Websites and Tech

Plugin

Also called WordPress plugin, extension, add-on

An add-on that gives a website platform such as WordPress a new feature, from contact forms and SEO settings to shops, bookings and security.

Quick facts: Plugin

Category
Websites and Tech
Also called
WordPress plugin, extension, add-on
Level
Beginner
Affects
Site features, speed, security, cookie consent and UK GDPR obligations
Where to see it
WordPress Plugins screen, WordPress Site Health, Query Monitor, WPScan vulnerability database, browser developer tools
In this article4
  1. How a plugin works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

A plugin is a package of code that adds a feature to a website platform without changing the platform itself. On WordPress, plugins provide contact forms, SEO settings, online shops, booking calendars, backups, security tools and much more. Shopify calls them apps and other platforms use names such as extensions, but the idea is the same.

How a plugin works

WordPress is built with hooks: points in its code where other code is allowed to step in, add something or change the result. A plugin uses those hooks to do its job, for example adding a meta description box to the editor or sending form entries to your inbox. Installing one copies its files into wp-content/plugins; activating it tells WordPress to run them.

Free plugins come from the official WordPress directory, which holds tens of thousands of them and checks each one before listing it. Premium plugins are sold by their developers and update through a licence key. Each plugin can load its own scripts and styles on the front end, add database tables, set cookies and connect to outside services.

Why it matters

Plugins make a capable site affordable, but each one is code someone else wrote, running on your site. Out-of-date plugins are one of the most common routes into hacked WordPress sites, which is why security patches need applying promptly. Plugins also add weight: a slider, a chat widget, a social feed and a popup tool can each load scripts on every page.

For a UK business, plugins also bring legal duties. Many set cookies or send visitor data to outside companies: analytics tools, embedded maps and videos, chat widgets, reCAPTCHA, email marketing forms. Under PECR, non-essential cookies and similar storage need consent before they are set, so your cookie banner has to know about and control each of them. Under UK GDPR, a plugin that sends personal data to its developer’s servers often makes that company a processor, and sometimes a separate controller. Either way you need to know where the data goes, have the right contract in place and mention it in your privacy notice.

Common mistakes

  • Installing a plugin that has not been updated in years, or that has open security warnings.
  • Running two plugins for the same job, such as two SEO plugins or two caching plugins, which produces conflicting output.
  • Leaving deactivated plugins installed. Their files are still on the server and can still be attacked.
  • Using nulled premium plugins from unofficial sites, a common source of malware.
  • Adding a plugin that sets tracking cookies on page load before the visitor has consented.
  • Updating everything on the live site at once without a backup, then not knowing which update broke the layout.

How to act on it

Go through your Plugins screen and, for each one, note what it does, whether you still need it, when it was last updated and whether it sets cookies or sends data elsewhere. Delete what you do not need. For the rest, check the cookies each one sets with your browser’s developer tools on a fresh visit, and make sure your banner blocks the non-essential ones until consent is given.

Before adding a new plugin, check its update history, number of active installs and support forum, and test it on a staging copy. Auditing plugins for speed, conflicts and SEO output is a standard first step in my WordPress SEO work.

Do and do not

Do

  • Check when a plugin was last updated before installing it
  • Find out what cookies and data each plugin sets or sends
  • Delete plugins you have deactivated and no longer need

Do not

  • Install nulled or pirated premium plugins
  • Run two plugins that do the same job
  • Update every plugin on the live site without a backup

Questions people ask about this

How many plugins is too many?

There is no safe number. One badly written plugin can slow a site more than twenty light ones. Judge each plugin by what it loads, how well it is maintained and whether you still need it, rather than by the total count.

Do I need consent for cookies set by a plugin?

If the cookie is not strictly necessary for something the visitor has asked for, such as a basket or login, then for UK visitors you generally need consent before it is set. Analytics, advertising, chat and many embed cookies fall into that group. Check each plugin's cookies and configure your consent tool to block them until the visitor agrees.

Should I turn on automatic plugin updates?

For well-maintained plugins with a good record, automatic updates usually reduce risk because security fixes arrive straight away. For plugins that run critical features, such as your shop or booking system, you may prefer to update manually after a backup and a check on staging. Whichever you choose, make sure someone looks at the site after updates.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.