WordPress
Plugin
Plugin is a PHP package that adds behavior to WordPress without changing core or the theme. It lives in wp-content/plugins and runs when activated.
How it is measured
A plugin is a folder or single file whose main PHP file starts with a comment header containing Plugin Name:. Active ones are listed in the active_plugins option, and wp plugin list shows name, status, and version. WordPress loads them on each request, so every active plugin adds PHP execution time.
Query Monitor attributes queries, hooks, and HTTP calls to each plugin, which is the quickest way to see which one costs the most. The Plugins screen also shows available updates and a Site Health check lists inactive plugins.
Worked example
A consultant audits a 22-plugin site that takes 2.4 seconds to generate a product page. Query Monitor shows one slider plugin runs 61 queries on every page, including pages without a slider. Another makes a remote request to its licensing server on every admin load, adding 700 ms.
Replacing the slider with a block cuts 61 queries, and the license check moves to once a day. The page falls to 1.1 seconds, with 18 plugins active.
How it differs
A plugin is optional and can be deactivated from the Plugins screen. A must-use plugin loads without activation and cannot be turned off there. A plugin can add features across any theme, while a theme controls presentation, so a plugin that outputs styling can be lost on a theme switch if it depends on theme CSS.
Common errors
Keeping deactivated plugins on disk with known vulnerabilities. Installing nulled copies of premium plugins. Running two plugins that do the same job. Ignoring update notices for a year. Assuming a plugin is safe because it has many installs, without checking when it was last updated.
In practice
List your plugins with wp plugin list this week. Delete any that are inactive. For each remaining one, note why it is there, and check that it was updated in the last year. Test updates on a staging copy first.