PublisherKits PluginTidy

Description

Most WordPress sites accumulate plugins. A developer installs one for a job that ended three years ago, someone else solves the same problem a different way, and nobody dares turn anything off in case it breaks the site.

WordPress can only tell you what is active. It has no idea what is used. PluginTidy closes that gap.

It looks at each plugin and gathers evidence: whether its shortcodes and blocks appear in your content, whether it has scheduled work, whether the data it stores is still written to, whether anyone opens its settings, whether it is still maintained, and whether several plugins do the same job.

Then it tells you what it found — and shows you every reading behind it, so you can disagree.

It gives you evidence, not verdicts

Every assessment expands into the checks that produced it. Nothing is a recommendation on its own.

  • Confidence is reported separately from the score. A check that could not run lowers confidence rather than counting against a plugin.
  • It says “not enough evidence yet” when that is the truth. Evidence builds up from the day you install it, so a plugin that runs once a quarter is not called idle just because it has been quiet for a fortnight.
  • Security, backup and shop plugins are handled carefully and are never put forward for removal automatically.
  • Leave a note on any plugin — “powers the jobs board, do not remove” — and it appears everywhere that plugin is listed.

It knows when it cannot tell

If scheduled tasks are not running on your site, every plugin looks idle. PluginTidy detects that and excludes scheduled activity from the assessment rather than holding it against everything. The same applies when WordPress.org cannot be reached: it says so, and the confidence figures show it.

It keeps a record

From the moment you install it, PluginTidy records every plugin installed, activated, updated, deactivated or removed — who did it, when, and why, if you tell it. The history survives the plugin being deleted, so a problem that shows up later can be traced back to the change that caused it.

What is free

Everything above. The full audit, all the evidence, the redundancy findings, the notes, and the complete change log. Nothing is capped — an audit that stopped at ten plugins would be absurd for a tool whose whole purpose is having too many.

The free version never changes another plugin. It does not delete one, and it does not switch one on or off. It reads, it scores, and it records. When you decide to act, it links you to WordPress’s own Plugins screen.

What PluginTidy Pro adds

Pro does two things the free audit deliberately will not: it acts on what was found, and it keeps looking after you stop.

Acting on it safely

  • Quarantine — switch a plugin off for an observation window while PluginTidy watches for anything that breaks, with everything reversible.
  • A complete copy first — files, database tables and settings are saved before anything is switched off, and restored on request.
  • Deletion with the leftovers cleaned up, only offering to remove what was actually saved in that copy.
  • A pre-flight check that reads everything still running on your site for code calling into the plugin you are about to switch off, and says what it found — including whether it finished looking.

Keeping it that way

  • Scheduled re-audits. Sprawl comes back. Somebody adds three plugins for a project, the project ends, and the plugins stay. The re-audit catches the next wave while it is still small.
  • Alerts when something changes — a plugin stops being maintained, or is pulled from the directory. That happens on somebody else’s schedule, not yours.
  • The record gets more useful with age. The change log is free and starts the day you install it. In month eighteen it is the only thing connecting a change to what broke afterwards.
  • Plugin Audit Reports as PDF and CSV, to hand to a client or an auditor.

More from PublisherKits

PluginTidy is one of a small range of tools built for people who actually run publications. Each works on its own, and all are free on WordPress.org:

  • PublisherKits BioBuilder – stop leaving author profiles blank. When a post is published, BioBuilder finds the author’s professional profile and fills in their bio, social handles, job title and employer.
  • PublisherKits SocialPromoter – write, post and schedule social promotions from inside the WordPress editor, straight to X, LinkedIn, Facebook Pages and Bluesky.
  • PublisherKits ExcerptBuilder – AI-powered excerpt generation using the WordPress AI Client. Write, rewrite or tidy excerpts on demand, or auto-draft them on publish for review.

External services

This plugin contacts WordPress.org (api.wordpress.org) to find out whether each installed plugin is still maintained and whether it has been removed from the plugin directory.

What is sent: the folder name of each installed plugin. Nothing else — no site address, no email address, no content, no personal data. Answers are cached for twelve hours.

This happens when you run an audit. If WordPress.org cannot be reached, the audit still completes and says that this check was skipped.

WordPress.org privacy policy: https://wordpress.org/about/privacy/

This plugin also uses Freemius (freemius.com) to handle licensing, and to offer an optional diagnostic opt-in.

What is sent, and only if you accept the opt-in when you activate the plugin: your site address, your WordPress administrator email address, and version information about WordPress, PHP and your site. You can decline this and the plugin works exactly the same. Nothing about your content, your visitors or your audit results is ever sent.

If you buy a licence, your licence key is checked with Freemius so the paid features can be switched on. That check happens whether or not you accepted the diagnostic opt-in, because it is what the licence is.

Freemius terms of service: https://freemius.com/terms/
Freemius privacy policy: https://freemius.com/privacy/

This plugin also includes the PublisherKits Support Copilot (bwtlsupport.com, operated by Black and White Trading Ltd) – the Help button on PluginTidy’s screens. Nothing is sent until someone with plugin permissions reads the privacy notice in the chat and agrees.

What is sent when you ask a question: your question and the recent chat; your site address and, where available, your licence installation identifier, used to authorise the request and apply fair-use limits; the PluginTidy version; the admin screen you are on; and a few non-sensitive diagnostics – how many plugins are active and inactive, whether an audit has run, whether scheduled tasks work, and whether WordPress.org could be reached. The names of the plugins on your site, your audit results, your notes and your change log are never sent. Choosing “Send to support” keeps the conversation as a ticket, with the email you give and your WordPress first and last name.

Terms of service: https://publisherkits.com/terms/
Privacy policy: https://publisherkits.com/privacy-policy/

Installation

  1. Install through Plugins Add New, or upload the folder to /wp-content/plugins/.
  2. Activate it.
  3. Open PluginTidy in your admin menu and run the audit.

The audit is done in small batches, so it cannot time out on a site with a lot of plugins.

FAQ

Will it break my site?

The free version cannot: it never changes anything. It reads your plugins, your content and your database, and writes only its own records.

Why does it say “not enough evidence yet” about so much?

Because it is being honest. Some of what it measures — whether anyone opens a plugin’s settings, whether anything changes — can only be observed from the day it is installed. Leave it running and the picture fills in. Facts it can establish immediately, such as a plugin having been removed from the WordPress.org directory, are reported straight away.

Does it send my data anywhere?

The free version contacts WordPress.org to ask whether your plugins are still maintained, sending only the plugin’s folder name. Nothing else leaves your site.

It says three plugins do the same job. Which should I remove?

That is deliberately your decision. PluginTidy has no way of knowing which one your content is actually built with, so it names them all and does not guess.

Does it work if WP-Cron is broken on my site?

Yes, and it will tell you that it is. The audit never relies on WP-Cron, precisely because a broken scheduler is one of the things it detects.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“PublisherKits PluginTidy” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

0.17.0

  • Added the Support Copilot: a Help button on every PluginTidy screen that answers usage and setup questions in a popup, grounded in documentation matched to your installed version. It is read-only and can never change anything on your site, and it does not send the names of the plugins on your site, your audit results, your notes or your change log. It asks for consent before sending anything, and can pass a conversation to the support desk as a ticket. Ships in both the free and Pro builds.
  • PluginTidy still uses no AI to audit your plugins. Every reading in the audit is a measurement. The assistant is a separate support service, and it says so in the chat.

0.16.5

  • Plugin information is now read from WordPress.org as JSON rather than as serialised PHP data. What is sent is unchanged: only each plugin’s folder name.
  • Readme: the WordPress.org link in the external services section now points only at the privacy policy it actually is.

Earlier versions

Versions before 0.16.5 were distributed directly by PublisherKits and were never listed on WordPress.org.