WordPress shows a plugin that was closed on WordPress.org as if it were simply up to date: no update arrives, no warning is shown. The same goes for plugins that have not been updated in years.
Atelixo Closed & Abandoned Alert fixes that, with no settings to configure:
- Plugins screen: a short warning under each plugin that was closed on WordPress.org (with the closure date and reason when available) or abandoned (no update in over 2 years), with a link to its WordPress.org page.
- Site Health: a “Closed or abandoned plugins” test. Critical if a closed plugin is installed, recommended if an abandoned one is.
- No false alerts: a plugin is only flagged when WordPress.org clearly says so. Network errors, timeouts or unexpected answers never produce an alert, and the last known status is kept.
- Your consent first: nothing is sent to WordPress.org until an administrator clicks Enable checks, and checks can be stopped at any time.
- Lightweight: checks run in the background once a day. Nothing is requested from WordPress.org while pages load, and no CSS or JavaScript is added.
Plugins that are not hosted on WordPress.org (premium plugins, plugins with a third-party Update URI), must-use plugins and drop-ins are not tracked and never show a warning.
Enable, recheck, stop
After activation, a notice on the Plugins screen explains what will be sent and offers an Enable checks button. Once enabled, the plugin’s row offers:
- Recheck now: schedules a new check in the background. Results appear within a few minutes.
- Stop checks: removes the scheduled checks and deletes the stored results. Nothing more is sent until checks are enabled again.
External services
This plugin connects to the WordPress.org Plugins API (https://api.wordpress.org/plugins/info/1.2/) to find out whether each installed plugin is still available on WordPress.org, was closed, and when it was last updated.
- Consent: no request is made and no check is scheduled until an administrator (a user who can activate plugins) clicks Enable checks in the notice shown on the Plugins screen after activation. Stop checks on the plugin’s row (or deactivating the plugin) withdraws this consent: scheduled checks are removed and stored results are deleted.
- What is sent: the slug (folder name) of each installed plugin, one request per plugin, along with the standard WordPress HTTP headers (WordPress version and site URL in the user agent). No personal data is sent.
- When: only while checks are enabled, in the background via WP-Cron: right after Enable checks, then once a day, after a plugin is installed or updated (new plugins only), and when an administrator clicks Recheck now. Never while a page loads.
- Not sent: plugins with an
Update URI header pointing outside WordPress.org, must-use plugins and drop-ins.
This service is provided by WordPress.org: Terms of Service, Privacy Policy.