-05-20100K+WP.org ↗

Local Google Fonts

local-google-fonts

No vuln2025-05-01100K+WP.org ↗

Disable REST API

disable-json-api

No vuln2023-09-1490K+WP.org ↗

Widget CSS Classes

widget-css-classes

No vuln2024-11-1290K+WP.org ↗

Invisible reCaptcha for WordPress

invisible-recaptcha

No vuln2020-04-0780K+WP.org ↗

Fixed Widget and Sticky Elements for WordPress

q2w3-fixed-widget

No vuln2023-03-3080K+WP.org ↗

PHP Code Widget

php-code-widget

No vuln2022-03-3080K+WP.org ↗

Display Posts – Easy lists, grids, navigation, and more

display-posts-shortcode

No vuln2024-10-1480K+WP.org ↗

Heartbeat Control

heartbeat-control

No vuln2023-08-3180K+WP.org ↗

Advanced Excerpt

advanced-excerpt

No vuln2024-01-1980K+WP.org ↗

Title Remover

title-remover

No vuln2021-06-0370K+WP.org ↗

Brazilian Market on WooCommerce

woocommerce-extra-checkout-fields-for-brazil

No vuln2024-02-1770K+WP.org ↗

Easy Theme and Plugin Upgrades

easy-theme-and-plugin-upgrades

No vuln2022-04-2070K+WP.org ↗

Column Shortcodes

column-shortcodes

No vuln2022-10-1160K+WP.org ↗

HTML Editor Syntax Highlighter

html-editor-syntax-highlighter

No vuln2024-03-1650K+WP.org ↗

ActiveCampaign Postmark for WordPress

postmark-approved-wordpress-plugin

No vuln2024-11-1850K+WP.org ↗

Easy SSL Plugin for SAKURA Rental Server

sakura-rs-wp-ssl

No vuln2019-11-2550K+WP.org ↗

Categories to Tags Converter

wpcat2tag-importer

No vuln2024-10-2150K+WP.org ↗

Contact Form 7 add confirm

contact-form-7-add-confirm

No vuln2018-02-2750K+WP.org ↗

Portfolio Post Type

portfolio-post-type

No vuln2020-08-2950K+WP.org ↗

Clear Cache for Me

clear-cache-for-widgets

No vuln2025-06-0940K+WP.org ↗

Revision Control

revision-control

No vuln2018-04-0140K+WP.org ↗

Hide Page And Post Title

hide-page-and-post-title

No vuln2024-09-2340K+WP.org ↗

Increase Maximum Upload File Size

upload-max-file-size

No vuln2023-08-1440K+WP.org ↗

Login Logo

login-logo

No vuln2024-09-1140K+WP.org ↗

Disable Google Fonts

disable-google-fonts

No vuln2019-02-2440K+WP.org ↗

Really Simple CSV Importer

really-simple-csv-importer

No vuln2017-11-2840K+WP.org ↗

Schema

schema

No vuln2025-06-1440K+WP.org ↗

Disable Search

disable-search

No vuln2025-04-1440K+WP.org ↗

Export Media Library

export-media-library

No vuln2023-04-0530K+WP.org ↗

Hide Title

hide-title

No vuln2019-05-2230K+WP.org ↗

reCAPTCHA for MW WP Form

recaptcha-for-mw-wp-form

No vuln2024-05-0930K+WP.org ↗

Display PHP Version

display-php-version

No vuln2023-05-1630K+WP.org ↗

Elementor Beta (Developer Edition)

elementor-beta

No vuln2025-03-0430K+WP.org ↗

Frequently Asked Questions

According to Vimsy's Plugin Graveyard (updated June 2026), 90 WordPress plugins with 1,000+ active installations have not received a security or maintenance update in over 12 months. Of these, 47 have at least one known vulnerability documented in the Wordfence Intelligence database, affecting an estimated 4.2 million WordPress installations. Vulnerability severity is measured using the CVSS standard: 6 plugins carry critical-severity ratings, 15 carry high-severity ratings.

A plugin is listed here if it has not received a code update in 12 or more months. This is the point at which security researchers consider a plugin at elevated risk — enough time for unpatched vulnerabilities to be discovered and exploited.

No. Unmaintained does not mean immediately compromised. It means the risk is elevated and growing. A plugin with no known vulnerabilities but no recent updates is a lower-risk concern than one with a documented CVE. This directory shows both, clearly labelled.

Deactivate and delete the plugin immediately if there's a known vulnerability. If there's no documented vulnerability but the plugin is abandoned, assess whether you still need it — if so, find a maintained alternative. If you're not sure, a WordPress site audit will tell you exactly what to do.

Vulnerability information comes from Wordfence Intelligence, one of the most comprehensive WordPress security databases. Install counts and plugin metadata come from the WordPress.org API. Data refreshes automatically on the 1st of each month.

"Working" and "safe" are different things. A plugin can function correctly while containing a security vulnerability that allows an attacker to access your site. Hackers don't break your site — they quietly use it.

If you believe a plugin has been incorrectly listed (e.g. it received an update not yet reflected in the data), email [email protected]. Data refreshes monthly but we'll review urgent corrections manually.