How to manage WordPress plugins safely, on one site or many
WordPress plugin management is the routine of choosing, installing, updating, auditing and removing the plugins a site runs, so nothing outdated, abandoned or unused is left behind. On one site you do it from the Plugins screen in wp-admin; across several sites, a tool that can bulk update WordPress plugins saves you logging in to each one.

The short answer
WordPress plugin management means running only the plugins a site needs, from sources you trust, kept up to date and removed cleanly once you stop using them. It matters because plugins carry most of the risk: Patchstack found that 91% of the new WordPress vulnerabilities reported in 2025 were in plugins.
- Choose: check Last updated, Tested up to, active installs and support replies before you install.
- Install: use Plugins > Add Plugin or upload a zip file. Only administrators can.
- Update: back up first, apply security fixes promptly, then check the pages that matter.
- Audit monthly: delete unused plugins and replace closed, abandoned or vulnerable ones.
- Remove: deactivate, then delete, so the plugin's uninstall routine can run.
- Many sites: work from one dashboard instead of every wp-admin, for example with WPCentrify, a hosted WordPress management platform for anyone responsible for more than one WordPress site (our product).
What does WordPress plugin management involve?
Plugin management covers everything that happens to a plugin on your site, from the day you consider it to the day you remove it. That is seven jobs: choose, install, configure, update, audit, deactivate and delete.
It deserves a routine because the choice is huge and the quality varies. The WordPress.org plugin directory offers over 75,000 free plugins, which the WordPress documentation describes as "of varying quality". Plugins are also where most vulnerabilities are found: Patchstack counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025, 91% of them in plugins, 9% in themes and only 6 in WordPress core.
On one site, all of it happens under Plugins in wp-admin. Installed Plugins sorts them into views such as Active, Inactive, Recently Active (switched off in the past week), Update Available and Auto-updates Enabled, plus Must-Use and Drop-ins when a site has them.
How do you choose a WordPress plugin?
Pick plugins that are actively maintained, tested with current WordPress, widely used, answered by their authors and needed for a job nothing else on the site already does. For plugins in the WordPress.org directory, the plugin's page shows most of this.
| What to check | Warning sign |
|---|---|
| Last updated | A long gap with no release while WordPress has moved on |
| Tested up to | Older than all three of the latest major WordPress versions (7.1, 7.0 and 6.9 in October 2026). WordPress.org then shows a notice that the plugin "hasn't been tested with the latest 3 major releases of WordPress" |
| Active installations | Very few sites use it, so fewer people spot problems early |
| Issues resolved in last two months | Many unresolved support threads, or questions nobody answers |
| WordPress and PHP version | A minimum your site or host does not meet |
| Closed notice | A red notice that the plugin "has been closed and is no longer available for download". The reason appears after 60 days and can be a security issue |
Field names as shown on WordPress.org plugin pages and in the WordPress Plugin Handbook, checked 10 October 2026.
- One plugin per job. Check that your theme, WordPress or a plugin you already run does not do the same thing. Two plugins doing one job invite conflicts.
- Get premium plugins only from the vendor, never from an unofficial download site, and check how updates arrive, usually with a license key.
How do you install a WordPress plugin?
Install plugins from Plugins > Add Plugin in wp-admin (Add New in older versions), by searching the WordPress.org directory or uploading a zip file, and only as an administrator.
- From the directory: search, open More Details to check compatibility, then click Install Now and Activate.
- From a zip file: for a premium plugin, click Upload Plugin, choose the zip, click Install Now, then Activate Plugin.
- By SFTP: when the server blocks installs from wp-admin, copy the unzipped folder into
wp-content/pluginsand activate it on the Plugins screen.
Who can install plugins: on a single site, only the Administrator role can install, update and delete them. On a multisite network only Super Admins can install them, and site administrators can activate plugins only when the network allows it. Our guide to WordPress user roles and permissions explains who should have that power.
If an administrator cannot see Add Plugin, check wp-config.php: DISALLOW_FILE_MODS set to true blocks installs and updates from wp-admin. Many sites also set DISALLOW_FILE_EDIT to remove the plugin and theme file editor.
After activating a plugin, configure it, check the pages it touches and note who added it and why.
What are plugin dependencies in WordPress?
Since WordPress 6.5, a plugin can name the plugins it needs in a Requires Plugins header, and WordPress enforces it:
- A plugin cannot be installed until the plugins it requires are installed, or activated until they are active.
- A required plugin cannot be deactivated while its dependents are active, or deleted while they are installed.
- The Plugins screen shows Requires: and Required by: lines under each plugin involved.
- Only slugs are listed, so WordPress does not check the required plugin's version, and a dependency from outside WordPress.org has to be installed by hand.
So before you remove a plugin, look for a Required by line, and when an add-on refuses to activate, install and activate what it requires first.
How do you update WordPress plugins?
Update plugins from the Plugins screen or Dashboard > Updates, one at a time, in bulk or automatically, and check the site after each round of updates.
| Method | How | Best for |
|---|---|---|
| One at a time | Click update now under the plugin on the Plugins screen | Page builders, store plugins and anything custom code depends on |
| Several at once | Open Update Available, tick the plugins, choose Update from Bulk actions and click Apply | Routine releases on one site |
| Automatically | Click Enable auto-updates (WordPress 5.5 and later). WordPress runs them twice a day | Well-maintained plugins on sites nobody checks daily |
| From a zip file | Upload the newer zip with Upload Plugin and replace the installed version (WordPress 5.5 and later) | Premium plugins without a working updater |
| Command line | wp plugin update --all with WP-CLI, or --dry-run to preview | Developers and scripted maintenance |
From the WordPress.org documentation and the WP-CLI handbook, checked 10 October 2026.
- Back up first. WordPress's own documentation says to "always make sure you have a current backup of your site before updating your plugins".
- Do not sit on security fixes. Patchstack's 2026 report found that about half of high-impact vulnerabilities were exploited within 24 hours of disclosure.
Automatic updates have their own settings and filters, covered in our guide to WordPress automatic updates. WordPress itself follows different rules, explained in WordPress core updates.
What does WordPress do when a plugin update fails?
WordPress puts the previous version back when a plugin update fails to install, and since version 6.6 it rolls back a plugin auto-update that crashes the home page. It does not catch every way an update can break a site.
- Failed installs are undone (WordPress 6.3). WordPress first moves the old version into
wp-content/upgrade-temp-backup/, and restores it if the update fails partway. This covers plugins and themes. - Crashing auto-updates are rolled back (WordPress 6.6). After a plugin updates automatically, WordPress loads the home page with a loopback request. If it finds a PHP fatal error, it restores the previous version and emails the site admin.
Those safety nets do not take a full backup first, check any page other than the home page, notice a layout or checkout that breaks without a fatal error, or roll back a theme auto-update.
If an update has already broken a site, follow our steps for when a plugin update breaks your site. To close the gaps, every update needs a way back and a check afterwards. That is what safe WordPress updates add in WPCentrify (our product): a risk score before each plugin or theme update, and automatic rollback after a PHP fatal error, a 5xx server error or a visual break found by visual regression testing, which compares the page before and after.
What are must-use plugins?
Must-use plugins are PHP files in wp-content/mu-plugins that WordPress loads automatically on every site in the installation. They cannot be switched off from wp-admin; the only way is to remove the file.
- They load before normal plugins, in alphabetical order.
- They show no update notices, so whoever added a file has to keep it updated.
- Only PHP files directly in the folder load, so a plugin in a subfolder needs a small loader file.
- They are listed in a separate Must-Use view on the Plugins screen.
Hosts, developers and management tools use them for code that must always run, which is why they belong in every audit: know what each file is and who added it.
Should you deactivate or delete a plugin?
Deactivate a plugin to switch it off for a while; delete it when you no longer need it. Only deleting removes the plugin's files and runs its uninstall routine.
| Deactivate | Delete | |
|---|---|---|
| Files | Stay in wp-content/plugins | Removed from the server |
| Settings and data | Kept, so the plugin picks up where it left off | Removed if the plugin has an uninstall routine that clears its options and tables |
| Security | The code stays on the server, and Site Health asks you to remove inactive plugins | The code is gone |
| Use it when | Troubleshooting, or you need the plugin again soon | You no longer use it, or you have replaced it |
Based on the WordPress Plugin Handbook and the Site Health check, checked 10 October 2026.
In wp-admin, click Deactivate, then Delete. WordPress then runs the plugin's uninstall routine, an uninstall.php file or an uninstall hook, where a plugin should clear out its options and database tables.
Not every plugin cleans up. Some keep their data on purpose so a reinstall keeps your settings, and some have no uninstall routine, so tables and options stay behind as clutter in the database and every backup. On the command line, wp plugin delete skips the uninstall routine, while wp plugin uninstall runs it.
Delete inactive plugins rather than keeping them just in case. Tools > Site Health puts it plainly: "Inactive plugins are tempting targets for attackers. If you are not going to use a plugin, you should consider removing it."
How do you audit your WordPress plugins?
Once a month, go through every installed plugin and ask whether it is used, maintained, still available, free of known vulnerabilities and not duplicating another plugin.
| Question | What to do |
|---|---|
| Is it used? | Check the Inactive view and ask whoever installed it. Delete what nobody needs |
| Is it maintained? | Plan a replacement once it falls three major WordPress versions behind |
| Is it still available? | A closed plugin gets no updates. Replace it, at once if it was closed for a security issue |
| Is it vulnerable? | Update to the version that fixes it. If there is no fix, deactivate and replace it |
| Does it overlap? | Keep one plugin per job |
| Do you know where it came from? | Look into any plugin, must-use file or drop-in nobody remembers adding |
Our recommended checklist, not an official WordPress rule.
The vulnerability question matters more than it looks. Patchstack's 2026 report found that 46% of vulnerabilities "did not receive a fix from the developer in time for public disclosure", so updating alone does not always protect you. Sometimes the only fix is a different plugin.
If nobody can explain a plugin in the main list or the Must-Use view, scan your WordPress site for malware. Across many sites, WPCentrify's WordPress vulnerability monitoring and its WordPress activity log answer the vulnerability and origin questions without opening each site.
How many WordPress plugins is too many?
There is no fixed number: one abandoned or badly built plugin can do more harm than twenty well-maintained ones, so judge each plugin rather than the count.
The count still matters a little. WordPress's own performance guide says "the number of plugins and their performance will also have a huge impact on your site's performance" and recommends deleting unnecessary ones. Every plugin is also one more thing to update. Keep a plugin only if you can say what it does, it is maintained and nothing else on the site already does its job.
A simple monthly plugin management routine
Once a month, run the same seven steps on every site, and apply security releases as soon as they appear rather than waiting for the monthly slot.
- Back up first. Make sure you have a recent backup you have restored before, taken as close to the updates as you can.
- Review what is waiting. Open Update Available, note which releases fix security problems and read the changelog of any major version.
- Update in a quiet window. Apply security fixes first, then the rest, and update page builders and store plugins one at a time.
- Check the pages that matter. Open the home page, forms, checkout and login, and look for broken layouts as well as errors.
- Clear out what you do not need. Delete inactive plugins nobody needs, and look through the Must-Use and Drop-ins views.
- Check maintenance and security notices. Look for plugins that are closed, untested with recent WordPress versions or flagged as vulnerable, and plan replacements.
- Write down what changed. Note what you updated, removed or replaced, so the next problem is quick to trace.
Step one is the one never to skip. A dependable WordPress backup keeps copies away from the site, so a problem on the server cannot take them with it.
Do you need a WordPress plugin manager?
For one site, WordPress's own Plugins screen is the plugin manager most people need. Add a separate tool only for a job it does not do, such as switching to an older version, measuring plugin performance or managing plugins on many sites.
| Tool | What it adds | Cost, as stated |
|---|---|---|
| WordPress Plugins screen | Install, activate, update, auto-update, deactivate and delete on one site | Built into WordPress |
| WP Rollback | Switches a WordPress.org plugin or theme to another version. 300,000+ active installs, tested up to 7.1.3 | Free. The free version works only with WordPress.org plugins and themes |
| uiXpress Plugin Manager | Per-plugin performance figures, a known-good version kept on every update path, and bulk actions | Included in every uiXpress plan. $97 one-time Solo price |
| WPCore Plugin Manager | Installs a saved collection of plugins in one go | Free. Tested up to 6.8.11, with the "not tested with the latest 3 major releases" notice on its page |
| MainWP | Installs, activates, deactivates, deletes and auto-updates plugins across sites, and flags possibly abandoned plugins daily. You host it | Free and open source, with a paid Pro version |
| WPCentrify | Hosted. Updates every site you choose, with risk scores, automatic rollback, zip installs, safe removal and an activity log | Free during early access |
From each tool's own pages, checked 10 October 2026. Disclosure: WPCentrify is our product. No affiliate links.
Check a plugin manager the way you check any other plugin: as the table shows, not every one is kept current.
How do you manage plugins across many WordPress sites?
Manage them from one dashboard, so each update, install and removal is done once, checked and recorded, instead of repeated in every wp-admin.
Every step above multiplies with each site. The WPCentrify account we use for our own work manages 18 WordPress sites, and on 10 October 2026 it showed 11 updates waiting for review. Checking them site by site would mean 18 separate logins.
WPCentrify is built for this job (disclosure: WPCentrify is our product). Plugin management sits inside a WordPress website management platform that also runs backups, uptime checks and security monitoring for every site you connect. For plugins, it gives you:
- Updates across every site in one action. Plugin, theme and WordPress core updates are grouped by release in bulk updates, so one choice reaches every site you select, paid plugins included.
- Exclusions and update windows. Keep a plugin out of bulk updates on one site, and give each site its own update window.
- Risk scores and automatic rollback. Plugin and theme updates are risk-scored and rolled back automatically after a PHP fatal error, a 5xx server error or a visual break.
- Installs from a zip. Upload a plugin or theme zip and install it on a website from the dashboard.
- Safe removal. Switch plugins off or remove plugins and themes. An active plugin is deactivated first, and WPCentrify refuses to delete its own connector, the active theme or the parent of the active child theme.
- Vulnerability findings. What each site runs is matched against vulnerability data refreshed every day, with the version that fixes each problem.
- Every action on the record. Updates, installs and removals land in the activity log, along with changes made in wp-admin. Alerts arrive by email.
To be clear about the limits: WPCentrify checks an update on the live site right after it runs, not on a copy of the site, and rolls it back if a check fails. If you would rather host the dashboard yourself, MainWP is free and open source. Either way, the aim is to manage multiple WordPress sites from one place instead of logging in to each one.
Sources
- Manage Plugins, Plugin and themes auto-updates, Roles and Capabilities and the WordPress 5.5 release notes, WordPress.org documentation
- Must Use Plugins, Optimization and Editing wp-config.php, WordPress Advanced Administration Handbook
- Uninstall Methods and Alerts and Warnings, WordPress Plugin Handbook
- WP_Site_Health::get_test_plugin_version() and the wp plugin commands, WordPress developer resources
- Introducing Plugin Dependencies in WordPress 6.5, Rollback for failed manual plugin and theme updates (6.3), Merge Proposal, Rollback Auto-Update and the WordPress 6.6 Field Guide, Make WordPress Core
- The WordPress.org plugin directory, WordPress releases and the plugin pages for WP Rollback and WPCore Plugin Manager
- State of WordPress Security in 2026, Patchstack
- uiXpress Plugin Manager and MainWP Easy Plugin Manager, vendor pages
All sources checked on 10 October 2026.
Questions about WordPress plugin management
WordPress plugin management is the routine of choosing, installing, updating, auditing and removing the plugins a site runs. The goal is a short list of maintained plugins, each with a clear job, kept up to date and removed cleanly when no longer needed.
Go to Plugins in wp-admin. Installed Plugins lets you activate, deactivate, update, turn on auto-updates for and delete each plugin, and Add Plugin lets you search the WordPress.org directory or upload a zip file.
On a single site, only the Administrator role can install, update and delete plugins. On a multisite network only Super Admins can install them, and site administrators can activate plugins only if the network allows it. If nobody can install plugins, check for DISALLOW_FILE_MODS in wp-config.php.
Deactivating switches the plugin off but keeps its files and settings, so you can turn it back on. Deleting removes its files and runs its uninstall routine if it has one, which usually removes its settings and database tables.
Usually yes. WordPress's Site Health check recommends removing inactive plugins, because their code stays on the server where attackers can target it. Check first that no other plugin requires it and that you will not need its settings, because deleting can remove them.
There is no fixed number. One abandoned or badly built plugin can cause more trouble than twenty well-maintained ones, so keep only plugins you can explain, that are maintained and that do not duplicate each other.
Check for updates at least once a week and do a full review once a month. Apply security fixes as soon as you can: Patchstack's 2026 report found that about half of high-impact vulnerabilities were exploited within 24 hours of disclosure.
Check its WordPress.org page. A plugin not tested with the last three major WordPress releases shows a notice saying so, and a long gap since the last update or unanswered support threads are further warning signs. A closed plugin gets no updates, so replace it.
If an update fails to install, WordPress puts the previous version back, a safety net added in WordPress 6.3. Since 6.6, a plugin auto-update that causes a PHP fatal error on the home page is rolled back and the site admin is emailed. Updates that break another page or the layout are not caught.
For one site, WordPress's built-in Plugins screen covers installing, updating, auto-updates and removal, so add a tool only for a specific job, such as WP Rollback for switching versions. For many sites, use a management platform such as MainWP, which you host yourself, or WPCentrify, a hosted platform that is our product.
Use a management platform instead of logging in to each site. In WPCentrify you update plugins, themes and WordPress core across every site you choose in one action, with a risk score and automatic rollback after a PHP fatal error, a 5xx server error or a visual break, and every action is recorded in the activity log.
Related reading
Bulk updates
Update plugins, themes and WordPress core on every site you choose, in one action.
See the featureWordPress automatic updates
Turn auto-updates on or off for core, plugins and themes, and set them up safely.
Read the guideA plugin update broke my site
Get access back, find the culprit and roll it back, step by step.
Read the guideMore on this topic: WordPress core updates and how to scan a WordPress site for malware.
Manage every site's plugins from one dashboard
Update plugins across every site you choose, with a risk score and automatic rollback, and remove what you no longer need, without logging in to each wp-admin.
Free during early access. No credit card required.