Make the replacement decision from evidence
Plugin age alone does not determine risk. A removed listing, known unpatched vulnerability, broken compatibility, business dependency and missing rollback path each change the urgency. Select the condition that best matches the plugin you are reviewing.
How to act on the result
Low immediate risk
Document ownership, monitor updates and keep a normal replacement path.
Review required
Confirm listing, changelog, compatibility and security records before the next platform update.
Migration priority
Build the replacement in staging, preserve data and URLs, and schedule removal.
Urgent containment
When an unpatched or exploited issue exists, reduce exposure while preserving a tested rollback and investigating compromise.
Frequently asked questions
Does this checker scan my WordPress site?
No. It is a private browser-based triage checklist. It does not connect to your website or query a live vulnerability database.
Does a high score mean I should delete the plugin immediately?
Not necessarily. Preserve data, identify dependencies, prepare a replacement and test rollback. Known active exploitation can require faster containment.