Somebody will tell you to stay under ten. Somebody else runs forty on a fast site. Both are right, because the number is not what matters — a plugin that adds a contact form costs almost nothing, and one that rebuilds how every page is rendered costs a great deal.
Three questions tell you more than any count.
Question 1: does it load on every page, or only where it is used?
This is the big one. A well-built plugin loads its code only on pages that need it. A badly built one adds its stylesheet and script to every page on the site, including pages that never use it.
Ten well-behaved plugins can be lighter than two badly behaved ones. The usual offenders are sliders, page builders, anything with "ultimate" or "all-in-one" in the name, and social sharing plugins.
Question 2: is anyone still maintaining it?
On the plugin's page in the WordPress directory, check when it was last updated and whether it is tested with the current WordPress version. A plugin untouched for two years is not stable — it is abandoned, and the next WordPress or PHP release may break it. Worse, nobody is fixing its security holes.
Most WordPress sites that get compromised are compromised through an outdated plugin, not through WordPress itself.
Question 3: would you notice if it vanished?
Go through the list and ask this honestly of each one. On most sites that have been running a few years, a third of the plugins are leftovers — installed to try something, never removed. Each is code you are not using, that still loads, that still needs patching.
What is actually worth having
Nearly every business site needs a handful of categories filled, and one plugin each:
- Caching — the single biggest speed win available.
- SEO — titles, descriptions, sitemap. One, not two; running two is a common cause of duplicate tags.
- Backups — scheduled, stored off the server, and restored once as a test.
- Security — login limiting and file monitoring.
- Forms — whatever you already know.
- Images — compression and WebP conversion.
That is six. Most sites need a few more for their specific business, and that is fine. What is not fine is three plugins doing the same job because nobody removed the previous attempt.
How to audit what you have
- List every plugin and write one sentence on what it does. Anything you cannot write a sentence for is a candidate for removal.
- Check the last-updated date on each. Anything over a year is a risk.
- Look for overlap. Two SEO plugins, two caching plugins, two security plugins — pick one.
- Deactivate the doubtful ones, then delete them. Deactivated is not removed; the files stay on the server and stay exploitable.
- Do it on a staging copy first if the site matters, and take a backup either way.
The honest summary
Plugins are why WordPress is useful. The problem is never that you have plugins — it is that nobody has looked at the list in three years. An hour spent auditing it usually makes the site faster and meaningfully safer, and costs nothing.
If you would rather someone did that properly, it is part of our WordPress customization and maintenance work. Send us the URL for an outside look.
