ShieldWave

All articles

Outdated WordPress plugins: what to update first and what to delete

Why old plugins are the most common way into WordPress, how to spot them, what to update first, what to delete, and whether to switch on auto-updates.

Radek, ENSOMEDIAPublished 5 min readPo polskuبالعربية

WordPress itself is looked after fairly well. A large community works on it, security fixes come out quickly, and minor updates have installed themselves automatically for years. The weak spot is plugins.

Every plugin is a piece of code written by someone else. Sometimes by a large company with its own security team, sometimes by one person who stopped working on it several years ago. A typical business site has a dozen or more, and a shop often has more than that. It only takes one of them to have a hole.

Why plugins are the most common way in

Companies that track WordPress vulnerabilities for a living, such as Patchstack and Wordfence, publish yearly round-ups. The picture is much the same every time: the large majority of newly found vulnerabilities are in plugins, fewer are in themes, and WordPress core is a small fraction.

The mechanism is simple. A plugin author learns about a hole and releases a fixed version. The release notes are public, and so is the code. Someone looking for easy targets compares the old and new versions, sees what was fixed, and writes a script that hunts for sites still running the version from before the fix. A site that updated the plugin is safe. One that leaves it for six months ends up on the list.

Nobody is aiming at your business personally. Bots check sites in bulk and take whichever ones let them in.

How to see what is out of date

Log in to the admin and open Dashboard > Updates. At the top you will see your WordPress version, and below it a list of plugins and themes with newer versions available. The red badge with a number next to Plugins in the left-hand menu tells you how many are waiting.

On the Plugins page, each outdated plugin has a bar under its name saying a new version is available, with a link to the details. Click it. In the changelog, authors often say plainly that they fixed a security issue.

Have a look at Tools > Site Health too. WordPress points out some problems there by itself, such as inactive plugins you should remove or an outdated PHP version on the server.

One trap: no update notice does not mean a plugin is current. Paid plugins bought outside the official directory usually only update with a valid licence. Plugins bundled with a theme often wait until the theme's author releases a new version. If the licence ran out three years ago, the admin may show nothing worrying while the plugin has not moved in three years. Ask whoever built the site whether there are any plugins like that.

What to update first

If there is a long backlog, do not just click "update all" and hope. An order that makes sense:

  1. Plugins whose changelog mentions "security" or names a type of vulnerability, such as XSS or SQL injection.
  2. Plugins your visitors interact with directly: forms, the shop, login and registration, file uploads, page builders.
  3. WordPress itself, if it is a whole major version behind.
  4. The theme and the remaining plugins.

If something cannot be updated because the new version needs a newer PHP or a newer WordPress, that tells you something as well. The whole site has fallen behind, and a proper service visit will serve you better than patching it piece by piece.

What to delete rather than update

A deactivated plugin is still sitting on your server. Its files can often be reached directly, bypassing the admin, so a hole in an inactive plugin is still a hole. If you do not use something, deactivate it and click Delete. Switching it off is not enough.

The second group is abandoned plugins. Open the plugin's page in the wordpress.org directory and check when it was last updated. If it has not been tested with the last three major WordPress releases, the directory shows a clear warning above the description that it may no longer be maintained. If the plugin has been closed, you will see a notice that it is no longer available to download. Sometimes the reason for closing is a security problem that was never fixed.

A plugin like that needs replacing with something that is still maintained. Before you swap it, write down what it did, so you can check afterwards that everything still works as before.

Take a backup before you update

Most updates go through without anyone noticing. Now and then, though, a new version clashes with the theme or another plugin, and instead of your site you get a blank white screen or a message about a critical error. WordPress then emails the administrator a description of the problem and a link to recovery mode, but it is better not to need it.

So before any larger round of updates:

  • take a full backup of the files and the database, stored off the server (the piece on forgotten backups explains why not in the website folder),
  • update one plugin at a time and, after each, check the home page, the contact form and, on a shop, the basket and checkout,
  • run bigger shop updates outside your busiest hours,
  • if your hosting company offers a test copy of the site, known as staging, try the update there first.

Automatic updates: on or off

Since version 5.5, WordPress lets you switch on automatic updates for each plugin separately. On the Plugins page every entry has an Enable auto-updates link.

The upside is obvious: a security fix installs itself without waiting for someone to find the time. After each automatic update, WordPress emails the administrator with a note of what changed.

The downside is just as clear. If an update breaks something, it may happen at night or over the weekend, when nobody is watching.

A sensible compromise for a small business looks like this:

  • small, simple plugins from reliable authors update automatically,
  • the shop, the page builder and anything your orders depend on get updated by hand, but regularly, say once a week, with a backup first,
  • unused and abandoned plugins leave the site.

The worst option is manual updates that nobody actually does. If you are not sure someone opens the admin every week, automatic updates are a smaller risk than plugins left untouched for a year.