Pop quiz, class: what’s the most common way a WordPress site ends up slow, broken or hacked? Very often, it’s a plugin. Not because plugins are bad (they’re one of WordPress’s superpowers) but because not every plugin is well built or well maintained. Today you’ll learn a quick, repeatable routine to vet any plugin before it touches your site.
Professor’s note: Set a five-minute timer and work through the checks below. With practice, you’ll run through them in two or three minutes.
Minute 1: Check the Vital Signs
On the plugin’s WordPress.org page (or the Add New Plugin screen), look at the sidebar details:
- Last updated: recently updated plugins are more likely to be actively maintained. A plugin untouched for many months isn’t automatically bad, but warrants more scrutiny.
- Tested up to: this shows the most recent WordPress version the developer has tested against. If it’s several major versions behind, be cautious.
- Active installations: a large number suggests it’s widely trusted, though newer plugins naturally start small.
- Requires PHP version: make sure your hosting meets the requirement.
Warning: If WordPress.org shows a notice that a plugin has been closed or hasn’t been tested with the latest three major releases, take that seriously. Closed plugins can’t be downloaded and may have unresolved security issues.
Minute 2: Read the Reviews (the Right Way)
Star ratings are a start, but the detail matters more:
- Sort by recent: a plugin that was great years ago may have changed direction.
- Read the one- and two-star reviews: look for patterns. Is everyone reporting the same bug, conflict, or aggressive upselling?
- Look at developer replies: a developer who responds politely and helpfully to criticism is a good sign.
Minute 3: Visit the Support Forum
Click the Support tab. WordPress.org shows how many issues were resolved in the last two months. Scan the recent threads:
- Are questions answered, or left hanging for weeks?
- Are there unresolved reports of fatal errors or conflicts with popular plugins?
- Does the developer point people to paid support for basic issues? That’s allowed, but worth noting.
Minute 4: Check Security History and Scope
Search for vulnerabilities
Search the plugin name in a public vulnerability database such as WPScan, Patchstack or Wordfence Intelligence. Past vulnerabilities are common, even in excellent plugins. What matters is whether they were fixed promptly and whether the version you’ll install is patched.
Does it do only what you need?
A plugin that does one job well is often safer and lighter than a giant plugin where you use one feature out of fifty. Check whether WordPress core, your theme, or a plugin you already have can do the job.
Tip: Before installing anything, ask: “Could a few blocks or a pattern do this instead?” Surprisingly often, the answer is yes.
Minute 5: Test Before You Trust
Never install an unfamiliar plugin straight onto a busy live site. Instead:
- Take a backup — or confirm your automatic backup ran recently.
- Use a sandbox — try it in WordPress Playground (playground.wordpress.net) or on a staging copy of your site. Many plugin pages on WordPress.org include a “Live Preview” button that opens the plugin in Playground.
- Check the front end and admin — click around, check key pages, and look for errors or layout changes.
- Measure speed — compare a quick performance test before and after activation.
- Review what it adds — new admin menus, dashboard notices, scripts on every page, or database tables it creates.
Red Flags to Walk Away From
- “Nulled” or pirated copies of premium plugins, which frequently contain malware.
- Downloads from random websites instead of WordPress.org or the developer’s official site.
- Requests for excessive permissions or your admin credentials.
- No documentation, no support, and no updates.
- Reviews that all look suspiciously similar or were posted on the same day.
Premium Plugins: Extra Checks
Paid plugins sold outside WordPress.org don’t show the same public stats, so adapt the routine. Look for a public changelog with regular entries, clear documentation, a stated refund policy, and a support channel you can contact before buying. Check that the developer or company has a track record, and search for independent reviews rather than relying only on the sales page.
After You Install
Vetting doesn’t stop at installation. Keep the plugin updated, keep an eye on its changelog for major changes, and remove it if you stop using it. Our plugins hub lists vetted recommendations, and our security checklist in resources explains how updates fit into a wider security plan.
Homework
Choose one plugin currently on your site and run it through all five minutes of checks. Write down its score out of five (one point per minute passed). Anything scoring three or below deserves a closer look or a replacement. Then test yourself with our plugin quiz.