PROTECT MY WP

Plugin Risk Auditor

Spot abandoned, low-install, or recently-transferred plugins in your stack.

One per line. Up to 40. You can also paste full wordpress.org/plugins/… URLs and we'll pull the slug.

What this checks

Paste a list of WordPress plugin slugs. The tool queries the wordpress.org plugin API for each one and grades it against the signals that matter:

Where to get the slugs

Paste one per line. The tool checks up to 40 at once.

What it doesn't check

This is a public-signal audit. It uses only the data wordpress.org exposes: last updated, tested-up-to, install count, author. It doesn't scan the plugin's code, doesn't look at CVE databases, and doesn't know about premium plugins that live outside the wordpress.org repository.

For premium plugins, you have to do the work manually. Chapter 8 of Protect My WP covers the full plugin vetting process.

Related reading

Want the full playbook?

This tool is one small piece. Protect My WP is the whole handbook. Start with the free chapter.