Security tests

Deactivated plugins

Why Security Ninja warns about deactivated plugins, and how to remove unused ones safely.

Deactivated plugins still leave files on the server. Outdated code in those files can still be a target, even when the plugin is not running.

  1. Go to Plugins → Installed Plugins.
  2. Review inactive plugins.
  3. Delete any plugin you do not need.

Deleting a plugin removes its files. Some plugins leave options in the database. Clean that residual data only if you know what the plugin stored, or use a trusted cleanup workflow.

If you manage many sites, a dashboard such as MainWP can help you keep plugin inventories consistent.

Related: Check if plugins are up to date.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image