Technote

Themes & plugins Practical

Plugin count is a budget, not a feature list

The plugin ecosystem is WordPress's greatest strength. But each one you enable adds an item to check every month, and that budget is finite.

Plugins are the main reason you can run a business site on WordPress at all. Booking, payments, forms, translation, memberships — being able to add these without commissioning development is a genuine strength, and nothing here disputes that.

One change of perspective makes the decisions much easier, though. A plugin list is not a feature list; it is a monthly budget. The cost starts the moment you install, and it is billed not in money but in things to check, every month.

What each one brings with it

The real cost of one plugin — the bottom three never appear on the install screen

Update checking is the steadiest cost. Install twenty and you have twenty release cycles to follow each month, several of which need a look at the site afterwards. Skipping that work does not save the budget — it defers it, and published vulnerabilities remain only on the sites that never updated.

Conflict surface grows with combinations rather than count. Two plugins make one pair; ten make forty-five. That is why “the page worked yesterday and is broken today” becomes so much harder to trace as the list grows.

How many is right? Change the question

“How many plugins are too many?” has no numeric answer. Five heavy ones can weigh more than fifteen light ones, and ten are entirely justified if the business needs ten.

The better question is this: how many can I genuinely check each month? If you run the site alone and can give this an hour a month, whatever fits in that hour is your ceiling. Anything above the ceiling does not disappear — it accumulates unchecked.

What to remove first

Tidying is not hard, and it usually turns up several candidates at once.

The test is not convenience but whether it earned its place this month

Start with deactivated plugins. It feels safe to leave them switched off, but the files are still on the server, and a file with a known vulnerability can matter regardless of activation state. If you think you might want it later, you can install it again later.

Next, overlapping functions. Two SEO plugins emit duplicate information to search engines and leave you worse off than one. Two backup tools or two security suites are just as common, and they routinely block each other in ways that make diagnosis impossible.

Finally, check for things the theme or core already does. Image optimisation, tables of contents and share links have increasingly become built-in, and some jobs belong on the server rather than in a plugin at all.

When you do add one

Three minutes before installing filters out most of the trouble: is it recently updated, does it have a healthy install base, what does its vulnerability history look like — and one more, will I actually use this feature this month? Plugins installed because they might be handy someday tend to spend budget while someday never arrives.

Choosing and maintaining plugins is collected in the Themes & plugins archive, and turning the pre-install check into a habit is covered in the before your first security incident series. To see the state of what is installed now, start with the diagnostic plugin in our free tools; to have the cleanup and the upgrades done for you, our optimization program includes that work.

More on this topic

All technotes

Themes & plugins Practical

Decide the editable regions before you design them

A design the CMS cannot express stays up for negotiation long after it ships. Deciding what editors may change, first, removes the negotiation entirely.

Designers 6 min read

₩270,000 · Join the program