Why fewer plugins?

Every plugin is third-party code with its own updates, flaws and load.We check each one: does your website need it?

Plugins installed, before and after typical example
41 at handover
26 after our review
30 pairs doing the same job
50 active, but with no job
70 deactivated, still on the server
30 no update in over a year
10 copy from an unknown source
A typical picture at handover, not the figures of any specific client.
  • What a plugin bringsWhat a plugin brings along
  • Good pluginsHow we spot a good plugin
  • When one breaksWhat happens when a plugin breaks

What a plugin is

A plugin is third-party software on your server. It adds a feature, but also four oblig­a­tions. Two for the same job often get in each other's way.

A plugin is a piece of software that someone else wrote and that runs on your server. It adds a feature, but it also brings four oblig­a­tions.

Two plugins for the same job double these obligations and can interfere with each other.

  • At handover, we review every plugin indi­vid­u­ally
  • What is not needed is deleted, not just deac­ti­vated
  • Where two plugins overlap, one of them stays

WordPress can do a lot without an extra plugin.

What every plugin brings along Diagram
One pluginadds one feature
Update schedule The vendor decides when
Vulner­a­bil­i­ties Even when deactivated
Load On every page view
Depen­den­cies On the page builder, say
Two for the same job:
Cache 1 Cache 2
They overwrite each other. When something fails, it is unclear which one it was.

What goes wrong in practice

A lot of damage happens without an attack. In all three patterns, third-party code was treated as if it were your own.

  • Change made in plugin code, overwritten by the update
  • Page builder updated live, home page broken for hours
  • Theme template edited, overwritten by the update
  • Custom changes live in custom code
  • Updates first on a copy of the website

Cases from our work, treated confi­den­tially.

The same change, two places Diagram
In the plugin's code
In custom code
before the update
Plugin, old version Your change
before the update
Plugin, old version
Your change
Vendor update
after the update
Plugin, new version Change gone
after the update
Plugin, new version
Change stays
The same applies to theme templates.

How we choose and update plugins

Before adding any new plugin, we check four points, and we install updates in a fixed order. If a plugin breaks anyway, it is clear what happens next.

Profile before every new plugin Selection
Actively maintained Updated within the last year, vendor fixes bugs
Widely used Many instal­la­tions, so bugs surface early
Well documented Every version described, security fixes named
From the vendor No copies from unknown sources: no updates, often malware
First: is a plugin needed at all? If you explicitly want one, we install it.
Order of an update run one at a time
  1. 1 Backup, confirmed
  2. 2 WordPress
  3. 3 Page builderits add-ons
  4. 4 Translation pluginTheme
  5. 5 Other plugins, one after another
  6. 6 Shop systemPayment
  7. 7 Cache cleared, site checked
Whatever depends on it comes after. Checked: home page, menu, form, checkout, login.
When a plugin breaks
  1. 1Backup restored, website runs as before
  2. 2Inves­ti­ga­tion on the copy of the website
  3. 3Old version for now, with a review date
  4. 4Bug fixed: the update is installed
  5. 5Not fixed: we look for a replace­ment
  6. Decisions are yours to make
Licenses included
Elementor Rankmath WPForms WPML WP Rocket

No license invoices for you. When maintenance ends, the licenses end too; we point this out before any cancel­la­tion.

Questions clients ask about plugins

Can you install a specific plugin for me? Yes, first on the copy.

If it is poorly maintained or an existing one does the same, we tell you. The decision stays with you.

Should I switch to a tool I saw adver­tised? Usually not.

A switch means setup, testing and new third-party code. If what you have does not solve your problem, we suggest a switch ourselves.

Can you modify a plugin for me? Not in its code.

The next update would overwrite the change. We extend it through hooks, build a small plugin of our own, or pass the request to the vendor.

Why delete, not deac­ti­vate? Otherwise the code stays.

A vulner­a­bility in a deactivated plugin can still be reached, only nobody notices it. If the plugin is needed later, it is quickly rein­stalled.

Ready for dependable care?

Book a call
30 minutes by phone or video. You pick an open slot in the calendar.
Send a message
Briefly describe what you need. You will get a reply within 24 hours on working days.