123,970 slugs, 70,909 of them listed: we counted the entire WordPress plugin directory
On 28 August 2026 we fetched every plugin listed in the WordPress directory and matched it against every slug the directory has ever issued. This is the workshop report: how we counted, what came out, and where the numbers stop saying anything.
"How many WordPress plugins are there?" sounds like a question with one number for an answer. There are at least two. The official statistics page on wordpress.org shows which WordPress, PHP and database versions are in use and in which languages; it gives no plugin count (as of October 4, 2026). The plugin API does report a total while you page through it, just a different one depending on how you sort. While we were collecting, "by recency" and "by popularity" were about 4,100 plugins apart. We repeated both calls on October 4: the totals still disagree.
So we counted. Every listed plugin fetched one by one, every slug matched against the list of all slugs the directory has ever issued. The result is the Plugin Directory Census 01/2026, a full count of the WordPress plugin directory with an open method.
Two numbers instead of one
Every plugin in the directory gets a slug: the folder name it lives under, such as contact-form-7. The slug stays taken even after the plugin drops out of the listings. That gives you two populations, and both are real:
| Metric on 28 Aug 2026 | Value | Source |
|---|---|---|
| slugs ever issued | 123,970 | SVN directory listing plus late additions |
| listed plugins | 70,909 | plugin API, fetched in full |
| no longer listed | 53,061 (42.8%) | exact set difference |
| no release for more than 365 days | 41,395 (58.4%) | field last_updated |
| installs in total | 324.8 to 482.3 million | field active_installs, as a range |
The third row is the one people trip over. Two in five slugs ever issued are not listed today. It sounds more dramatic than it is, and still nobody had pinned this number down cleanly before. Other projects do measure the directory regularly; the census page names them under "How many plugins are in the WordPress plugin directory?", and the census replaces none of them. What is new is the denominator: the complete list of every slug ever issued.
How we counted
The directory: every page of the API
The source is the public wordpress.org plugin API, the query_plugins action sorted by recency. 284 pages of 250 entries, one request every 250 milliseconds, 190 seconds in total. No key, no login, no dependency beyond Node.js.
In practice the API has quirks you only notice when a total refuses to add up:
- Sorting changes the population. Page through by popularity and roughly 4,100 plugins never show up, with nothing to tell you. We only page by recency.
- The reported page count is wrong. On one search, page 1 announced 11 pages; page 11 then announced 27. Our snapshot stops at the first empty page, not at the number the API reports.
- Anything past page 999 quietly returns page 999. That does not matter for a full snapshot, which ends after 284 pages. The script has a guard for it anyway.
- The directory moves while you read it. Six records turned up on two pages because plugins were updated mid-run. They are deduplicated by slug.
Every day count is measured against one fixed point: 28 August 2026, 21:56:30 UTC. Otherwise "more than a year without a release" would depend on when someone happened to start the script.
The denominator: the SVN listing
Every plugin ever accepted into the directory has a folder in the wordpress.org Subversion repository. The folder listing from 27 August 2026 had 123,921 entries. 49 plugins were added between that listing and the directory snapshot the next day; they appear in the directory but not yet in the listing, and they count as issued. That makes 123,970 slugs ever issued. "Not listed" stops being an estimate and becomes the exact difference between two sets: 53,061.
This is the real difference from a sample. A sample gives you an estimate with error bars. A full census gives you an exact figure for everything that can be counted. The only fuzziness left is whatever the source itself reports fuzzily, and we will get to that.
Cross-checks and checksums
Before a number goes on the page, a validation run checks it against the rest. The latest one, from 14 September 2026, has 25 checks, all passed. A few of them:
- listed plus not listed equals exactly the 123,970 issued;
- the data file of listed plugins contains exactly 70,909 slugs, the list of unlisted ones exactly 53,061, with no duplicates and no overlap;
- the size groups and the years of addition each add back up to 70,909;
- every checksum quoted on the page matches its file.
Every published file is listed with its SHA-256 in the data table on the census page, the three scripts included: one pulls the full snapshot, one computes the figures, one writes the page files. They run without dependencies. Many figures can also be recounted straight from the published file of all 70,909 slugs, for example the 54 distinct install values. Run the scripts today and you get today's state, which gives you a comparison point of your own.
What "not listed" means, and what it does not
53,061 unlisted slugs are not 53,061 closed plugins. The difference contains closed plugins, but also slugs that never shipped a release, and rejected submissions. How it splits is not something this issue can tell, and we do not extrapolate it. The list of unlisted slugs is public anyway, one per line, with no other fields. If you are looking for a particular slug, you will find it there. You will not find a reason.
We set ourselves one language rule for this: two in five, never rounded up. 42.8 percent is not half, and a rounded half turns into "half of all WordPress plugins are abandoned" by the third retelling at the latest. That is not true, and no field in the API says it.
The second finding: silence is the norm, but it barely touches anyone
The number we consider more important is not even in the headline. 41,395 listed plugins, 58.4 percent, had gone more than 365 days without a release on the reference date. Weighted by installs it is 3.7 to 7.8 percent. Both numbers are correct. They answer different questions: by count the directory is quiet, by usage it is alive.
The split by size shows how both can be true:
| Installs | Plugins | no release for over a year | share of all installs |
|---|---|---|---|
| under 1,000 | 63,894 | 61.7% | 0.7 to 1.5% |
| 1,000 to 9,999 | 4,816 | 33.7% | 3.0 to 5.7% |
| 10,000 to 99,999 | 1,733 | 17.0% | 9.9 to 18.5% |
| 100,000 to 999,999 | 399 | 5.3% | 22.6 to 38.4% |
| 1 million and up | 67 | 1.5% | 41.5 to 60.9% |
Nine in ten listed plugins have fewer than 1,000 installs, and silence is normal there. The 67 plugins with at least a million installs carry 41.5 to 60.9 percent of all installs, and exactly one of them had gone more than a year without a release. The group ranges do not add up to 100 percent, by the way, because each group is computed in its worst case against the rest.
"Silent" means one thing here: no release for more than 365 days, measured on the last_updated field. Whether a plugin is abandoned is not something the field says. A small tool that does one job and has worked for years does not need a release every month. The field says nothing about security either. How to spot a plugin that will leave you stranded is covered in our guide to updating WordPress plugins; which layers a security plugin covers and which it leaves open, in our comparison of WordPress security plugins.
Author self-reports call for the same care. 8,131 listed plugins (11.5%) state PHP 5 as their floor, and 31,584 (44.5%) state nothing at all. Big names are among them: Classic Editor, published under the author name WordPress.org, lists PHP 5.2 as its floor according to its census profile, and its last release came 92 days before the reference date. A floor is not evidence that the code fails on PHP 8. What the field still tells you is the subject of our piece on WordPress plugins that declare PHP 5.
Where the numbers stop
A census that does not state its limits gets misquoted. These belong with every figure.
Installs are not websites
The active_installs field counts installations that report to the wordpress.org update check. They are not websites, not users and not customers. Downloads are something else again: Contact Form 7 shows 423,084,624 downloads in its profile, updates included, against 10,000,000 to 19,999,999 active installs. One number is more than twenty times the other, and neither converts into the other.
One significant digit, so a range
Across the full census, active_installs takes exactly 54 distinct values, each with one significant digit, and each is the lower bound of a bucket: 10,000 means 10,000 to 19,999. For shares that is harmless, the range stays narrow. For sums it is not. All installs together come to between 324.8 and 482.3 million, a spread of 48.5 percent. The spread is built into the source, and no sample can shrink it. Anyone who writes "X million websites use Y" carries that range around, whether they mention it or not.
The top bucket is open
For plugins with ten million installs or more, the API gives no upper bound. That affects three plugins, Contact Form 7 among them. We compute with 19,999,999, as for every other bucket, and mark the bucket as open-ended everywhere. The upper bound of every sum therefore rests on a convention.
No reasons, no trends
Why a slug is no longer listed is not in any field of this issue. And because it is the first one, there is no comparison point: issue 01 is a baseline, and any statement about a trend would be invented. tested and requires_php are self-reported by authors, and nobody verifies them. No measured field supports a statement about security, vulnerabilities or the EU Cyber Resilience Act.
A conflict of interest, stated openly
We sell WordPress plugins ourselves, and some of them are in the directory. The same queries, formulas and thresholds apply to them as to every other plugin. The census does not analyse any category we sell in separately.
What you can do with it
The practical part is the plugin check on the census page. Enter the slugs running on your site, one per line. You will find them as folder names under wp-content/plugins/, or WP-CLI gives you the list with wp plugin list --field=name. The lookup runs in your browser and nothing reaches us. For each plugin you see the install range, the last release and how it compares with plugins of similar size.
Each of the 466 plugins with 100,000 installs or more has its own profile with every value on the reference date and a comparison with its size group, for example Akismet, in the directory since 2005. If a silent plugin shows up in your list, take a second look: are support questions being answered, does it run on your PHP version, is there a maintained successor?
For journalists there is a short summary with a link to the raw data in the research section of our press page. If you think a value is wrong, write to moin@hafenstudios.com; every correction is listed with its date in the version history on the census page.
Check your own plugins
Enter your slugs, one per line, and see where each plugin stands in the directory: install range, last release, comparison with its size group. The lookup runs in your browser.
Frequently asked questions
How many plugins are in the WordPress plugin directory?
On 28 August 2026, 70,909 plugins were listed in the WordPress directory, counted in a full census through the wordpress.org plugin API. By then 123,970 slugs had been issued in total. The API itself reports different totals depending on the sort order, so a single number without a date and a method is worth little. The directory keeps growing, and a query today returns a different figure.
How many WordPress plugins are no longer updated?
41,395 of the 70,909 listed plugins, or 58.4 percent, had gone more than a year without a release on 28 August 2026. Weighted by installs that is only 3.7 to 7.8 percent, because silence sits mostly with small plugins. Whether a plugin is abandoned is not something the measured field says. A tool that does one job and works does not need a release every year.
Why are so many plugin slugs no longer listed?
The data does not show the reasons; what it does show is that 53,061 of 123,970 slugs ever issued (42.8 percent) were not listed on the reference date. They include closed plugins, but also slugs that never had a release. Not listed is therefore not the same as closed. The complete list of these slugs is public on the census page.
How many active installs do WordPress plugins have in total?
All reported active installs together come to between 324.8 and 482.3 million. The spread of 48.5 percent exists because wordpress.org reports installs with one significant digit and as a lower bound. Installs are not websites: a site running 20 plugins counts 20 times. That is why we never convert them into websites or users.
How do I find out when my plugins were last updated?
Enter your plugin slugs in the check on the census page, one per line, and you see the install range and the time since the last release for each one. You will find the slugs as folder names under wp-content/plugins or with the WP-CLI command wp plugin list --field=name. The lookup runs in your browser and nothing is sent to us. A long silence is a reason to look closer, nothing more.
Can I verify the census figures myself?
Yes, the method, the data files and the three scripts are public, each file with a SHA-256 checksum. The scripts run under Node.js with no further dependencies: one pulls the full snapshot from the API, one computes the figures, one writes the page files. Many figures can be recounted straight from the published file of all 70,909 slugs. A fresh run today gives you the current state.