hafenstudios · Plugin Directory CensusIssue 01/2026 · Reference date · Version 1.1
58.4% of listed WordPress plugins had gone more than a year without a release. They carry 3.7 to 7.8% of installs.
Horst Wenzel, plugin author with five entries in the directory, three of them on the reference date · hafenstudios, Hamburg, Germany · wordpress.org profile · moin@hafenstudios.com
Summary
On we retrieved every one of the 70,909 plugins listed in the WordPress plugin directory and held them against all 123,921 slugs ever issued.
58.4% of listed plugins (41,395) had no release for more than 365 days; weighted by installs it is 3.7 to 7.8%.
Both numbers are correct, they answer different questions: by count the directory is silent, by usage it is alive.
Install counts (active_installs, reported by the update check, not websites) come from the source with one significant digit; every number resting on them is therefore given here as a range.
Figure 1
counted by plugins · 41,395 of 70,909
58.4%
weighted by installs · 17.5 million to 26.0 million of 324.8 million to 482.3 million
3.7 to 7.8%
0255075100%
Fig. 1 Share of listed plugins with no release for more than 365 days, n = 70,909. Top by count (exact), bottom weighted by installs. The pale area is the range between the lower and upper bound: lower bound = silent lower sums against the remainder at upper sums, upper bound the other way round. The quotient of the lower sums alone would be 5.4%; it is not a range and therefore does not appear in the headline. Installs report themselves through the update check, they are not websites.
1How many WordPress plugins are no longer maintained?
On , 41,395 of the 70,909 listed plugins (58.4%) had gone more than 365 days without a release; they carry 3.7 to 7.8% of all installs.
Table 1 · Key figures of the directory
Figure
Value
Share
Range (lower to upper bound)
Precision
Source field
slugs ever issued
123,921
undefined
SVN directory listing
listed plugins
70,909
undefined
query_plugins
slugs not listed today
53,012
42.8%
undefined
difference
no release for more than 365 days
41,395
58.4%
3.7 to 7.8% of installs (17.5 million to 26.0 million)
undefined
last_updated, active_installs
no release for more than 730 days
35,602
50.2%
2.0 to 4.3% (9.7 million to 14.1 million)
undefined
same
no release for more than 1,095 days
32,920
46.4%
1.4 to 3.0% (6.6 million to 9.7 million)
undefined
same
last touched in the year they were added and no release for more than 730 days
19,013
26.8%
undefined
added, last_updated
installs in total
324.8 million to 482.3 million, top bucket open-ended
undefined
active_installs
carry the directory warning “not tested with the last three major releases” (tested up to below 6.9 or no value)
44,720
63.1%
undefined
tested
tested against WordPress 7.1 (core released a few weeks ago)
6,458
9.1%
undefined
tested
tested against WordPress 7.0
12,858
18.1%
undefined
tested
no minimum PHP version (the field is false, not empty)
31,584
44.5%
undefined
requires_php
state PHP 5.x as their floor
8,131
11.5%
58.0 million to 82.8 million installs
undefined
requires_php, active_installs
median days since the last release
749
undefined
last_updated
released within the last 90 days
18,878
26.6%
undefined
last_updated
The numbers in one sentence, ready to quote
On , 41,395 of the 70,909 plugins listed in the WordPress plugin directory (58.4%) had gone more than 365 days without a release; weighted by active installs that is 3.7 to 7.8%.
Common wrong sentence “More than half of all WordPress plugins are abandoned.” What is measured is the share of plugins without a release for more than a year; whether a plugin is abandoned is not something the field says.
53,012 of 123,921 plugin slugs ever issued (42.8%) were no longer listed on .
Common wrong sentence “53,012 plugins were closed.” Not listed is not closed: the difference also contains slugs that never had a release.
The sum of all reported active installs lies between 324.8 million and 482.3 million; the spread of 48.5% is inherent, because active_installs carries one significant digit.
Common wrong sentence “X million websites run abandoned plugins.” Installs are not websites, and the value is a range, not a point.
8,131 listed plugins (11.5%) state PHP 5.x as their floor; together they carry 58.0 million to 82.8 million installs.
Common wrong sentence “8,131 plugins require PHP 5.” The value is a self-reported lower bound, not evidence that the code fails on PHP 8.
2How precise is active_installs?
Across the full census active_installs takes exactly 54 distinct values, each with one significant digit, and each value is the lower bound of a bucket: 10,000 means 10,000 to 19,999.
Figure 2
Fig. 2 The 54 values active_installs took on , and the sum across all 70,909 plugins. The spread is inherent and no sample makes it smaller. For shares the range is narrow (Fig. 1), for sums it is wide. Where we are precise we say so; where we are not, we show it.
Lower bound
Upper bound
Spread
Plugins in the top bucket
324.8 million
482.3 million
48.5%
3
What follows from this
Every claim of the shape “X million websites use Y” drawn from this source carries that range, whether it says so or not. And this report nowhere extrapolates from installs to websites, users or customers.
3How many plugins are in the WordPress plugin directory?
On , 70,909 plugins were listed; 123,921 slugs have ever been issued, 53,012 of them (42.8%, two in five) are not listed today.
ever issued
listed
not listed
share
123,921
70,909
53,012
42.8%
Who measured before us
Three sources count the directory regularly, and this report replaces none of them. wp.md (Pavel Ciorici) has tracked the popularity of about 3,000 plugins and themes daily since 2024. WP Open Data (Javier Casares) publishes monthly open datasets, among them the number of plugins in the directory. And the wordpress.org API itself reports a total while paging, though a different one depending on the sort order (Appendix A.1). What is replicated here is the directory size as a denominator. New, and found in none of those sources: the denominator taken from the SVN directory listing, the range built from opposing bounds, the self-measurement, and the six API findings in the appendix.
4Where does the silence sit?
Silence is a function of size: 61.7% of plugins with fewer than 1,000 installs had no release for more than a year, among plugins with a million installs and up it is 1.5%.
Figure 3
Fig. 3 Five install groups following the buckets of the API, n = 70,909. On the left the share of plugins (exact), on the right the share of installs as a range, at the end of each row the share with no release for more than 365 days. 19,013 plugins (26.8%) were last touched in the year they were added and have had no release for more than 730 days. The group ranges are worst case per group against the remainder and therefore do not add up to 100 per cent. The bucket boundaries are those of the API, not ours. 67 plugins carry 41.5 to 60.9% of all installs.
Figure 4
Fig. 4 Year of the last release, n = 70,909. The dashed line is the active threshold; the year it falls in is drawn as an outline only, because yearly bars are not precise to the day. This figure carries no range; it counts plugins, not installs.
Figure 5
Plugins under 1,000 installs, density per time slice
= one plugin, length = range= your plugins
as a table
Installs
under 1 year
1 to 3 years
over 3 years
1,000 to 9,999
3,191
761
864
10,000 to 99,999
1,438
183
112
100,000 to 999,999
378
16
5
1M and up
66
1
0
Fig. 5 7,015 plugins with 1,000 installs and up, time axis logarithmic. Each dash is filled evenly, because the source does not say where inside the bucket the true value sits. The horizontal bands are real: the API knows only 54 values. The shares from Fig. 1 hold for the whole directory, this cloud shows 9.9% of it; the remaining 90.1% sit in the band below.
Figure 6
Fig. 6 Share of plugins with no release for more than 365 days by year of addition, n = 70,909. A cross-section of survivors, not a time series; a series follows from issue 02 on.
5Check your own plugins
Enter the directory slugs running on your site, one per line. You find them in the address of the directory page or as the folder name under wp-content/plugins/. With WP-CLI: wp plugin list --field=name, paste the output here. ls wp-content/plugins works too.
The lookup runs in your browser, nothing reaches us. Open the network tab, please do.
The same table for our own entries on the reference date
Slug
Installs
Last release
Tested up to
State
hafenstudios-ads
100 to 199
0.0 years ago
7.1
released within the thresholdreleased within the thresholdreleased within the threshold
wellenbrecher
0 to 9
0.0 years ago
7.1
released within the thresholdreleased within the thresholdreleased within the threshold
leadlotse
0 to 9
0.1 years ago
7.0 (7.0.4) · behind 7.1
released within the thresholdreleased within the thresholdreleased within the threshold
All three were listed in July and August 2026 and therefore score well on every maintenance figure by construction; without this sentence the row would be flattering. Two further entries have been added since the reference date, hafen-core on 31 August and linkjet on 4 September 2026; they are not part of this census and appear in issue 02.
284 pages of 250 entries each, one request every 250 milliseconds, 190 seconds in total
Denominator
Directory listing of plugins.svn.wordpress.org: 123,921 entries
Deduplication
Six records showed up on two pages during the run, because the directory sorted by recency keeps moving; they are deduplicated by slug
Reference point
2026-08-28 21:56:30 UTC; every day count is measured against this point
Range formula: every quantity derived from active_installs is given as the sum of the lower bounds and the sum of the upper bounds. Shares use opposing bounds, so that the worst case is covered in both directions:
lower = sL / (sL + (totU − sU))
upper = sU / (sU + (totL − sL))
Convention for the top bucket: for plugins with ten million installs and up the API states no upper bound. We compute with 19,999,999, exactly as with every other bucket, and mark the bucket as open-ended in every figure.
Terms as they are meant here: a slug is the folder name in the directory. Silent means no release for more than 365 days, measured against last_updated; the threshold can be switched in the figures. Installs are active_installs, reported by the update check, the lower bound of a bucket, not websites.
7Limits
Installs are not websites, not users and not customers. They count installations that report to the update check, and every number is the lower bound of a bucket.
Downloads and installs cannot be converted into one another; every automatic update counts as a download.
tested and requires_php are self-reported by the authors and are named as such every time they appear here. Nobody verifies them.
“Not listed” is not “closed”. The difference contains closed plugins, but also slugs that never had a release. Why a slug is no longer listed is not something this issue says.
The top bucket is open. For plugins with ten million installs and up the source states no upper bound.
Issue 01 is a baseline without a point of comparison. Any statement about a trend would be invented.
Why this report makes no CRA claim
No field measured here supports a statement about security, vulnerabilities or conformity with the Cyber Resilience Act. The reporting obligations under Article 14 apply from 11 September 2026, the remaining obligations from 11 December 2027, and free software developed outside a commercial activity falls outside the scope. A plugin without a release for a year is therefore neither a security finding nor a conformity statement. It is silent, and that is all the number says.
8Why no plugin names appear here
The data would yield a ranking of the most silent extensions, and that would be the most shared part of this page. We do not build it, not in the data appendix either. Such a list turns a measurement into an accusation against named individuals, often volunteers. Anyone who wants to know about a particular case can look it up in section 5 and gets exactly what the official API gives. The highest resolution this page offers are counts: 22 of 466 plugins with 100,000 installs and up had been silent for more than a year, 5 for more than three years; 1 of 67 with a million and up. No sentence singles out an individual case.
9Conflict of interest
hafenstudios sells WordPress plugins. Five of them are in the directory, three of those already on the reference date, and those three appear in section 5 in the same table as any other lookup; Leadlotse trails 7.1 on the tested-up-to field. Our plugins carry no user telemetry, and they never will. No category we sell in is analysed separately in this report.
10Issue 02
What issue 02 will measure, fixed before the data was collected
Unchanged
Thresholds of 365, 730 and 1,095 days; ranges following the formula in section 6; convention for the top bucket; no names, no ranking.
Newly measured
Which slugs vanished from the directory between the two reference dates and how many of them the API reports as closed, with a reason. Shares and reasons only, no names.
What is not coming
No ranking, no names, no statement about security or vulnerabilities.
census-slugs.tsv all 70,909 slugs with install bucket, days since the last release, tested-up-to version and minimum PHP version; header row slug, installationsbereich (install bucket), tage_seit_release (days since release), getestet_bis (tested up to), php_min
The collection and analysis scripts (seekarte-bestand.mjs, seekarte-auswerten.mjs, seekarte-seitendaten.mjs) run under Node.js without dependencies. They will appear here as text copies with a checksum once they have been reviewed and filed; until then this page says “method and raw data open” and nothing more.
Cite
Horst Wenzel, hafenstudios: Plugin Directory Census 01/2026, reference date , version 1.1, https://hafenstudios.com/census/01-2026/, SHA-256 of the aggregate file 9889e83a5dfcb8ef9752e8f80b062060085ace8805de163601b0188a51281a37
Version history
Version
Date
Change
1.0
2026-08-28
First publication
1.1
2026-09-06
Range formula following blueprint 4.12 (opposing bounds instead of a quotient), number of active_installs values corrected from 52 to 54, wording of the PHP floor, new figures 2 to 6, aggregates gruppen, kohorten, getestet, weitere, dichte, selbstmessung, reference point in the dataset
Every issue is listed on the series page, which is also where the collection window for the next issue is announced, before the data is collected.
AAppendix A: Quirks of the API
While collecting the data we stepped into every one of them. All six are reproducible with the calls below; this page calls none of them, the calls are for you to run. Tone: documented finding, not accusation.
A.1 The directory cannot state its own size consistently
Expected The same total, no matter which sort order is used.
Observed At the same moment, reproduced three times: through browse=updated the API reports 70,826 results, through browse=popular 66,709. A difference of about 4,100. Anyone paging by popularity loses part of the directory without noticing.
Expectedinfo.pages on page 1 states how many pages there are.
Observed For one search, page 1 reports 11. Request page 11 and the same response suddenly reports 27. Anyone using info.pages as a stop condition loses about 60 per cent of the hits. We stop at the first empty page instead, not at the reported number.
Expected Page 1000 returns the thousandth block or an error.
Observed Requesting page 1000, 1001, 2000 and 3001 returns the content of page 999 each time, and info.page then reports 999 as well. A crawler that trusts its own counter takes in the same records repeatedly and notices nothing. Possibly an intentional load guard, undocumented.
Expected A larger limit returns more days of download history.
Observed The download history accepts limit up to 730 and then returns 729 days. From 731 up it silently drops to 179 days. Tested with 731, 800, 850, 900, 999, 1000 and 2000, always the same.
Expectedrequires_php, tested and requires are version strings or empty.
Observed For 44.5% of listed plugins requires_php is not empty but false. The same happens with tested and requires. Anyone parsing for a version string either crashes or silently miscounts. This is the most likely reason why the compatibility numbers in circulation disagree.
Reproduction
$ curl -s 'https://api.wordpress.org/plugins/info/1.2/?action=query_plugins&request[browse]=updated&request[per_page]=250' | grep -o '"requires_php":false' | wc -l
→ a number greater than 0
A.6 The industry's most quoted figure has one significant digit
Expectedactive_installs is a count.
Observed Across the full census active_installs takes only 54 distinct values. There is no 12,500 and no 47,000. The value is also the lower bound of a bucket, not its midpoint. What that means for sums is shown in figure 2.