
Most WordPress sites accumulate plugins. A developer installs one for a job that ended three years ago, someone else solves the same problem a different way, and nobody dares turn anything off in case it breaks the site.
WordPress can only tell you what is active. It has no idea what is used. PluginTidy closes that gap.
It looks at each plugin and gathers evidence: whether its shortcodes and blocks appear in your content, whether it has scheduled work, whether the data it stores is still written to, whether anyone opens its settings, whether it is still maintained, and whether several plugins do the same job.
Then it tells you what it found — and shows you every reading behind it, so you can disagree.
Every assessment expands into the checks that produced it. Nothing is a recommendation on its own.
If scheduled tasks are not running on your site, every plugin looks idle. PluginTidy detects that and excludes scheduled activity from the assessment rather than holding it against everything. The same applies when WordPress.org cannot be reached: it says so, and the confidence figures show it.
From the moment you install it, PluginTidy records every plugin installed, activated, updated, deactivated or removed — who did it, when, and why, if you tell it. The history survives the plugin being deleted, so a problem that shows up later can be traced back to the change that caused it.
Everything above. The full audit, all the evidence, the redundancy findings, the notes, and the complete change log. Nothing is capped — an audit that stopped at ten plugins would be absurd for a tool whose whole purpose is having too many.
The free version never changes another plugin. It does not delete one, and it does not switch one on or off. It reads, it scores, and it records. When you decide to act, it links you to WordPress’s own Plugins screen.
Pro does two things the free audit deliberately will not: it acts on what was found, and it keeps looking after you stop.
Acting on it safely
Keeping it that way
PluginTidy is one of a small range of tools built for people who actually run publications. Each works on its own, and all are free on WordPress.org:
This plugin contacts WordPress.org (api.wordpress.org) to find out whether each installed plugin is still maintained and whether it has been removed from the plugin directory.
What is sent: the folder name of each installed plugin. Nothing else — no site address, no email address, no content, no personal data. Answers are cached for twelve hours.
This happens when you run an audit. If WordPress.org cannot be reached, the audit still completes and says that this check was skipped.
WordPress.org privacy policy: https://wordpress.org/about/privacy/
This plugin also uses Freemius (freemius.com) to handle licensing, and to offer an optional diagnostic opt-in.
What is sent, and only if you accept the opt-in when you activate the plugin: your site address, your WordPress administrator email address, and version information about WordPress, PHP and your site. You can decline this and the plugin works exactly the same. Nothing about your content, your visitors or your audit results is ever sent.
If you buy a licence, your licence key is checked with Freemius so the paid features can be switched on. That check happens whether or not you accepted the diagnostic opt-in, because it is what the licence is.
Freemius terms of service: https://freemius.com/terms/
Freemius privacy policy: https://freemius.com/privacy/
This plugin also includes the PublisherKits Support Copilot (bwtlsupport.com, operated by Black and White Trading Ltd) – the Help button on PluginTidy’s screens. Nothing is sent until someone with plugin permissions reads the privacy notice in the chat and agrees.
What is sent when you ask a question: your question and the recent chat; your site address and, where available, your licence installation identifier, used to authorise the request and apply fair-use limits; the PluginTidy version; the admin screen you are on; and a few non-sensitive diagnostics – how many plugins are active and inactive, whether an audit has run, whether scheduled tasks work, and whether WordPress.org could be reached. The names of the plugins on your site, your audit results, your notes and your change log are never sent. Choosing “Send to support” keeps the conversation as a ticket, with the email you give and your WordPress first and last name.
Terms of service: https://publisherkits.com/terms/
Privacy policy: https://publisherkits.com/privacy-policy/