Most WordPress sites we take on have a long list of plugins installed. Some of them are doing important work. A surprising number are doing nothing at all, except slowing the site down, adding things to update and giving attackers more doors to try.
Every plugin is code that runs on your site, and every plugin needs updating. The fewer you have, the faster and safer your site tends to be. Here are the seven we remove most often.
1. Plugins you deactivated and forgot about
A deactivated plugin doesn't run, but its files are still on your server. If a security issue is found in it, those files can still be a risk, and because it's switched off, it often gets skipped when updates are done. If you haven't needed it in six months, you probably don't need it at all.
2. Demo importers and theme setup helpers
Premium themes often install a one-click demo importer or a setup wizard. They're useful on day one and pointless after that. Once your site is built, they can go.
3. Hello Dolly and other default extras
Hello Dolly comes with WordPress and shows a song lyric in your dashboard. It's harmless, but it's one more thing in the list. The same goes for sample plugins your host or theme added that you've never opened.
4. A second page builder
We regularly find sites with two or three page builders installed because the site was redesigned at some point and nobody removed the old one. Each builder loads its own scripts and styles. Keep the one your pages are actually built with and remove the rest, after checking no old pages still rely on them.
5. Duplicate SEO plugins
Two SEO plugins don't double your rankings. They usually output two sets of page titles, meta descriptions and sitemaps, which confuses search engines. Pick one and remove the other.
6. Caching and backup plugins on managed hosting
On managed WordPress hosting like WP Engine, page caching and nightly backups are handled at the server level. A caching plugin on top of that can conflict with the host's own caching, and a backup plugin often stores copies of your site on the same server, using up space. Check with your host first, but on a managed platform these are usually doing a job that's already done.
7. Plugins that haven't been updated in years
Look at each plugin's details in the WordPress plugin directory. If it hasn't been updated in a couple of years, or has been closed, it's no longer being looked after. Abandoned plugins are one of the most common ways sites get compromised. Find a maintained alternative, or ask whether you need the feature at all.
Before you delete anything
- Take a full backup first.
- Test the change on a staging copy of your site, not the live one.
- Check whether any pages, forms or shortcodes depend on the plugin.
- Delete one plugin at a time, and check the site after each one.
If that sounds like a weekend you'd rather spend elsewhere, this is exactly the kind of job our clients use their monthly MyMarketer hours for. We do a plugin review as part of every migration, and Premium plans include an annual plugin audit.