Deactivated plugins still leave files on the server. Outdated code in those files can still be a target, even when the plugin is not running.
- Go to Plugins → Installed Plugins.
- Review inactive plugins.
- Delete any plugin you do not need.
Deleting a plugin removes its files. Some plugins leave options in the database. Clean that residual data only if you know what the plugin stored, or use a trusted cleanup workflow.
If you manage many sites, a dashboard such as MainWP can help you keep plugin inventories consistent.
Related: Check if plugins are up to date.