Most "is this plugin safe?" advice is vibes. I wanted numbers, so I built a dataset. Here's what it found, and exactly how, so you can check my work or build your own.
The finding first
Of 8,010 WordPress plugins with a publicly documented vulnerability since 2023 (15,534 vulnerability records in total):
3,780 have been removed from the wordpress.org plugin directory. Removal stops updates but doesn't uninstall — affected sites keep running the code.
277 carried a critical (CVSS ≥ 9.0) flaw on record before removal.







