How to check a WordPress plugin before you install it

You do not need to read code. Six checks, four minutes, and you will know more about a plugin than most people who install it.

You have found a plugin that does exactly what you need. A booking calendar, a popup, a way to add reviews to a product page. The description is confident, the screenshots look tidy, and there is an Install button right there. Before you press it, four minutes of looking will tell you whether this thing is going to sit on your site quietly, or whether it is going to be the reason somebody rings you in six months asking why the site looks funny.

You do not need to read a line of code for any of this. It is all on the plugin’s own listing page, in the WordPress repository or wherever you found it.

When it was last updated

Scroll to “Last updated” on the plugin page. Anything under three months is healthy. Anything over a year is a plugin nobody is maintaining, whether or not it still works today.

This matters more than almost anything else on this list, because WordPress core changes underneath every plugin, and so does PHP, and so do the tools attackers use to find weaknesses. A plugin that has not been touched in eighteen months is not neutral. It is a piece of unpatched software with your name on the invoice, waiting for someone to find the hole nobody has fixed because nobody is looking.

If you already run a plugin like this, the fix is not an update. There will not be one. The fix is to replace it with something maintained.

Installs against support threads

The repository shows “Active installations”, rounded to a range: 10,000+, 100,000+, and so on. On its own that number tells you popularity, not safety. Cross-reference it against the Support tab.

A plugin with 50,000 installs and an open, mostly-answered support forum is in reasonable shape. A plugin with 50,000 installs and forty unanswered threads going back a year is a plugin that has been abandoned by its author while still being used by tens of thousands of people who have not noticed. That gap between installs and responses is the tell. A small plugin with five active threads, all answered within a week, is safer than a big one nobody is minding.

The changelog

Below the description sits a Changelog tab, a list of every version and what changed in it. Read the last five or six entries.

You are looking for the word “security”: a fix, a hardening, a patch. Seeing it is a good sign, not a bad one. It means the author finds problems and closes them in public, which is exactly what you want from software you did not write yourself. What should worry you is a changelog that only ever says “minor fixes” and “improvements” for two years straight. Either nothing has ever gone wrong, which is unlikely for a plugin doing anything non-trivial, or nobody is looking closely enough to say what did.

Whether the author answers

Pick two or three support threads at random, ideally ones asking about something going wrong rather than a feature request. Read how the author responds. A reply within a few days, in plain English, that addresses the question, tells you there is a real person behind this plugin who treats it as more than a hobby they abandoned. Silence, or a reply that copies and pastes the same stock answer to everyone, tells you the opposite.

This is the same judgement you would make about a tradesperson from their reviews. Not whether they are perfect, but whether they show up when something is wrong.

Its vulnerability history

Search the plugin’s name alongside the word “vulnerability” or “CVE”. Several free databases track known security holes in WordPress plugins by name, and a plugin having appeared in one is not automatically a reason to avoid it. What matters is what happened next: how long the fix took, and whether you can see it in the changelog above.

A plugin with a vulnerability patched within a week of being reported is a plugin whose author takes it seriously. A plugin with a vulnerability that sat open for months, or one that has never been mentioned anywhere but has stopped receiving updates for a year or more, is the one to walk away from.

What it asks permission for

Last, look at what the plugin needs to do its job. A gallery plugin has no reason to want access to your users list. A contact form has no reason to need your WooCommerce order data. Most plugin listings describe what they connect to and what data they touch, usually near the bottom of the description or in a privacy section.

This is the same instinct you already use on your phone, where an app asking for your contacts to show you a torch is wrong. Apply it here. If a plugin’s request for access does not match what it visibly does on your site, that is worth a question before it is worth an install.

What this buys you

None of this guarantees a plugin is safe. It rules out the two ways most WordPress sites get hacked through plugins: something abandoned that nobody patches, and something badly built that nobody catches. Between them those cover most of what we find when we clean up a hacked site.

The four minutes are worth it before you install anything that touches payments, user data, or the parts of the site your customers see first. For everything already installed, the same six checks are worth doing once, this afternoon, rather than after something goes wrong.

If you would rather hand the whole question over, that is what our Care & Hosting covers: someone who already knows which plugins are worth trusting, for £49 a month.

Would you rather somebody sorted this for you?

We look after websites for £49 a month — hosting, updates, backups, security and small changes. Moving an existing site over is free. Or get a free review first and we will tell you what is actually wrong with the one you have.

Get a free website review See Care & Hosting