A Plugin Was Removed From WordPress.org. What Does That Mean?
Closed, removed, or just gone — how to read a missing plugin listing, and what to do.
You go to check a plugin and the page is gone, or shows a terse notice that it has been closed. WordPress.org will rarely tell you why. Here is how to interpret the silence.
The three states
- Closed — the listing exists but downloads are disabled. Something triggered a review: a guideline breach, an unresolved security report, or the author asking for closure.
- Removed — the listing is gone entirely.
- Author-retired — occasionally a developer withdraws a plugin deliberately and says so. This is the least alarming case, and the only one you can usually confirm.
What it means for your site
Practically: no more updates through WordPress, so no security fix will ever reach you automatically again. If the closure was security-related, you may be running the vulnerable version with no path forward. And because closures are frequently unexplained, you cannot rule that out.
What to do
- Check whether the plugin is active on your site. Active and closed is urgent; inactive and closed just means delete it.
- Look for a developer statement — a GitHub repository, a company blog, a support thread.
- Search for a vulnerability record referencing the plugin around the closure date.
- Plan a replacement using the migration order.
- Meanwhile, restrict what you can: if the plugin exposes a public form or endpoint you do not need, disable that feature.
A closed listing plus a public vulnerability record and no patched version is the clearest “replace this now” signal in WordPress. WPDeeply marks that combination as replace-soon at minimum, and fix-today when the component is active.
Want this checked automatically across every plugin, theme and core file on your site? WPDeeply Risk Monitor is free.