There is no correct number of WordPress plugins. A site running eight can be slow and insecure; a site running twenty-six can be fast and clean. What matters is what each plugin does, how well it is built, and whether anyone is still maintaining it. Surveys of real installs put the typical site somewhere around twelve to fifteen active plugins, which tells you what is common but nothing at all about what is healthy.
Still, the question comes up on almost every site I inherit, usually phrased the same way: someone read that plugins slow your site down, counted theirs, and got nervous. That instinct is half right. The count is not the problem. What the count is usually a symptom of is the problem.
Why the plugin count is the wrong question
Plugins are not uniform units of weight. A plugin that adds one admin setting and touches nothing on the front end costs you effectively nothing. A page builder loads its own stylesheet, its own JavaScript bundle, and its own render pipeline on every single page view. Both count as “one plugin.”
So the honest version of the question is: what is each of these doing, and is it worth what it costs? Answer that for every plugin on the site and the number takes care of itself. Sites that end up with thirty-five plugins rarely got there by deliberate choice. They got there by five years of solving one problem at a time with whatever came up first in a search.
The three real costs
Performance. Every active plugin runs on every request, and the cost is rarely where people look for it. Front-end weight is the visible part — extra stylesheets and scripts loading on pages that do not use the feature. The less visible part lives in the database. WordPress loads a set of “autoloaded” options on every page load, and plugins add to it. Since version 6.6, WordPress has flagged an autoload total over 800 KB in Site Health as a performance problem, and the fastest way to blow past 800 KB is to install and delete a dozen plugins over several years, because many of them leave their settings rows behind when they go.
Security surface. This is the cost most owners underrate. Patchstack counted 7,966 new vulnerabilities across the WordPress ecosystem in 2024. Ninety-six percent of them were in plugins. WordPress core itself accounted for seven. Every plugin you add is another codebase you are trusting, written by someone you have never met, running with full access to your database.
Maintenance. Plugins get abandoned. In 2024 alone, 1,614 plugins and themes were pulled from the WordPress.org directory over security issues their developers never fixed. A plugin sitting quietly on your site with no update in three years is not stable. It is unmaintained, which is a different thing that looks identical from the dashboard.
How to audit your plugins in an afternoon
You do not need a developer for the first pass. You need a spreadsheet and two hours. Work through your plugin list one row at a time and answer four questions for each.
- What does this do, in one sentence? If you cannot answer, that is your answer. Something on the site probably depends on it, so do not delete it yet — but flag it.
- When was it last updated? The plugin’s directory page shows this. Under six months is healthy. Over a year deserves a look. Over two years, start planning a replacement.
- Is it still doing a job the site needs? Contest plugins from a 2021 giveaway. A social sharing bar nobody clicks. A slider on a page that was rewritten. This is where most of the cuts are.
- Does something else already do this? Two caching plugins fighting each other. An SEO plugin plus a separate schema plugin plus a separate sitemap plugin. Overlap is common and often causes the exact bugs people blame on “WordPress being slow.”
Then deactivate the candidates one at a time — not all at once — and click through the site after each. One at a time is slower and it is the only way you will know which change broke the thing you notice two clicks later. Take a full backup first, and if the site matters to your revenue, do this on a staging copy rather than live.
Deactivating is not deleting. A deactivated plugin still sits on the server with its code intact, which means an unpatched vulnerability in it can still be reachable. Once you are confident nothing broke, delete it properly from the plugins screen so its uninstall routine runs. Some plugins clean up after themselves. Many leave database tables and options rows behind, which is why an old site’s database is usually carrying junk from plugins it stopped using years ago.
Which plugins are worth keeping
Some jobs genuinely should be a plugin. Do not write your own form handler, your own backup system, or your own payment processing. Those are solved problems where a maintained plugin with a real company behind it is the safer choice by a wide margin.
The keep-list on a well-run small-business site tends to look like: something for forms, something for backups, something for security hardening, something for SEO, a caching layer if your host does not handle it, and whatever runs a genuinely specialized function — bookings, e-commerce, an events calendar, a membership area. That is a real stack and it is not short. It is also all load-bearing.
One caution on picking replacements: install count is not a security rating. Of 2024’s vulnerabilities, 1,018 affected plugins with more than 100,000 active installations. Popular plugins are attractive targets precisely because they are popular. Judge a plugin by its update cadence, its support forum, and whether a business depends on its revenue — not by the download number.
When a plugin should be custom code instead
The plugins worth replacing with a few lines of purpose-built code are the ones doing something structural to your content. Galleries and portfolios are the usual example. A gallery plugin gives you a way to arrange images inside a page, which means your work lives as decoration inside prose rather than as content the site understands.
On the site I built for Santa Fe artist Jay Pearson, in collaboration with Monsoon Design on the identity, the archive of works is a custom post type rather than a stack of gallery plugins. Each piece is its own entry with its own fields and its own page. Adding a work takes one screen, the grid and the single-work view build themselves, and there is no third-party plugin standing between the artist and his own archive. That architecture is a day of setup and it removes a permanent dependency.
How many WordPress plugins is too many?
You have too many plugins when you can no longer say what each one does and why it is there. In practice, most small-business sites run well on somewhere between five and fifteen actively maintained plugins, each doing one clear job. Twenty-five is not automatically a problem if all twenty-five are current, necessary, and well built. Six is a problem if two of them have not been updated since 2022. Judge the list, not the length of it.
Where to start this week
Open your plugins screen and sort by last updated. Anything untouched for more than two years goes on a list to replace. That single pass removes more risk than any amount of counting, and it takes about ten minutes.
If you look at that list and cannot tell what half of it is doing, that is a normal place to be — it is what happens when a site is maintained by the person who also runs the business. Patrick Iverson is a Santa Fe brand strategist and custom WordPress developer who has run an independent practice here since 2001 and has built on WordPress since 2003. If you want a second set of eyes on your plugin list before you start deleting things, that is a short conversation worth having.



