Most "is this plugin safe?" advice is vibes. I wanted numbers, so I built a dataset. Here's what it found, and exactly how, so you can check my work or build your own.

The finding first

Of 8,010 WordPress plugins with a publicly documented vulnerability since 2023 (15,534 vulnerability records in total):

3,780 have been removed from the wordpress.org plugin directory. Removal stops updates but doesn't uninstall — affected sites keep running the code.

277 carried a critical (CVSS ≥ 9.0) flaw on record before removal.