Do deactivated WP plugins and themes pose a security risk?
I have been using a wordpress plugin to do a security audit of my wordpress-backed website. I am the sole administrator of this site.
One thing I find very strange is that it reports deactivated themes and plugins as problems.
I keep my list of active plugins small, but I've never given a second thought to keeping plugins or themes I no longer use. Am I missing something? Can a malicious actor find some way to use to exploit deactivated plugins or themes?
[link] [comments]