You have a graveyard of inactive plugins sitting in your WordPress installation. Even when deactivated, they're a security risk — their files are still on your server, accessible and exploitable.
Why This Matters
Deactivated plugins:
- Still have PHP files on your server that can be directly accessed via URL
- Don't receive your attention — you might miss critical security updates for plugins you're not using
- Increase your attack surface — each plugin is code that could contain a vulnerability
- Add clutter to your plugin list, making management harder
- Slow down updates — WordPress still checks for updates on inactive plugins
A 2023 study found that 29% of WordPress vulnerabilities were in plugins that site owners had deactivated but not deleted.
How to Fix It
Safe Practice: Before making any technical changes, ensure you have a full backup of your site (files and database) via your hosting control panel or a dedicated plugin like UpdraftPlus.
- Go to Plugins → Installed Plugins
- Click the "Inactive" filter at the top
- For each inactive plugin, ask: "Will I use this in the next 30 days?"
- If no → Delete it (not just deactivate — delete)
- If maybe → keep it but set a reminder to decide in 30 days
Bulk Delete
- Check the checkbox next to each plugin you want to remove
- From the "Bulk actions" dropdown, select Delete
- Click Apply
What to Watch For
- You can always reinstall a plugin from the WordPress directory. Don't keep plugins "just in case."
- If you're worried about losing settings, most plugins store their data in the database — not in the plugin files. Reinstalling usually restores your settings.
- Exception: Premium plugins that aren't in the WordPress directory should be backed up before deletion. Download the zip file first.
- After deleting plugins, check your site to make sure nothing breaks. Some themes depend on specific plugins being present (even if inactive).