Site Fleet HealthGuide

A plugin on your sites was closed on WordPress.org: what now?

Updated 2026-10-11 ยท by Hieu Tran, written with AI agents and checked against the sources below

A closed plugin shows a red notice on its WordPress.org page and stops getting updates through the directory. Installed copies keep running, so nothing on the site tells you. The notice gives the closure date, and only after 60 days does it show the reason. WordPress.org doesn't share details beyond the reason with anyone outside its security team and the plugin's authors.

Free tool: Check up to 10 client sites: versions, closed plugins and known vulnerabilities

Paste site addresses; it reads public files only and compares them with WordPress.org and the Wordfence Intelligence database.

The five reasons

What to do

  1. Find every site running it. Plugin folders show in page source as /wp-content/plugins/<slug>/, and the installed version is in that folder's readme.txt.
  2. Closed in the last 60 days with no reason yet: assume the worst until it's known. If the plugin isn't essential, deactivate it now.
  3. Security Issue: check vulnerability databases (Wordfence Intelligence, WPScan, Patchstack) for the plugin and your version. Replace or remove it; if it was exploitable on your version, check the site for signs of compromise.
  4. Author Request or Guideline Violation: no updates are coming from the directory. Plan a replacement, and check whether the author moved it elsewhere; then you're trusting a new update source.
  5. Write it down per client: which sites, which version, what you did and when. That's the record you'll want if the client asks later.

Catch the next one

A closure doesn't show in the WordPress dashboard, and most management tools only report updates. Checking each installed plugin's WordPress.org status every week, or after a security mailing list mentions one, is the only way to hear about it before a client does.

Free tool: Check up to 10 client sites: versions, closed plugins and known vulnerabilities

Paste site addresses; it reads public files only and compares them with WordPress.org and the Wordfence Intelligence database.

When did you last find out a plugin on a client site was closed or vulnerable, and how (a scanner, an email, a hack)?

We're researching this problem and read every answer. Tell us what happened (4 short questions, no sign-up; AI tools help us read the answers).

More guides