Your WordPress Site Has 27 Plugins. That’s Why It’s Slow.

Your WordPress Site Has 27 Plugins. That’s Why It’s Slow.

Website Dreamwork

Key takeaways

  • The average small business WordPress site I audit has 22–35 active plugins. That is 3–4x what the site actually needs.
  • Every plugin is code that runs. Runs slowly, on someone else’s schedule, with someone else’s security discipline.
  • Plugins are the #1 cause of slow admin, slow front-end, and hacked WordPress sites.
  • A ruthless cull — usually down to 8–12 — wins back seconds of load time and hours of your future life.
  • The rule is boring: keep only plugins that do a job you cannot live without, from developers who ship updates.

Every once in a while, an East Texas small business owner asks me to “take a look at why the site is slow.” I log into the WordPress dashboard. I click Plugins. I stare at a list that goes down four screens. Backup plugin. Backup plugin from 2020. A caching plugin. A different caching plugin from a different developer. A form plugin that hasn’t been updated in 18 months. A slider. A carousel. A photo gallery. A different photo gallery. A gutenberg-block library that adds 40 blocks nobody uses. A Facebook Pixel plugin. A separate Google Analytics plugin. A newsletter opt-in. A cookie banner. A social share plugin. A related posts plugin. A comment plugin. A different comment plugin. And so on.

Twenty-seven active plugins. On a five-page brochure website. That is the problem. That has always been the problem. And that is why the site loads in six seconds.

What plugins are actually doing

Every WordPress plugin is a chunk of code that runs during each page load. Some of them run once and quit. Most of them keep running, checking things, calling external services, writing to the database. On the admin side, plugins have “wp-cron” jobs that fire on schedules you never see. On the front end, plugins inject CSS, JavaScript, and sometimes ads or trackers you never authorized.

Twenty-seven of them, all sharing the same PHP process, all fighting for the same MySQL queries. That is why your site is slow. That is why the admin takes 8 seconds to save a page. That is why your host tells you to upgrade to a more expensive plan.

You do not need a faster host. You need fewer plugins.

The math of plugin bloat

Here is what a bloated stack costs you, roughly:

What plugin count adds 27 plugins 10 plugins
Extra CSS files loaded 15–25 5–8
Extra JavaScript files 18–30 3–7
Database queries per page +120–200 +30–50
Security surface area 27 attack vectors 10
Monthly hours updating them 1–2 15 minutes

None of those numbers are exact. All of them are directionally right. The point is not the exact math; the point is that every plugin has a real ongoing cost, and most of the plugins doing that costing are not paying you back.

The cull, in five categories

1. Duplicates — delete instantly

Two caching plugins is not twice as fast; it is fighting. Two analytics plugins fires two trackers. Two galleries costs you both loading their CSS. Delete the worse one. Keep the better one. Two minutes of work.

2. Never used in the last 90 days — delete

If a plugin’s admin screen has not been opened in three months and it is not doing something automatic and critical, it is dead weight. Deactivate. Wait a week. If nothing broke, delete.

3. Abandoned by the developer — delete

WordPress.org tells you when a plugin was last updated. If it says “not tested with the latest 3 major versions of WordPress,” it is a security time bomb. Replace with a maintained alternative or delete.

4. Doing something the theme or WordPress core already does — delete

Modern block themes include galleries, buttons, columns, custom fonts, and layout tools. If you are running a “custom columns” plugin, you probably do not need to. Same for sliders (the block editor has one), and social sharing (a properly designed theme has small share buttons built in).

5. Doing one small thing badly — consolidate

A separate plugin for Analytics, another for Pixel, another for schema, another for cookies, another for the sitemap? Consolidate into one modern SEO plugin (Rank Math or Yoast) and one performance plugin (WP Rocket, LiteSpeed, or Perfmatters). Six plugins collapse into two.

What to keep

An average small business site’s healthy plugin list:

  1. An SEO plugin (Rank Math or Yoast)
  2. A caching / performance plugin (WP Rocket, LiteSpeed Cache, or FlyingPress)
  3. A form plugin (Fluent Forms, WS Form, or Gravity Forms)
  4. An anti-spam plugin (Cleantalk, Antispam Bee)
  5. A security plugin (Wordfence or Solid Security, or none if your host handles it)
  6. A backup plugin (UpdraftPlus or your host’s built-in)
  7. Image optimization (ShortPixel or built into your cache)
  8. If e-commerce: WooCommerce and its 1–2 essential extensions
  9. If bookings: one booking plugin, chosen carefully
  10. If content design needs: one page builder or block library (not two)

Eight to twelve plugins covers 90% of small business sites. Anything above that needs a specific justification.

The one-plugin rule. One caching plugin. One SEO plugin. One security plugin. One backup plugin. When you find yourself with two of anything, one has to go.

How to cull safely in one afternoon

  1. Back up your site before you touch anything.
  2. List every active plugin in a spreadsheet.
  3. Note the last update date and last time you used it.
  4. Sort the list into “keep,” “replace,” and “delete.”
  5. Deactivate the “delete” ones one at a time. Reload the front page. If nothing broke, move on.
  6. Wait a week. Check the site. Then hit “Delete” on the deactivated ones.
  7. Consolidate the “replace” ones over the next week.
Watch out. Do not deactivate five plugins at once and then discover the contact form was tied to one of them and nobody’s emails came through for three days. One at a time. Test each time.

The security angle

Almost every WordPress site that gets hacked was hacked through an out-of-date plugin. Not through a hardened server. Not through a weak WordPress core. Through a plugin the site owner did not know they had.

Fewer plugins means fewer attack surfaces. That alone is worth the cull. When you drop from 27 to 10, you go from “statistically likely to be exploited this year” to “probably fine.”

What good looks like after

A well-groomed WordPress site:

  • Loads its homepage in under 2 seconds on 4G
  • Passes Core Web Vitals across the board
  • Runs 10–15 plugins, all actively maintained
  • Updates plugins with two clicks and no prayer
  • Is genuinely enjoyable to log into and use

All of that is downstream of the plugin count. Not the theme. Not the host. Not the mysterious “something Google changed.”

Where people go wrong (and when to call a pro)

The mistake is either doing nothing (“it’s been working, don’t touch it”) or ripping out plugins randomly and breaking things. Neither of those is the answer. The answer is a careful, backed-up, one-at-a-time cull, with a clear plan for what to keep and what to replace. It is boring work. It is also the difference between a site that loads in 2 seconds and one that loads in 6. If your gut says “I don’t have time for this” — that is what an afternoon of our time is for. We come in, cull, consolidate, tune, and hand you back a leaner WordPress.

Frequently Asked Questions

Are more expensive plugins actually less bloat?

Sometimes, but not automatically. Well-maintained premium plugins tend to be leaner, but there are lightweight free plugins and bloated premium ones. Test with real performance tools, not marketing pages.

Do inactive plugins slow the site?

Inactive plugins do not run on the front end, but they can still be a security risk if their files are exploitable. Delete anything you are not actively using.

Can I just switch to a page builder that replaces plugins?

Some page builders (Bricks, Cwicly, GenerateBlocks) replace a lot of small plugins. Others (Elementor with 30 add-ons, or Divi loaded with modules) make bloat worse. Pick carefully.

What about must-use plugins my host installed?

Those are usually fine and sometimes required. Do not delete them without checking with your host, but do audit them — some hosts install marketing plugins nobody asked for.

Want us to audit and thin your plugin stack — safely?

Get a Free Quote

Leave a Reply

Your email address will not be published. Required fields are marked *