You have a graveyard of inactive plugins sitting in your WordPress installation. Even when deactivated, they're a security risk — their files are still on your server, accessible and exploitable.

Why This Matters

Deactivated plugins:

  • Still have PHP files on your server that can be directly accessed via URL
  • Don't receive your attention — you might miss critical security updates for plugins you're not using
  • Increase your attack surface — each plugin is code that could contain a vulnerability
  • Add clutter to your plugin list, making management harder
  • Slow down updates — WordPress still checks for updates on inactive plugins

A 2023 study found that 29% of WordPress vulnerabilities were in plugins that site owners had deactivated but not deleted.

How to Fix It

Safe Practice: Before making any technical changes, ensure you have a full backup of your site (files and database) via your hosting control panel or a dedicated plugin like UpdraftPlus.

  1. Go to Plugins → Installed Plugins
  2. Click the "Inactive" filter at the top
  3. For each inactive plugin, ask: "Will I use this in the next 30 days?"
  4. If no → Delete it (not just deactivate — delete)
  5. If maybe → keep it but set a reminder to decide in 30 days

Bulk Delete

  1. Check the checkbox next to each plugin you want to remove
  2. From the "Bulk actions" dropdown, select Delete
  3. Click Apply

What to Watch For

  • You can always reinstall a plugin from the WordPress directory. Don't keep plugins "just in case."
  • If you're worried about losing settings, most plugins store their data in the database — not in the plugin files. Reinstalling usually restores your settings.
  • Exception: Premium plugins that aren't in the WordPress directory should be backed up before deletion. Download the zip file first.
  • After deleting plugins, check your site to make sure nothing breaks. Some themes depend on specific plugins being present (even if inactive).