A closed plugin shows a red notice on its WordPress.org page and stops getting updates through the directory. Installed copies keep running, so nothing on the site tells you. The notice gives the closure date, and only after 60 days does it show the reason. WordPress.org doesn't share details beyond the reason with anyone outside its security team and the plugin's authors.
Free tool: Check up to 10 client sites: versions, closed plugins and known vulnerabilities
Paste site addresses; it reads public files only and compares them with WordPress.org and the Wordfence Intelligence database.
/wp-content/plugins/<slug>/, and the installed version is in that folder's readme.txt.A closure doesn't show in the WordPress dashboard, and most management tools only report updates. Checking each installed plugin's WordPress.org status every week, or after a security mailing list mentions one, is the only way to hear about it before a client does.
Free tool: Check up to 10 client sites: versions, closed plugins and known vulnerabilities
Paste site addresses; it reads public files only and compares them with WordPress.org and the Wordfence Intelligence database.
When did you last find out a plugin on a client site was closed or vulnerable, and how (a scanner, an email, a hack)?
We're researching this problem and read every answer. Tell us what happened (4 short questions, no sign-up; AI tools help us read the answers).