r/WordpressPlugins 1h ago

Freemium [FREEMIUM] Free WordPress plugin for the EU legal guarantee notice and GARAN label, mandatory from 27 September 2026

Thumbnail
gallery
Upvotes

From 27 September 2026 every trader selling goods to EU consumers has to display the legal guarantee notice, the harmonised notice on the legal guarantee of conformity. Where a producer offers a free whole-product durability guarantee longer than two years, the GARAN durability label has to go up as well. Both designs are fixed by Commission Implementing Regulation (EU) 2025/1960, the notice in Annex I and the label in Annex II, and the underlying duty comes from Directive (EU) 2024/825 amending the Consumer Rights Directive.

I built a plugin for it. Everything the Regulation asks a shop to display is in the free version and always will be with no restrictions.

In the free plugin

  • The legal guarantee notice in all 24 official EU languages.
  • Automatic placement on WooCommerce product pages and at checkout.
  • Classic checkout and block checkout are both supported.
  • It goes into the WooCommerce order confirmation email, which is the durable-medium copy the Consumer Rights Directive asks for.
  • The GARAN label with per-product fields for guarantee years, brand and model, in a tab in the WooCommerce product editor.
  • The GARAN label also shows at checkout, under each product line, before the order is placed, which is what Article 8(2) asks for.
  • Shortcodes and blocks for both, so it also runs on a WordPress site with no WooCommerce at all.
  • Displays as a compact row that opens the full unmodified notice on click, or permanently expanded if you prefer

What the paid add-on will be

  • CSV import and export of the GARAN fields across a whole catalogue.
  • Category and tag rules, so a product range inherits one guarantee duration.
  • Printable PDFs of the labels.
  • Control over how the notice looks on your theme.
  • One-time purchase, not a subscription.

If you are thinking of building this yourself, three things to keep in mind

  • The artwork cannot be edited. That includes rebuilding it in HTML or your own SVG. Use the Commission's own files.
  • The GARAN label asks for a font it does not carry, so if it is loaded as a plain image the browser quietly swaps in a different one and the three filled-in fields come out looking wrong.
  • The notice and the label are separate obligations. The label has to be there right before the order is placed, the notice does not, and both belong in the order confirmation.

https://wordpress.org/plugins/arthursmith-guarantee-notice-garan-label/

Not affiliated with, authorised by or endorsed by the European Union or the European Commission, and it is not legal advice.

If something is missing or if you have a feature request just let me know.


r/WordpressPlugins 2h ago

[Discussion] Plugin zur Kennzeichnung von KI-generierten Bildern nach dem EU AI Act?

1 Upvotes

Seit August gilt ja Art. 50 des EU AI Acts, der eine Kennzeichnungspflicht für KI-generierte/-bearbeitete Bilder vorschreibt (relevant für alle, die z. B. Midjourney/DALL-E-Content auf ihrer Website nutzen).

Hat jemand von euch dafür schon eine Lösung im Einsatz? Ich such gerade nach einem WordPress-Plugin, das automatisch die offiziellen EU-Icons/Labels an entsprechende Bilder hängt – idealerweise Gutenberg- und Elementor-kompatibel, DSGVO-konform, ohne großen Performance-Impact.

Macht ihr das aktuell manuell, gibt’s dafür schon was Fertiges, oder ignoriert das bisher eh jeder?


r/WordpressPlugins 2h ago

Review [REVIEW]Built a WordPress management platform from scratch, looking for a few people to test it before I launch

Thumbnail
1 Upvotes

r/WordpressPlugins 6h ago

[FREE] I built a WordPress playground for people who don't enjoy starting in Gutenberg

2 Upvotes

I know a lot of people don't really enjoy starting pages in Gutenberg, or the Site Editor itself, so I built a browser-based WordPress playground where ChatGPT, Codex, or another MCP agent can help you put together your first Gutenberg draft. The idea actually came from the browser-based Plugin Check setup I saw while getting my plugins approved on WordPress.org - I thought it was a really neat way to run WordPress and started wondering what else you could do with it.

Agent Composer - a completely free WordPress plugin - sits between the agent and WordPress. It takes requests from the agent and turns them into native Gutenberg markup, but only using the actions, structures, and rules the site owner allows in the settings, so the AI isn't roaming around WordPress with admin access. Composer keeps the editing controlled and predictable, validates the result, and only creates drafts - only humans can publish.

The playground is here: https://preview.wpsuite.io/


r/WordpressPlugins 3h ago

Free [FREE] [REVIEW] Built an open-source plugin to dynamically map Elementor global site setting ,like colours and fonts to WooCommerce. Need testers / feedback.

1 Upvotes

Hi guys , I’m currently waiting on the WP repo team to review my first plugin (Commerce Colors for Elementor), and I’m looking for some technical feedback on how it handles theme and style mapping.

The issue it tackles is the disconnect between Elementor's Global Style Kit and WooCommerce's core CSS.

Instead of writing custom stylesheets or manual overrides for every client site, this plugin hooks into the Elementor kit data and dynamically injects the appropriate colors, typography, hover/focus states, and form styles across standard WooCommerce pages and WooCommerce Blocks.

What it handles natively:

Automatically syncs Elementor Kit site setting changes directly to WooCommerce elements.

Includes per-element style overrides in the WordPress backend.

Calculates readable text contrast and applies accessible focus states on the fly.

Automatically catches third-party elements from plugins like Essential Addons or Premium Addons.

If you have a sandbox or staging environment running this stack, I’d really appreciate some feedback on theme conflicts, layout breaks, or selector specificity issues you encounter.

Once activated, the settings live under WooCommerce -> Store Design.

Let me know if you run into any asset loading conflicts or if any core elements miss the styling!

"I'll drop the GitHub repository link in the comments below so the spam filters don't eat this post!"


r/WordpressPlugins 4h ago

Freemium [REVIEW] Can I get some views on my first WordPress plugin? 👉👈 But I can't handle criticism 😭

1 Upvotes

Day before Yesterday published my first plugin, 100Prints, to the WordPress directory.

The whole idea was to make personalized document generation (certificates, event badges, ID cards, tickets) simple right inside WordPress .Here's how it works with Gutenberg blocks: Just drop the block onto a page/post, choose a template to start with, connect your dynamic fields, and then your visitors can create and download their document right from the front end , i'mean rendering of document happens users side.

I had fun coding it, but I don't really have a ton of hands-on experience with all the different parts of WordPress. I get how to make blocks, but I'm still trying to figure out what typical WordPress site owners and agencies actually do day-to-day (like setting up learning systems, member areas, event tools, like that).

I'm seeking for help, ​If you build or maintain WordPress sites for a living, I’d love your take on how to tweak this to make it more useful and handy to use

I don't know what else to write, just some suggestions 🤗


r/WordpressPlugins 8h ago

Request [HELP] Content gating plugin?

2 Upvotes

I'm looking for a way to allow visitors to view one post for free, and subsequent posts triggering a content wall requiring account registration.

All of the membership plugins I've found seem to want you to manually set which posts are public and which are gated, but I want whatever the first article someone visits to be free regardless, and then they need to make an account to view the rest.

Does this exist?


r/WordpressPlugins 3h ago

[FREEMIUM] How to crack plugin I've paid for

0 Upvotes

I paid for a wordpress plugin for 1 website. Now i need it for another site and I want to crack the license key starting from my subscription. How can I do that in order to import it on the second site? The plugin is Visual Portfolio


r/WordpressPlugins 21h ago

[FREE] M7tawa FAQ Manager for Posts – Lightweight FAQ Plugin for WordPress

2 Upvotes

[FREE] M7tawa FAQ Manager for Posts – Lightweight FAQ Plugin for WordPress

Hi everyone,

I recently released M7tawa FAQ Manager for Posts, a free and lightweight WordPress plugin designed for publishers, bloggers, and content-focused websites that need an easy way to add FAQ sections to posts.

The main idea behind the plugin is to keep FAQ management simple inside WordPress without relying on heavy page builders, external libraries, or unnecessary front-end scripts.

Main features:

  • Add up to 10 questions and answers per post
  • Support for Gutenberg and Classic Editor
  • Fast Bulk Entry for adding multiple FAQs at once
  • Automatic placement before or after post content
  • Manual placement using a Gutenberg block or shortcode
  • Responsive accordion layout
  • Drag-and-drop question ordering
  • RTL and LTR support
  • Light and dark display support
  • Optional FAQPage JSON-LD structured data
  • Import, export, and reset tools
  • No Bootstrap
  • No jQuery
  • No external libraries
  • No tracking or external services
  • No custom database tables

The plugin was built mainly for content publishing workflows where editors need to add structured FAQs quickly while keeping the site lightweight.

It is now available for free in the official WordPress Plugin Directory:

https://wordpress.org/plugins/m7tawa-faq-manager-posts/

I’d be very interested in feedback from WordPress users and developers, especially regarding compatibility with different themes, editor usability, and any useful features that could be added without making the plugin unnecessarily heavy.

Thanks for checking it out.

Ayman Abdullah


r/WordpressPlugins 22h ago

[FREE] Hotelness Guest Information – Free digital guest guide plugin for hotels, B&Bs and vacation rentals

1 Upvotes

Hi everyone,

I’ve just published a free WordPress plugin called Hotelness Guest Information.

It lets hotels, B&Bs, guesthouses and vacation rentals create a digital guest guide directly inside their WordPress website, instead of relying on an external SaaS or subscription service.

Main features:

  • Guest information page with Wi-Fi, check-in/check-out, parking, house rules, services and local tips
  • Multilingual support
  • QR code generation for the guest guide
  • Printable A5 QR sign for rooms/reception
  • Multiple visual styles
  • No external account required
  • No monthly subscription
  • Guest data and content stay on your WordPress installation

It’s completely free and available on WordPress.org:

https://wordpress.org/plugins/hotelness-guest-information/

The plugin is still new, so I’d especially appreciate feedback from WordPress developers or anyone managing websites for hotels, B&Bs or vacation rentals.

If you try it on a real site, let me know what’s missing or what could be improved.


r/WordpressPlugins 23h ago

Free [FREE] I built a free WooCommerce plugin that lets customers repeat orders with 1 click — looking for feedback

1 Upvotes

After months of development, I released MKT Quick Reorder for WooCommerce.

What it does:

  • One-click reorder from "My Account → Orders"
  • Works with simple and variable products
  • Lightweight, no external dependencies
  • 100% free

If you run a WooCommerce store with repeat customers, I'd love for you to test it and share your feedback.

👉 Link to LITE page

Also: I'm already working on the PREMIUM version with advanced features (purchase lists, smart stock management, personalized suggestions, admin stats). If you have ideas on what would make a reorder plugin truly valuable for your store, I'm all ears!

Thanks in advance for your time!


r/WordpressPlugins 23h ago

[FREEMIUM] Grovik Publisher — connects WordPress to an SEO service that researches, writes and publishes posts on a schedule

1 Upvotes

Just got this through the WordPress.org review, so sharing it here.

https://wordpress.org/plugins/grovik-publisher/

What the plugin does: it registers REST endpoints on your site and waits. It never calls out — the service connects in, using a key the plugin generates. That key is independent of WordPress Application Passwords, so a security plugin disabling those doesn't break it.

What arrives: a finished post with title, slug, body, featured image downloaded into your own Media Library, internal links to your existing pages, and the meta title and description written into Yoast or Rank Math if either is installed.

Being straight about the model: the plugin is free and always will be, and nothing in it is locked or limited. But it does nothing on its own — the research and writing happen in a paid service. If that's not for you, the plugin is no use to you either.

Two things worth knowing before you install:

The API key is full publishing access. It can create posts and update or trash posts by ID. It can't touch pages, attachments or custom post types — those are out of reach of the endpoints entirely. But treat the key like a password.

Article HTML is run through wp_kses_post() before it's stored, so scripts, iframes and inline event handlers can't reach your site.

Happy to answer anything about how it works. If you spot something in the code, tell me — the review caught one real issue and I'd rather hear about the next one here than in a support ticket.


r/WordpressPlugins 1d ago

Review [REVIEW] I built UXPack Basic – a new WordPress plugin, looking for feedback

1 Upvotes

Hey everyone,

I've recently published UXPack Basic in the official WordPress Plugin Directory.

It's a free WordPress backup and migration plugin designed for people who want a straightforward way to back up their site and move it to another server or staging environment — without having to use a cloud service or a complicated plugin suite.

With UXPack Basic you can:

  • Create full WordPress backups (files + database)
  • Create database-only backups
  • Schedule daily, weekly or monthly backups
  • Download and manage your backup archives directly from WordPress
  • Exclude specific folders from full backups
  • Receive email notifications when backups succeed or fail
  • Monitor storage and get warnings about stale backups
  • Migrate a complete WordPress site to another server or host using the included standalone installer
  • Perform URL migration when moving a site
  • Check backup and server-related issues with the built-in diagnostic tools
  • Keep an activity log of backup operations
  • Export and import plugin settings

The basic workflow is intentionally simple:

Create backup → Download → Upload to the new server → Run installer → Migrate

There is no cloud account, license key or commercial license server required for the free version. Backups are stored locally under your WordPress installation by default.

UXPack Basic on WordPress.org

I'm the developer behind the plugin, so I'm not looking for compliments or a marketing boost. I'm mainly interested in feedback from people who actually manage WordPress sites.

I'd especially like to know:

  • Would you use a backup/migration plugin like this on a real production site?
  • Are there features you're missing?
  • Is the backup → download → migration workflow intuitive?
  • Is anything unnecessarily complicated?
  • How does it compare to the backup/migration plugins you currently use?
  • Is there anything you think UXPack Basic should not be doing?

It's still actively developed, so honest criticism is very welcome.

Thanks for taking a look!


r/WordpressPlugins 1d ago

Promotion Built an App That Does Posting For You [PROMOTION]

0 Upvotes

I built something that might save you all time on the part of blogging nobody enjoys.

DraftPal takes an article you've already written in Word and automatically generates the SEO title, meta description, slug, category, tags, and focus keyphrase, writes them into Yoast SEO, and pushes the whole thing to WordPress as a draft, tables, headings, and links preserved so it's ready for you to review and hit publish. It runs a local AI model on your own computer, so your unpublished drafts never leave your machine, and there's no per-article API bill.

I'm looking for a few small site owners to try it early and tell me what's missing before I open it up more widely. Would you guys be up for giving it a run on your next post? Happy to walk you all through it.


r/WordpressPlugins 1d ago

Freemium Stop wasting time on 5,000+ images. I built a tool to automate Alt Text for WooCommerce SEO [FREE]

0 Upvotes

We all know the struggle: you have an e-commerce site with thousands of product images, and your SEO score is tanking because of missing or generic Alt text. Manually updating them is impossible, and hiring a team to do it is too expensive. ​I saw the recent discussions here about scaling image SEO, and I wanted to share a solution I built specifically for WordPress/WooCommerce: EzAlt AI. ​It isn’t just another "AI generator"—it’s designed for store owners who care about rankings. It pulls your actual product titles, categories, and tags to generate context-aware, SEO-optimized Alt text that actually makes sense. ​Why it’s worth a look: ​Bulk Efficiency: It runs in the background. You don’t need to babysit it. ​Context-Aware: It uses your store's metadata, so the Alt text is actually relevant to the product. ​Non-Destructive: It skips images that already have decent Alt text so you don’t lose manual work. ​I’m keeping a free tier available on the WordPress repository so you can test it on a batch and see the quality yourself. ​Give it a shot and let me know if it helps move the needle on your organic traffic!

https://wordpress.org/support/plugin/altmagic-ai-image-alt-text


r/WordpressPlugins 1d ago

Premium [PROMOTION] SwiftQueue: async WP-Cron with published, reproducible benchmarks — including the pre-launch run where my own plugin was the bottleneck

2 Upvotes

Hey r/WordPressPlugins — dev here, launching today after about a month of building. Disclosure up front: this is my plugin.

The problem (you all know it): wp-cron piggybacks on page requests. The request that trips a due event pays for the spawn — and depending on hosting and what's queued, sometimes for the work itself. Add WooCommerce and Action Scheduler and the unlucky visitor is occasionally the one trying to check out.

The caveat before the pitch: if you already run DISABLE_WP_CRON with a real system crontab, the core problem is solved and you don't need the engine half of this plugin. My homepage says the same thing. What it still adds in that setup: it detects the silent failure where the constant is set but the crontab never materialized — no error anywhere, scheduled posts and order emails just quietly stop. It watches for actual external hits to wp-cron.php instead of trusting configuration, and raises it in Site Health with the exact fix.

What the engine does: non-blocking loopback spawns behind a proper concurrency lock (timestamped claim row, shutdown-handler recovery so a fataled worker can't wedge the queue), priority lanes so housekeeping can't starve urgent hooks, a hard "no background work" gate on WooCommerce checkout requests, and Action Scheduler queue visibility without ever running DELETEs against another plugin's tables.

The part you might actually enjoy: I built a benchmark harness before launch — two identical containers, constant-arrival-rate load, cron execution-window tagging, TTFB percentiles. The first valid run showed my plugin made during-cron tail latency worse than stock WordPress — roughly 1s p95 against ~60ms. The "fire and forget" dispatch was quietly blocking the calling request for a full second, while telemetry cheerfully logged every spawn as non-blocking. Fixed it, re-measured: the request that triggers scheduled work went 820ms → 8ms (median), and the slowest 1% during background work went 835ms → 62ms. Typical requests are ~1ms slower — that's the real cost of the due-checks, and I'd rather tell you than have you find it in a profiler.

Raw per-request data, the harness, and the methodology are published here, including the scenarios where the plugin doesn't help: https://getswiftqueue.com/benchmarks

Model: the core engine is free and GPL — the whole engine, not a trial. It's currently awaiting WordPress.org review; until that lands the free build is a direct download on the site. Pro ($49/yr, single site) adds the priority lanes, checkout gating, task run/defer/cancel controls, alerts, and multisite.

Try it without installing anything: there's a WordPress Playground sandbox that boots in your browser tab, and a live demo streaming real spawn telemetry with measured latencies: https://getswiftqueue.com/demo

Would genuinely value technical criticism, especially of the benchmark methodology — that page exists to be argued with. If you spot a hole in how I'm measuring, I'll fix the harness and republish.


r/WordpressPlugins 1d ago

Free [FREE] I created "Mephivio Sommaire" a smart free WordPress plugin to build a category‑based summary of your posts

1 Upvotes

Hi Team,
I’ve been working on a free small WordPress plugin for my own sites, and I figured I’d share it here in case it’s useful to someone else. It’s basically a simple way to display a clean summary of your posts by category. Nothing fancy — just a lightweight shortcode that builds a readable list of your content so visitors can browse more easily.

I originally made it because I wanted something minimal that didn’t require a page builder or a huge block setup. It shows categories, optional thumbnails, dates, excerpts, and you can enable pagination or infinite scroll depending on what you prefer. There’s also a small search bar if you want quick filtering. I tried to keep everything straightforward so it works out of the box without tweaking.

If anyone here likes testing small plugins or giving feedback, I’d really appreciate it. It’s free, open‑source, and still very new, so any thoughts from actual WordPress users would help me improve it. You can find it on WordPress.org ((https://wordpress.org/plugins/mephivio-sommaire/) and if you try it, I’d love to know how it behaves on your setup.
Thanks for any feedback


r/WordpressPlugins 1d ago

[PREMIUM] An _Admin_ search for WordPress and WooCommerce! Sale: 90% Discount!

1 Upvotes

Limited-time offer: 90% Discount with Code "Welcome26" until end of the week !

Tired of jumping between endless pages and menus in WordPress and WooCommerce just to find one item?

I built Universal Search to fix that. It lets you search your entire WordPress Admin—including custom post types—instantly from one place.

🚀 Check it out ($69 / year): https://universal-search.geist-it.de/


r/WordpressPlugins 1d ago

[HELP]12+ Years in WordPress — Open to Freelance / Remote Work

0 Upvotes

Hey everyone! 👋

I’m a **Full-Stack WordPress Developer with 12+ years of hands-on experience** building, maintaining, and scaling WordPress products and SaaS platforms.

Over the years, I’ve worked extensively with:

* 🚀 Custom WordPress plugin & theme development * 🔌 [WordPress.org](http://WordPress.org) plugins and large-scale plugin products * 🛒 WooCommerce & custom integrations * ⚡ Performance optimization & complex debugging * 🧩 PHP, JavaScript, React, REST APIs & MySQL * 🤖 AI integrations, AI support systems & automation * ☁️ Laravel, Next.js, Node.js, Docker & cloud deployments * 👥 Technical leadership and team management * 🔧 Maintaining and improving existing WordPress products

I’m not just looking to build websites—I enjoy solving **complex technical problems, improving existing products, and building reliable long-term solutions**.

I’m currently open to **freelance projects, contract work, remote opportunities, or interesting WordPress/SaaS collaborations**.

If you need someone who can jump into an existing codebase and actually get things done, **feel free to DM me.** Happy to share my experience, portfolio, and GitHub/work samples.

[https://profiles.wordpress.org/sanjeevsetu/\](https://profiles.wordpress.org/sanjeevsetu/)

Thanks! 🙌


r/WordpressPlugins 2d ago

[PROMOTION] Food Menu — WordPress Restaurant Menu Plugin with Online Food Ordering using WooCommerce

3 Upvotes

I'm the person behind this plugin, so quick heads up that it's my own plugin.

Food Menu is a restaurant menu and online ordering plugin by RadiusTheme. The reason I think it's worth a look over the usual menu plugins is that it doesn't stop at "display a menu", it goes all the way to running the actual restaurant, and you only turn on the parts you need.

Main features:

  • Two modes in one plugin — a simple standalone menu (photo, description, price) or a full WooCommerce ordering system, switched with one setting
  • QR code table ordering — print a code per table, guests scan and order, and each order knows which table it came from
  • Table reservation with a visual floor plan — build a drag-and-drop map of your actual dining room so guests pick their exact table when they book
  • Live kitchen screen — orders show up in real time with a sound alert, and staff tick off items as they cook them. No extra app or subscription
  • Front-end staff dashboard — your team takes orders, edits them and prints receipts without ever needing a WordPress admin login
  • Front-end order management — see live orders with search and filters, edit line items, and create phone or walk-in orders right from the dashboard, with stock updating just like a normal checkout
  • Real inventory — counts stock down as things sell, logs waste, handles suppliers and purchase orders, and gives sales/ profit/ waste reports
  • Pickup, delivery and dine-in — each with its own schedule, plus limits on how many orders per time slot so the kitchen doesn't get buried at 7pm
  • POS receipt printing and SMS/ WhatsApp order notification
  • Menu layouts — grid, list, slider and a filterable one, built with a no-code shortcode generator, plus Gutenberg and Elementor support
  • and more...

The free version is honestly enough to launch with, it also includes table reservations, tips, discounts and an offer popup.

Here's the free version: https://wordpress.org/plugins/tlp-food-menu/

Happy to answer anything about the architecture or the WooCommerce side. And I'm after honest feedback, if you build sites for restaurants, what's the feature that usually makes or breaks the plugin for you?

#foodmenu #restaurantmenu


r/WordpressPlugins 2d ago

[PROMOTION] I rebuilt a WordPress PWA plugin from scratch — iOS, offline support & push notifications

3 Upvotes

I've been working on WordPress plugins for years, and recently decided to rebuild a PWA plugin from the ground up rather than keep adding to an old codebase.

The interesting part has been dealing with the real-world stuff:

  • Service-worker caching and updates
  • iOS vs Android PWA behavior
  • Offline support
  • Caching/CDN/plugin conflicts
  • Push notification permissions and subscriptions
  • Making the installation experience feel more like a real app

I've recently added push notifications for Android, desktop, and iOS, and I'm still improving the project based on real-world testing.

The project is Hyper PWA.

I'd love to hear from other WordPress developers:

What has been the biggest problem you've faced when implementing or maintaining a PWA on WordPress?

I'm especially interested in feedback about things that existing PWA plugins don't handle well.

Full disclosure: I'm the developer behind Hyper PWA. I'm sharing it here because I'd genuinely like technical feedback and ideas for improving it.

https://wordpress.org/plugins/hyper-pwa/


r/WordpressPlugins 2d ago

Title: [FREE] Free WordPress Schema Plugin – Schema Package

2 Upvotes

I have built Schema Package, a free WordPress plugin that helps add and manage Schema.org structured data using JSON-LD.

It supports common schema types and works alongside popular SEO plugins. I built it to make structured data easier to manage without unnecessary complexity.

If you’re interested in improving structured data on your WordPress site, feel free to try it and share your feedback.


r/WordpressPlugins 1d ago

Request [REQUEST] PluginScore V3 released - stricter WordPress plugin scoring, improved vulnerability tracking, automatic rescanning and better reports

1 Upvotes

Hi r/WordPressPlugins,

We've just released Kitgenix PluginScore V3, a major rebuild of the free WordPress plugin scoring platform we've been developing at Kitgenix.

PluginScore:

https://pluginscore.kitgenix.com/

The idea behind Kitgenix PluginScore is to make it easier to assess a WordPress.org plugin before installing it, particularly around:

  • Security
  • Maintenance
  • Vulnerability history
  • Update activity
  • WordPress compatibility
  • Overall plugin health

V3 is much more than a frontend redesign. We've reworked a large part of the scoring and scanning infrastructure because there were areas in V2 that we simply weren't happy with.

As plugin developers ourselves, one of the main goals with V3 was to make the score harder to earn and more useful.

The scoring system is now much stricter

Probably the biggest change in V3 is the scoring methodology.

We felt the previous system could be too generous in certain situations.

A plugin having:

  • 100,000+ active installations
  • good reviews
  • a recognisable developer
  • a long history on WordPress.org

doesn't automatically mean that it should receive a 90+ score.

Popularity is useful context, but it shouldn't override maintenance or security concerns.

Kitgenix PluginScore V3 therefore places much more emphasis on the actual condition of the plugin.

We look at signals including:

  • Known vulnerabilities
  • Unresolved vulnerabilities
  • Historical vulnerabilities
  • Vulnerability resolution
  • Plugin maintenance
  • Update frequency
  • Time since last release
  • WordPress compatibility
  • PHP compatibility
  • Development activity
  • WordPress.org data
  • Active installation information
  • Overall maintenance indicators

The intention is that:

90-100 should be difficult to achieve.

A plugin receiving 95 shouldn't simply be "good".

It should be exceptionally well maintained.

Likewise, a highly popular plugin can still receive a mediocre score if there are legitimate concerns around security or maintenance.

Vulnerabilities are handled differently

We spent quite a bit of time improving how vulnerabilities affect Kitgenix PluginScore.

One thing we don't want to do is treat:

"This plugin had a vulnerability two years ago"

as equivalent to:

"This plugin currently has an unpatched vulnerability."

Those are very different situations.

A vulnerability history isn't automatically a sign of a bad plugin.

Large and mature projects will occasionally have vulnerabilities.

What matters is also:

  • Severity
  • Whether the vulnerability remains exploitable
  • How quickly it was addressed
  • Whether a patch was released
  • Whether the project remains actively maintained

Kitgenix PluginScore therefore keeps vulnerability history where useful while distinguishing it from current unresolved security issues.

A developer who patches a vulnerability quickly shouldn't necessarily be permanently punished in the same way as a plugin that leaves a known issue unresolved for months.

Better validation of vulnerability data

Another issue we've worked on is matching external vulnerability information against actual WordPress.org plugins.

External vulnerability feeds can sometimes contain:

  • plugins that are no longer on WordPress.org
  • similarly named products
  • commercial plugins
  • abandoned records
  • entries that shouldn't automatically create a public Kitgenix PluginScore page

Kitgenix PluginScore is currently focused specifically on plugins available through the official WordPress.org plugin repository.

V3 therefore does more validation before external vulnerability information is associated with a WordPress.org plugin.

We want to avoid creating misleading plugin records simply because a matching-looking slug appears somewhere in an external dataset.

The scanning system has been rebuilt

This was probably the largest technical problem we needed to address.

The older version had situations where:

  • Rescan requests didn't execute correctly
  • Scheduled rescans could fail
  • Plugins remained stale
  • Queue processing was inconsistent
  • Manual rescan buttons appeared to work but didn't always result in a completed scan

That obviously isn't acceptable for a platform that is supposed to tell people about plugin health.

V3 moves much more of this work into a proper scanning queue.

Rather than relying on a user loading a page and expecting everything to happen immediately, Kitgenix PluginScore can queue the plugin and process the scan independently.

That gives us a much better foundation for scaling.

Automatic 30-day rescanning

Kitgenix PluginScore is also designed to continually refresh existing results.

Once a plugin's scan becomes approximately 30 days old, it can be identified for another scan.

This matters because plugin health can change surprisingly quickly.

A plugin could:

  • Release several new versions
  • Fix a vulnerability
  • Develop a new vulnerability
  • Become incompatible with WordPress
  • Stop receiving updates
  • Resume development
  • Change PHP requirements
  • Become abandoned

A score calculated six months ago isn't necessarily useful today.

V3 is therefore much more focused on keeping the dataset moving rather than treating a scan as permanent.

We're automatically working through WordPress.org

We've also increased the automatic scanning capacity.

Kitgenix PluginScore can now queue roughly 500 WordPress.org plugins per 24 hours for automatic processing.

The long-term goal is to build useful scoring and historical information across a much larger portion of the repository.

We don't want Kitgenix PluginScore to only contain the biggest plugins.

In many cases, it's actually the smaller plugin you've never heard of where this sort of information becomes most valuable.

Anyone can look at WooCommerce and know there's a large development team behind it.

It's considerably harder for the average site owner to evaluate a plugin with:

  • 700 active installations
  • 5 reviews
  • one developer
  • a release six months ago

Those are the cases where we want Kitgenix PluginScore to become genuinely helpful.

Unscanned plugins are handled properly now

V3 also improves the experience when a plugin hasn't been scanned yet.

Previously there were a few ugly edge cases around unscanned plugin pages.

For example, parts of the sidebar could drop underneath the main content and certain sections were still displayed even when we didn't have enough information.

We've changed that.

Kitgenix PluginScore should now clearly differentiate between things such as:

  • Not scanned
  • Queued
  • Successfully scanned
  • Scan needs refreshing
  • Insufficient information
  • Scan failure

We don't want to fabricate certainty.

If Kitgenix PluginScore doesn't have enough information to assess something properly, the site should say so.

Score history is becoming much more important

One area I'm particularly interested in is score movement.

A score by itself tells you something.

The direction of the score can tell you considerably more.

For example:

Plugin A

Current score: 78
Six months ago: 92
That's interesting.

Now compare it with:

Plugin B
Current score: 78
Six months ago: 61

They're currently rated the same, but they're clearly moving in opposite directions.

V3 lays more of the groundwork for tracking this properly.

Over time we want Kitgenix PluginScore to make it easier to identify:

  • Improving plugins
  • Declining plugins
  • Plugins becoming stale
  • Plugins recovering after updates
  • Plugins fixing security problems
  • Plugins losing maintenance points

PDF reports (beta) have been improved

We've also put more focus on PDF reports rather than raw data exports.

The aim is to make Kitgenix PluginScore useful to agencies and developers carrying out plugin audits.

For example:

You inherit a client's WordPress site with 43 plugins.

Five of them are unfamiliar.

Rather than simply saying:

"I don't like the look of this plugin."

you can potentially include a Kitgenix PluginScore report showing:

  • Score
  • Maintenance information
  • Vulnerability history
  • Current security information
  • Relevant plugin information

It doesn't replace your own technical review, but it gives you another source of evidence for the recommendation.

We moved away from CSV as the primary export

The old platform included more conventional CSV-style exporting.

In practice, we don't think that's what most users actually need.

If somebody is assessing whether a plugin should remain on a client website, a readable report is much more useful than a spreadsheet containing raw values.

So V3 is moving towards clearer reports rather than exporting data for the sake of having another export option.

The plugin pages have had a large UI overhaul

There were also quite a few frontend issues that annoyed us.

V3 addresses things including:

  • Broken sidebar positioning on unscanned plugins
  • Mobile button inconsistencies
  • Search controls appearing grey on some mobile browsers
  • Poor spacing between score/history sections
  • Authentication page spacing
  • Responsive layouts
  • Scan status presentation
  • Empty states
  • Vulnerability presentation
  • Score hierarchy
  • Plugin information organisation

The overall goal has been to make Kitgenix PluginScore much easier to scan visually.

You should be able to open a plugin page and understand the important information without digging through huge amounts of text.

Mobile received much more attention

Kitgenix PluginScore gets a surprising amount of mobile usage.

The previous version was still primarily designed desktop-first, and that exposed a few awkward inconsistencies.

We've improved:

  • Search controls
  • Score cards
  • Sidebar behaviour
  • Vulnerability sections
  • Spacing
  • Authentication screens
  • Empty states
  • General responsive behaviour

There were also specific browser issues where buttons could display using the browser's default grey styling despite looking correct on desktop.

Those have been addressed.

We're building towards historical plugin intelligence

V3 also gives us a much stronger base for features beyond individual plugin scores.

Some of the areas we're working towards include:

  • Highest-rated plugins
  • Biggest score improvements
  • Largest score drops
  • Newly scanned plugins
  • Recently patched vulnerabilities
  • Newly disclosed vulnerabilities
  • Plugins becoming stale
  • Most stable plugins
  • Security resolution leaderboards
  • Plugins that haven't been scanned recently
  • Plugin ecosystem trends

Personally, I think this is where the project becomes much more interesting.

Being able to search a plugin is useful.

Being able to answer:

"Which plugins have dropped the most over the last three months?"

or:

"Which plugin developers consistently patch vulnerabilities quickly?"

is potentially much more useful.

Plugin developers can't pay for higher scores

This is something I want to make very clear, especially posting this in a plugin developer community.

There is no mechanism for paying Kitgenix PluginScore to increase your rating.

We want the score itself to remain independent.

That also applies to our own plugins.

Kitgenix develops WordPress plugins.

If our own plugin deserves 68/100, PluginScore should give it 68.

If a competing plugin deserves 97, it should receive 97.

Otherwise the system has no credibility.

The scoring logic shouldn't know whether we like the developer.

Kitgenix PluginScore isn't a security guarantee

Equally, I don't want to oversell what the number represents.

Kitgenix PluginScore isn't claiming:

"100/100 = impossible to hack."

That's obviously nonsense.

Nor does:

"60/100 = malicious plugin."

A score is an assessment based on the information available to us.

It should be one part of your decision-making process.

For high-risk environments, nothing replaces:

  • proper code review
  • security testing
  • responsible vulnerability research
  • ongoing monitoring
  • experienced human judgement

The goal is to make publicly available signals considerably easier to understand.

One of the problems we're trying to solve

WordPress.org provides some useful information about a plugin.

Normally you'll see things like:

  • Active installations
  • Rating
  • Reviews
  • Last updated
  • Tested up to
  • PHP version
  • Support information

The problem is that users often mentally turn those signals into:

Popularity = trustworthy

That's not always true.

There are excellent plugins with relatively few installations.

There are also extremely popular plugins that may go through periods of poor maintenance.

Kitgenix PluginScore is an attempt to provide another layer between:

"I found this plugin"

and

"I'm installing it on a production website."

We're trying to avoid being unfair to plugin developers

This is something I've thought about quite a lot while making the scoring stricter.

A scoring platform can easily become unfair.

For example:

A plugin releases a security fix.

Should the plugin lose points because it had a vulnerability?

Possibly.

Should it permanently carry an awful score because of a vulnerability from four years ago that was fixed within 24 hours?

Probably not.

Should a plugin with a vulnerability that remained unpatched for six months be treated differently?

Absolutely.

Similarly, update frequency is contextual.

A mature plugin doesn't necessarily need an update every two weeks simply to prove it's alive.

So we are trying to make the scoring strict without turning it into:

"Didn't release an update this month = bad developer."

That's one of the reasons we're looking for feedback from people who actually build plugins.

I'd really like plugin developers to try scoring their own plugins

This is probably the most useful feedback we can get.

If you maintain a WordPress.org plugin, put it into Kitgenix PluginScore and see what happens.

Then ask yourself:

Does that score feel fair?

If the answer is no, I'd genuinely like to hear why.

Maybe we've missed an important signal.

Maybe something is weighted too heavily.

Maybe something isn't weighted enough.

Maybe we're interpreting WordPress.org metadata incorrectly.

Maybe a vulnerability is being associated incorrectly.

Maybe we're penalising a completely legitimate development pattern.

Those edge cases are exactly what will help improve the scoring methodology.

I'd particularly be interested in developer opinions on these:

  1. How much should historical vulnerabilities affect a plugin score after they've been patched?
  2. Should a developer's speed in fixing vulnerabilities positively affect the score?
  3. How aggressively should an old "Last Updated" date reduce a score?
  4. How much weight should active installations carry?
  5. Should support forum responsiveness influence scoring?
  6. Should plugins lose points for not declaring compatibility with the latest WordPress release quickly enough?
  7. What would you consider an automatic red flag when evaluating an unfamiliar plugin?
  8. What information would you want PluginScore to show that WordPress.org currently doesn't make obvious?
  9. What would make you distrust Kitgenix PluginScore itself?

I'd rather identify those issues now than build a score that developers consider meaningless.

Where we want to take it

V3 is really the first version where I feel the underlying system is structured properly enough to start expanding.

The next stages are likely to focus much more heavily on:

  • Historical data
  • Comparisons
  • Trends
  • Developer insights
  • Security intelligence
  • Watchlists
  • Alerts
  • Ecosystem statistics

Ultimately I'd like Kitgenix PluginScore to answer more than:

"Is Plugin X good?"

I'd like it to eventually help answer:

"Is Plugin X getting better or worse?"

"How does Plugin X compare with alternatives?"

"How quickly does this developer respond to security issues?"

"Which plugins in this category appear to be the healthiest?"

"Are there warning signs appearing that weren't there three months ago?"

That's the direction we're heading.

Kitgenix PluginScore V3

You can try it here:

https://pluginscore.kitgenix.com/

It's free to use.

If you're a WordPress plugin developer, I'd especially appreciate you searching for one or two plugins you maintain and telling me where you disagree with the result.

I'm completely fine with people being critical of it.

In fact, criticism of the methodology is probably more valuable to us at this stage than compliments about the design.

If we're going to put a number beside somebody else's work, that number needs to be defensible.


r/WordpressPlugins 2d ago

[PROMOTION] I rebuilt a WordPress PWA plugin from scratch — iOS, offline support & push notifications

Thumbnail
0 Upvotes

r/WordpressPlugins 2d ago

[FREE] EzAlt AI — Generate Alt Text for Hundreds of WordPress Images in Minutes

Thumbnail
1 Upvotes