hafenstudios · Plugin Directory CensusIssue 01/2026 · Reference date · Version 1.1

58.4% of listed WordPress plugins had gone more than a year without a release. They carry 3.7 to 7.8% of installs.

Summary

On we retrieved every one of the 70,909 plugins listed in the WordPress plugin directory and held them against all 123,921 slugs ever issued.

58.4% of listed plugins (41,395) had no release for more than 365 days; weighted by installs it is 3.7 to 7.8%.

Both numbers are correct, they answer different questions: by count the directory is silent, by usage it is alive.

Install counts (active_installs, reported by the update check, not websites) come from the source with one significant digit; every number resting on them is therefore given here as a range.

Figure 1
No release for
counted by plugins · 41,395 of 70,909
58.4%
weighted by installs · 17.5 million to 26.0 million of 324.8 million to 482.3 million
3.7 to 7.8%
0255075100%
Fig. 1 Share of listed plugins with no release for more than 365 days, n = 70,909. Top by count (exact), bottom weighted by installs. The pale area is the range between the lower and upper bound: lower bound = silent lower sums against the remainder at upper sums, upper bound the other way round. The quotient of the lower sums alone would be 5.4%; it is not a range and therefore does not appear in the headline. Installs report themselves through the update check, they are not websites.

1How many WordPress plugins are no longer maintained?

On , 41,395 of the 70,909 listed plugins (58.4%) had gone more than 365 days without a release; they carry 3.7 to 7.8% of all installs.

Table 1 · Key figures of the directory
FigureValueShareRange (lower to upper bound)PrecisionSource field
slugs ever issued123,921undefinedSVN directory listing
listed plugins70,909undefinedquery_plugins
slugs not listed today53,01242.8%undefineddifference
no release for more than 365 days41,39558.4%3.7 to 7.8% of installs (17.5 million to 26.0 million)undefinedlast_updated, active_installs
no release for more than 730 days35,60250.2%2.0 to 4.3% (9.7 million to 14.1 million)undefinedsame
no release for more than 1,095 days32,92046.4%1.4 to 3.0% (6.6 million to 9.7 million)undefinedsame
last touched in the year they were added and no release for more than 730 days19,01326.8%undefinedadded, last_updated
installs in total324.8 million to 482.3 million, top bucket open-endedundefinedactive_installs
carry the directory warning “not tested with the last three major releases” (tested up to below 6.9 or no value)44,72063.1%undefinedtested
tested against WordPress 7.1 (core released a few weeks ago)6,4589.1%undefinedtested
tested against WordPress 7.012,85818.1%undefinedtested
no minimum PHP version (the field is false, not empty)31,58444.5%undefinedrequires_php
state PHP 5.x as their floor8,13111.5%58.0 million to 82.8 million installsundefinedrequires_php, active_installs
median days since the last release749undefinedlast_updated
released within the last 90 days18,87826.6%undefinedlast_updated
The numbers in one sentence, ready to quote
  1. On , 41,395 of the 70,909 plugins listed in the WordPress plugin directory (58.4%) had gone more than 365 days without a release; weighted by active installs that is 3.7 to 7.8%.

    Common wrong sentence “More than half of all WordPress plugins are abandoned.” What is measured is the share of plugins without a release for more than a year; whether a plugin is abandoned is not something the field says.

  2. 53,012 of 123,921 plugin slugs ever issued (42.8%) were no longer listed on .

    Common wrong sentence “53,012 plugins were closed.” Not listed is not closed: the difference also contains slugs that never had a release.

  3. The sum of all reported active installs lies between 324.8 million and 482.3 million; the spread of 48.5% is inherent, because active_installs carries one significant digit.

    Common wrong sentence “X million websites run abandoned plugins.” Installs are not websites, and the value is a range, not a point.

  4. 8,131 listed plugins (11.5%) state PHP 5.x as their floor; together they carry 58.0 million to 82.8 million installs.

    Common wrong sentence “8,131 plugins require PHP 5.” The value is a self-reported lower bound, not evidence that the code fails on PHP 8.

2How precise is active_installs?

Across the full census active_installs takes exactly 54 distinct values, each with one significant digit, and each value is the lower bound of a bucket: 10,000 means 10,000 to 19,999.

Figure 2
0 = fewer than 10 101001k10k100k1 M10 M 10,000 means 10,000 to 19,999 from 10M up: no upper bound in the API, 3 plugins, convention 19,999,999 what usually gets quoted 48.5% spread 324.8 million 482.3 million 0500 M
Fig. 2 The 54 values active_installs took on , and the sum across all 70,909 plugins. The spread is inherent and no sample makes it smaller. For shares the range is narrow (Fig. 1), for sums it is wide. Where we are precise we say so; where we are not, we show it.
Lower boundUpper boundSpreadPlugins in the top bucket
324.8 million482.3 million48.5%3

What follows from this

Every claim of the shape “X million websites use Y” drawn from this source carries that range, whether it says so or not. And this report nowhere extrapolates from installs to websites, users or customers.

3How many plugins are in the WordPress plugin directory?

On , 70,909 plugins were listed; 123,921 slugs have ever been issued, 53,012 of them (42.8%, two in five) are not listed today.

ever issuedlistednot listedshare
123,92170,90953,01242.8%

Who measured before us

Three sources count the directory regularly, and this report replaces none of them. wp.md (Pavel Ciorici) has tracked the popularity of about 3,000 plugins and themes daily since 2024. WP Open Data (Javier Casares) publishes monthly open datasets, among them the number of plugins in the directory. And the wordpress.org API itself reports a total while paging, though a different one depending on the sort order (Appendix A.1). What is replicated here is the directory size as a denominator. New, and found in none of those sources: the denominator taken from the SVN directory listing, the range built from opposing bounds, the self-measurement, and the six API findings in the appendix.

4Where does the silence sit?

Silence is a function of size: 61.7% of plugins with fewer than 1,000 installs had no release for more than a year, among plugins with a million installs and up it is 1.5%.

Figure 3
SHARE OF PLUGINSSHARE OF INSTALLS (RANGE)SILENTunder 1,000 90.1% 0.7 to 1.5% 61.7%1,000 to 9,999 6.8% 3.0 to 5.7% 33.7%10,000 to 99,999 2.4% 9.9 to 18.5% 17.0%100,000 to 999,999 0.6% 22.6 to 38.4% 5.3%1M and up 0.1% 41.5 to 60.9% 1.5%
Fig. 3 Five install groups following the buckets of the API, n = 70,909. On the left the share of plugins (exact), on the right the share of installs as a range, at the end of each row the share with no release for more than 365 days. 19,013 plugins (26.8%) were last touched in the year they were added and have had no release for more than 730 days. The group ranges are worst case per group against the remainder and therefore do not add up to 100 per cent. The bucket boundaries are those of the API, not ours. 67 plugins carry 41.5 to 60.9% of all installs.
Figure 4
1 year ago2 years ago3 years ago20043200520062007200820092010201120122013201420152016201720182019202020212022202320243,52420257,352202626,326
Fig. 4 Year of the last release, n = 70,909. The dashed line is the active threshold; the year it falls in is drawn as an outline only, because yearly bars are not precise to the day. This figure carries no range; it counts plugins, not installs.
Figure 5
Plugins under 1,000 installs, density per time slice
= one plugin, length = range= your plugins
as a table
Installsunder 1 year1 to 3 yearsover 3 years
1,000 to 9,9993,191761864
10,000 to 99,9991,438183112
100,000 to 999,999378165
1M and up6610
Fig. 5 7,015 plugins with 1,000 installs and up, time axis logarithmic. Each dash is filled evenly, because the source does not say where inside the bucket the true value sits. The horizontal bands are real: the API knows only 54 values. The shares from Fig. 1 hold for the whole directory, this cloud shows 9.9% of it; the remaining 90.1% sit in the band below.
Figure 6
0%25%50%75%100%200420062008201020122014201620182020202220242026younger than the threshold, low by constructionyounger than the threshold, low by constructionyounger than the threshold, low by constructiononly plugins listed today, vanished slugs are missing (survivors)
Fig. 6 Share of plugins with no release for more than 365 days by year of addition, n = 70,909. A cross-section of survivors, not a time series; a series follows from issue 02 on.

5Check your own plugins

Enter the directory slugs running on your site, one per line. You find them in the address of the directory page or as the folder name under wp-content/plugins/. With WP-CLI: wp plugin list --field=name, paste the output here. ls wp-content/plugins works too.

The lookup runs in your browser, nothing reaches us. Open the network tab, please do.

The same table for our own entries on the reference date

SlugInstallsLast releaseTested up toState
hafenstudios-ads100 to 1990.0 years ago7.1released within the thresholdreleased within the thresholdreleased within the threshold
wellenbrecher0 to 90.0 years ago7.1released within the thresholdreleased within the thresholdreleased within the threshold
leadlotse0 to 90.1 years ago7.0 (7.0.4) · behind 7.1released within the thresholdreleased within the thresholdreleased within the threshold

All three were listed in July and August 2026 and therefore score well on every maintenance figure by construction; without this sentence the row would be flattering. Two further entries have been added since the reference date, hafen-core on 31 August and linkjet on 4 September 2026; they are not part of this census and appear in issue 02.

6Method

Source
api.wordpress.org/plugins/info/1.2, action=query_plugins, browse=updated
Retrieval
284 pages of 250 entries each, one request every 250 milliseconds, 190 seconds in total
Denominator
Directory listing of plugins.svn.wordpress.org: 123,921 entries
Deduplication
Six records showed up on two pages during the run, because the directory sorted by recency keeps moving; they are deduplicated by slug
Reference point
2026-08-28 21:56:30 UTC; every day count is measured against this point

Range formula: every quantity derived from active_installs is given as the sum of the lower bounds and the sum of the upper bounds. Shares use opposing bounds, so that the worst case is covered in both directions:

lower = sL / (sL + (totU − sU))
upper = sU / (sU + (totL − sL))

Convention for the top bucket: for plugins with ten million installs and up the API states no upper bound. We compute with 19,999,999, exactly as with every other bucket, and mark the bucket as open-ended in every figure.

Terms as they are meant here: a slug is the folder name in the directory. Silent means no release for more than 365 days, measured against last_updated; the threshold can be switched in the figures. Installs are active_installs, reported by the update check, the lower bound of a bucket, not websites.

7Limits

Installs are not websites, not users and not customers. They count installations that report to the update check, and every number is the lower bound of a bucket.

Downloads and installs cannot be converted into one another; every automatic update counts as a download.

tested and requires_php are self-reported by the authors and are named as such every time they appear here. Nobody verifies them.

“Not listed” is not “closed”. The difference contains closed plugins, but also slugs that never had a release. Why a slug is no longer listed is not something this issue says.

The top bucket is open. For plugins with ten million installs and up the source states no upper bound.

Issue 01 is a baseline without a point of comparison. Any statement about a trend would be invented.

Why this report makes no CRA claim

No field measured here supports a statement about security, vulnerabilities or conformity with the Cyber Resilience Act. The reporting obligations under Article 14 apply from 11 September 2026, the remaining obligations from 11 December 2027, and free software developed outside a commercial activity falls outside the scope. A plugin without a release for a year is therefore neither a security finding nor a conformity statement. It is silent, and that is all the number says.

8Why no plugin names appear here

The data would yield a ranking of the most silent extensions, and that would be the most shared part of this page. We do not build it, not in the data appendix either. Such a list turns a measurement into an accusation against named individuals, often volunteers. Anyone who wants to know about a particular case can look it up in section 5 and gets exactly what the official API gives. The highest resolution this page offers are counts: 22 of 466 plugins with 100,000 installs and up had been silent for more than a year, 5 for more than three years; 1 of 67 with a million and up. No sentence singles out an individual case.

9Conflict of interest

hafenstudios sells WordPress plugins. Five of them are in the directory, three of those already on the reference date, and those three appear in section 5 in the same table as any other lookup; Leadlotse trails 7.1 on the tested-up-to field. Our plugins carry no user telemetry, and they never will. No category we sell in is analysed separately in this report.

10Issue 02

What issue 02 will measure, fixed before the data was collected

Unchanged
Thresholds of 365, 730 and 1,095 days; ranges following the formula in section 6; convention for the top bucket; no names, no ranking.
Newly measured
Which slugs vanished from the directory between the two reference dates and how many of them the API reports as closed, with a reason. Shares and reasons only, no names.
What is not coming
No ranking, no names, no statement about security or vulnerabilities.
Collection window
The date will be announced on the series page.

11Data and citation

FileFormatSizeSHA-256Licence
census-01-2026.json
aggregates and scatter cloud
JSON86 KB9889e83a5dfcb8ef9752e8f80b062060085ace8805de163601b0188a51281a37CC BY 4.0
census-slugs.tsv
all 70,909 slugs with install bucket, days since the last release, tested-up-to version and minimum PHP version; header row slug, installationsbereich (install bucket), tage_seit_release (days since release), getestet_bis (tested up to), php_min
TSV2.4 MBf99fd637dc5d9b049e13c8abd3c3abecc69f6a584cfeaabb41a9b6672e429e77CC BY 4.0
curl -O https://hafenstudios.com/census/01-2026/census-01-2026.json
curl -O https://hafenstudios.com/census/01-2026/census-slugs.tsv

The collection and analysis scripts (seekarte-bestand.mjs, seekarte-auswerten.mjs, seekarte-seitendaten.mjs) run under Node.js without dependencies. They will appear here as text copies with a checksum once they have been reviewed and filed; until then this page says “method and raw data open” and nothing more.

Cite

Horst Wenzel, hafenstudios: Plugin Directory Census 01/2026, reference date , version 1.1, https://hafenstudios.com/census/01-2026/, SHA-256 of the aggregate file 9889e83a5dfcb8ef9752e8f80b062060085ace8805de163601b0188a51281a37

Version history

VersionDateChange
1.02026-08-28First publication
1.12026-09-06Range formula following blueprint 4.12 (opposing bounds instead of a quotient), number of active_installs values corrected from 52 to 54, wording of the PHP floor, new figures 2 to 6, aggregates gruppen, kohorten, getestet, weitere, dichte, selbstmessung, reference point in the dataset

Every issue is listed on the series page, which is also where the collection window for the next issue is announced, before the data is collected.

AAppendix A: Quirks of the API

While collecting the data we stepped into every one of them. All six are reproducible with the calls below; this page calls none of them, the calls are for you to run. Tone: documented finding, not accusation.

A.1 The directory cannot state its own size consistently

Expected The same total, no matter which sort order is used.

Observed At the same moment, reproduced three times: through browse=updated the API reports 70,826 results, through browse=popular 66,709. A difference of about 4,100. Anyone paging by popularity loses part of the directory without noticing.

Reproduction
$ curl -s 'https://api.wordpress.org/plugins/info/1.2/?action=query_plugins&request[browse]=updated&request[per_page]=250' | grep -o '"results":[0-9]*'
→ "results":70826
$ curl -s 'https://api.wordpress.org/plugins/info/1.2/?action=query_plugins&request[browse]=popular&request[per_page]=250' | grep -o '"results":[0-9]*'
→ "results":66709

A.2 The reported page count is wrong

Expected info.pages on page 1 states how many pages there are.

Observed For one search, page 1 reports 11. Request page 11 and the same response suddenly reports 27. Anyone using info.pages as a stop condition loses about 60 per cent of the hits. We stop at the first empty page instead, not at the reported number.

Reproduction
$ curl -s 'https://api.wordpress.org/plugins/info/1.2/?action=query_plugins&request[search]=gallery&request[page]=1' | grep -o '"pages":[0-9]*'
→ "pages":11
$ curl -s 'https://api.wordpress.org/plugins/info/1.2/?action=query_plugins&request[search]=gallery&request[page]=11' | grep -o '"pages":[0-9]*'
→ "pages":27

A.3 The page number is silently clamped at 999

Expected Page 1000 returns the thousandth block or an error.

Observed Requesting page 1000, 1001, 2000 and 3001 returns the content of page 999 each time, and info.page then reports 999 as well. A crawler that trusts its own counter takes in the same records repeatedly and notices nothing. Possibly an intentional load guard, undocumented.

Reproduction
$ curl -s 'https://api.wordpress.org/plugins/info/1.2/?action=query_plugins&request[browse]=updated&request[page]=1000' | grep -o '"page":[0-9]*'
→ "page":999

A.4 “Give me everything” returns the least

Expected A larger limit returns more days of download history.

Observed The download history accepts limit up to 730 and then returns 729 days. From 731 up it silently drops to 179 days. Tested with 731, 800, 850, 900, 999, 1000 and 2000, always the same.

Reproduction
$ curl -s 'https://api.wordpress.org/stats/plugin/1.0/downloads.php?slug=akismet&limit=730' | tr ',' '\n' | wc -l
→ 729
$ curl -s 'https://api.wordpress.org/stats/plugin/1.0/downloads.php?slug=akismet&limit=731' | tr ',' '\n' | wc -l
→ 179

A.5 Version fields are sometimes a boolean

Expected requires_php, tested and requires are version strings or empty.

Observed For 44.5% of listed plugins requires_php is not empty but false. The same happens with tested and requires. Anyone parsing for a version string either crashes or silently miscounts. This is the most likely reason why the compatibility numbers in circulation disagree.

Reproduction
$ curl -s 'https://api.wordpress.org/plugins/info/1.2/?action=query_plugins&request[browse]=updated&request[per_page]=250' | grep -o '"requires_php":false' | wc -l
→ a number greater than 0

A.6 The industry's most quoted figure has one significant digit

Expected active_installs is a count.

Observed Across the full census active_installs takes only 54 distinct values. There is no 12,500 and no 47,000. The value is also the lower bound of a bucket, not its midpoint. What that means for sums is shown in figure 2.

Reproduction
$ curl -sO https://hafenstudios.com/census/01-2026/census-slugs.tsv && cut -f2 census-slugs.tsv | tail -n +2 | sort -n | uniq | wc -l
→ 54