Home / Security / Audit and remove unused admin accounts and plugins
Defensive & Operational · Security Ring

Audit and remove unused admin accounts and plugins

1-2 hr Impact: high Effort: low ✓ Manual completion

Old admin accounts and unused plugins left installed, even inactive ones, represent real attack surface, an unused plugin with a known vulnerability is just as exploitable whether you actively use it or not, since the vulnerable code is still present.

Attackers specifically scan for known vulnerabilities in installed plugins and themes, whether active or not, removing what you do not genuinely need shrinks your actual attack surface.

The full picture

Auditing and removing unused admin accounts and plugins addresses a genuine security principle worth understanding clearly — every active administrative account and every installed plugin or extension represents potential attack surface, regardless of whether it's actively being used, meaning unused elements provide risk with no corresponding legitimate benefit.

Unused admin accounts represent a particularly common, often-overlooked risk — former employees, contractors, or team members who no longer need administrative access but whose accounts were never properly deactivated represent genuine, unnecessary risk, since these accounts remain valid access points that could be compromised or misused without providing any current legitimate business value.

Unused plugins or extensions carry similar risk from a different angle — even inactive plugins can sometimes retain exploitable vulnerabilities, and simply having unnecessary code installed on your system, even if not actively invoked, represents unnecessary attack surface that a genuinely minimal, well-maintained system would eliminate entirely rather than leaving present but dormant.

This audit deserves periodic repetition rather than treatment as a single, one-time cleanup — team composition changes, and plugin needs evolve over time, meaning new unused accounts or extensions can accumulate after any initial cleanup, making this a genuine, recurring maintenance practice worth building into your regular security review process.

How to do it

  1. 1
    Audit every admin account with access
    Remove or downgrade access for anyone who no longer needs it, former employees, old contractors, unused service accounts.
  2. 2
    Audit every installed plugin or extension
    Identify anything not genuinely in active use.
  3. 3
    Remove unused plugins entirely, not just deactivate
    A deactivated plugin can still contain exploitable code sitting on your server, full removal is the real fix.
  4. 4
    Repeat this periodically
    This tends to accumulate again over time as new tools get tried and abandoned.

Common mistakes

How you will know it is done

No unused admin accounts or plugins remain, everything present is genuinely in active use.

Track this in your hive

The Security Ring turns this into a real, permanent mission — mark it complete once you have genuinely done it.

Open this mission in H.I.V.E. →