Reply To: Abandoned plugin (and owner domain) – a cause for concern?

WP Tavern Forums Discussions Abandoned plugin (and owner domain) – a cause for concern? Reply To: Abandoned plugin (and owner domain) – a cause for concern?

As long as you don’t have the plugin set to automatically update and the plugin doesn’t make any requests to the abandoned domain, then you should be okay to continue using the plugin for the time being. The worst-case scenario in that situation is that a vulnerability would be found in the plugin and there wouldn’t be an update. But considering how poorly developers respond to security issues in actively supported plugins, that isn’t a big risk. Depending on how long you are considering using the plugin and the security profile of your website, you could get a security review of the plugin done to hold you over.

If you are concerned the plugin might get taken over through the abandoned domain, you can contact the team running the plugin directory at plugins@wordpress.org about that.

Newsletter

Subscribe Via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.