• These are two plugins which are also installed on other websites without generating alerts about them being abandoned.

    Classic Widgets shows the same version 0.3 on both websites. In the Repository it says it was last updated 9 months ago, but on this website the alert says it was July 16, 2024.

    File Manager shows version 8.0.4 on another website and in the Repository, last updated 4 months ago. On this website it shows version 8.0 updated August 6, 2024. This one is weird because I tried deleting it and reinstalling it but it reinstalled the old version.

    AI suggested that this was a host issue but the host says no, it’s a Wordfence issue. I would just like to get rid of critical alerts for plugins which are not abandoned.

    The page I need help with: [log in to see the link]

Viewing 1 replies (of 1 total)
  • Plugin Support wfmargaret

    (@wfmargaret)

    Hi @catwingz,

    Thank you for reaching out! The abandoned plugin alert isn’t something Wordfence works out by itself. During the Vulnerability Scan stage, it asks the WordPress.org plugin API about each plugin and flags anything the repository reports as not updated in two years or more.

    File Manager 8.0 was released on 6 August 2024, which matches the date in your alert, and the repository is now at 8.0.4 as of 21 April 2026. Classic Widgets is in a similar situation, so it almost sounds like your site is seeing repository data that’s about two years old.

    What does your Plugins page say? If 8.0 is genuinely what’s installed (and not just what the scan reported), check whether your site shows any available updates. Older versions of the plugin have vulnerabilities, so I recommend you remove it until you can update it and check on this with your host, as Wordfence doesn’t determine which plugin version to install.

    Thanks,
    Margaret

Viewing 1 replies (of 1 total)

You must be logged in to reply to this topic.