Title: How safe are plugins?
Last modified: September 16, 2021

---

# How safe are plugins?

 *  [rusty1001](https://wordpress.org/support/users/rusty1001/)
 * (@rusty1001)
 * [4 years, 7 months ago](https://wordpress.org/support/topic/how-safe-are-plugins/)
 * Hi there,
 * I asked a plugin developer about something yesterday and said there is a bug 
   in the system on my website. I never gave them the website. Now some plugins 
   ask if you want to send anon. data about usage. That does not really worry me,
   but they did not ask, if they did actually see where its installed.
 * However I wonder how safe they can be and are they tested by WP when uploaded.
   I have a plugin that creates an excel spreadsheet from contact 7. What stops 
   the plugin sending a copy to the owners and how would be know and is there a 
   way to check. I have security installed but does that stop it? I also looked 
   at a list of vulnerable plugins and there are a few.
 * The basic question is what prevents or if possible a plugin extracts info from
   website without your knowledge, can you check that?
 * There is problem a plugin for that LOL
 * Admin, was not sure where to put, please move if required.
 * Thanks
    -  This topic was modified 4 years, 7 months ago by [rusty1001](https://wordpress.org/support/users/rusty1001/).

Viewing 2 replies - 1 through 2 (of 2 total)

 *  Moderator [James Huff](https://wordpress.org/support/users/macmanx/)
 * (@macmanx)
 * [4 years, 7 months ago](https://wordpress.org/support/topic/how-safe-are-plugins/#post-14880355)
 * > That does not really worry me, but they did not ask, if they did actually see
   > where its installed.
 * So, I took a look at your own other thread here since a year [https://wordpress.org/support/topic/wp-business-directory-recommendations/](https://wordpress.org/support/topic/wp-business-directory-recommendations/)
   and I don’t see what you’re referring to there. What did you mean by this?
 * > However I wonder how safe they can be and are they tested by WP when uploaded.
 * Yes, once a new plugin is added, it is manually checked to ensure it meets all
   guidelines before it becomes available in the directory: [https://developer.wordpress.org/plugins/wordpress-org/detailed-plugin-guidelines/](https://developer.wordpress.org/plugins/wordpress-org/detailed-plugin-guidelines/)
 * Violations result in the temporary removal of the plugin from the directory, 
   and repeat violations result in a permanent ban from the directory.
 * > What stops the plugin sending a copy to the owners and how would be know and
   > is there a way to check. I have security installed but does that stop it?
 * That would not be allowed here.
 * > I also looked at a list of vulnerable plugins and there are a few.
 * You’ll find that those are either removed or updated/fixed. The folks who run
   the plugin directory are notified of such things.
 * —
 * In short, plugins at [https://wordpress.org/plugins/](https://wordpress.org/plugins/)
   are as safe as we know based on strict guidelines and manual review. Always keep
   your plugins up to date, in case new security vulnerabilities are discovered 
   later.
 *  Thread Starter [rusty1001](https://wordpress.org/support/users/rusty1001/)
 * (@rusty1001)
 * [4 years, 7 months ago](https://wordpress.org/support/topic/how-safe-are-plugins/#post-14880421)
 * > So, I took a look at your own other thread here since a year …..and I don’t
   > see what you’re referring to there. What did you mean by this?
 * Thanks I am not referring to this plugin, can you delete that part of the post,
   I was asking about recommendations of a plugin, nothing to do with this conversation,
   thanks
 * Thanks for other I will go through, cheers
    -  This reply was modified 4 years, 7 months ago by [rusty1001](https://wordpress.org/support/users/rusty1001/).

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘How safe are plugins?’ is closed to new replies.

 * In: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
 * 2 replies
 * 2 participants
 * Last reply from: [rusty1001](https://wordpress.org/support/users/rusty1001/)
 * Last activity: [4 years, 7 months ago](https://wordpress.org/support/topic/how-safe-are-plugins/#post-14880421)
 * Status: not resolved

## Topics

### Topics with no replies

### Non-support topics

### Resolved topics

### Unresolved topics

### All topics
