Plugin Closed for Security Issue on WordPress.org: What Now

By · Updated · 7 min read

“This plugin has been closed” on WordPress.org means the plugin can no longer be downloaded or updated through the directory. When the notice ends with “Reason: Security Issue”, a vulnerability was reported and not fixed to the plugin team’s satisfaction. If you run it, you are running code with a known, unpatched problem and no update coming. It does not prove your site is already hacked. It does mean you should replace the plugin now and check for signs it was exploited.

What the closure notice actually says

The wording on the plugin’s WordPress.org page looks like this:

This plugin has been closed as of April 26, 2022 and is not available for download. This closure is permanent. Reason: Security Issue.

Variations you will see:

  • “This closure is temporary, pending a full review.” The plugin team has pulled it while something is investigated or fixed. Many come back with a patched release.
  • “This closure is permanent.” Nothing is coming back through the directory.
  • No reason at all. According to WordPress.org’s own developer FAQ, the reason is made public only sixty days after closure, and then only in broad terms — Security, Guideline Violation, Author Request and so on. A recently closed plugin with no stated reason may well be a security closure.

Not every closure is about security. Authors close plugins they no longer want to maintain, and plugins get pulled for guideline or licensing problems. Those still leave you on abandoned code, but they are not an alarm bell in the same way “Security Issue” is.

Why nobody told you

When a plugin is closed, WordPress.org stops generating download zips, so the plugin can’t be installed or updated from your dashboard. The code stays readable in the SVN repository, but your site gets no new versions. What your dashboard normally doesn’t do is warn you: the plugin simply stops showing updates, which looks exactly like a plugin with nothing to update.

Security plugins fill that gap. Wordfence, for example, reports a plugin removed from WordPress.org as a critical scan issue and flags plugins that have gone roughly two years without an update. If that is how you found out, the warning is correct — it just doesn’t tell you whether anything has happened yet.

Find out what the vulnerability was

The directory won’t tell you details, but the vulnerability databases usually do. Search the plugin’s name or slug in Wordfence Intelligence, Patchstack and WPScan. You are looking for three things:

  1. Which versions are affected, and whether a patched version exists anywhere (sometimes the author ships a fix on their own site after the directory listing closes).
  2. Whether exploitation needs a login. An unauthenticated file upload or privilege escalation is urgent. A flaw that needs an administrator account is much less so.
  3. Whether it is being exploited in the wild. Once a bug is public and a closed plugin can’t be patched, it tends to end up in automated attack kits.

Check whether it was already exploited

What to look for depends on the kind of flaw, but on a closed-for-security plugin I check all of these regardless:

  • Administrator accounts you don’t recognise, including ones hidden from the Users screen — see hidden admin users in WordPress.
  • PHP files where they shouldn’t be, especially in wp-content/uploads/ and inside the plugin’s own folder. PHP files in the uploads folder explains why that is almost always bad.
  • Injected scripts and redirects in the database — the Balada Injector campaign has built a long career on exactly this kind of unpatched plugin.
  • Access-log requests to the plugin’s files from addresses that aren’t yours, particularly POST requests to its AJAX actions or REST routes.
  • File modification dates clustering around one day you didn’t touch the site.

If you want a quick outside view first, run the site through my free site checker. If any of the checks above turn something up, the plugin is no longer the whole story; go through how did my WordPress site get hacked and plan a proper cleanup.

What to do with the plugin

If the checks come back clean, work through this in order:

  1. Decide whether you still need it. A surprising number of closed plugins are doing nothing on the sites I look at — a form plugin replaced years ago, a slider on a page nobody visits. Deactivate and delete. Deactivating alone is not enough: some vulnerabilities are reachable by requesting the plugin’s files directly, whether or not WordPress has it switched on.
  2. If you need the function, replace it with an actively maintained plugin that does the same job. Check the replacement’s last update date, its support forum and its entry in the vulnerability databases before installing.
  3. If a temporary closure is resolved, update to the fixed version as soon as it reappears, and confirm the changelog mentions the security fix.
  4. Be wary of “fixed” copies from elsewhere. A download site offering the closed plugin, or a Pro version with the licence removed, is a common way to install something worse. Nulled themes and fake plugins covers what those files tend to contain.
  5. If nothing replaces it, the code needs a developer to patch or rewrite the vulnerable part and take ownership of it. That is custom work, and it belongs with someone who will keep maintaining it.

Staying ahead of the next one

Closed plugins are a symptom of a bigger problem: nobody on most small sites is watching the plugin list. The sites I clean tend to have a dozen or more plugins, several of them not updated in years, and the owner finds out a plugin was closed only when it was used to break in. The fix is routine, not heroic — a scan that reports removed and abandoned plugins, updates applied promptly, and a quarterly look at whether every plugin still earns its place. Preventing future hacks covers the hardening side, and monitoring and maintenance plans explains what a good plan should actually include.

If you would rather not be the person who checks, that is precisely what my maintenance plans do: daily malware and blacklist scans, daily plugin, theme and database updates, and cleanups included if something does get through. And if a closed plugin has already been used against you, start with a full cleanup rather than a plugin swap — removing the door doesn’t remove whoever already walked through it.

Common questions

What does 'This plugin has been closed' mean on WordPress.org?

It means the plugin can no longer be downloaded or updated from the WordPress.org directory. The closure may be temporary pending review or permanent. Sixty days after closure the notice states a broad reason, such as Security Issue, Guideline Violation or Author Request, but WordPress.org does not publish the details.

Is my site hacked if I use a plugin closed for a security issue?

Not necessarily, but it is exposed. A security closure means a known vulnerability without an update through the directory. Check for unknown administrator accounts, PHP files in uploads, injected scripts in the database and suspicious requests to the plugin in your access logs, then replace or remove the plugin whatever you find.

Is deactivating a closed plugin enough?

No. Some vulnerabilities can be reached by requesting the plugin's files directly, whether WordPress has the plugin active or not. Once you have confirmed you no longer need it, delete it completely. If you do need the functionality, install a maintained replacement and then delete the closed plugin.

Why didn't WordPress warn me the plugin was closed?

Your dashboard normally just stops offering updates for a closed plugin, which looks the same as a plugin with nothing new to install. Security plugins such as Wordfence flag plugins removed from WordPress.org and plugins that have not been updated for a long time, which is how most owners find out.

Where can I find out what the vulnerability was?

Search the plugin name or slug in the Wordfence Intelligence, Patchstack and WPScan vulnerability databases. They usually list the affected versions, whether a login is needed to exploit it, the severity score and whether a fixed version exists. That tells you how urgently you need to act and what to check for.

Can I download the closed plugin somewhere else?

Be very careful. Copies on third-party download sites, and nulled versions of paid plugins, are a common way malware gets installed. If the author ships a fixed version on their own official site, that can be legitimate; otherwise replace the plugin with a maintained alternative rather than hunting for a copy.