The right move is a structured audit, not a blanket removal pass.
Start by listing every active plugin across the fleet and categorizing each one: actively maintained with known authorship, actively maintained but with unclear provenance, or unmaintained. For the unclear and unmaintained categories, apply the same disclosure checks you would use for a new plugin. Look for AI disclosure statements, review the plugin’s support thread for unresolved security reports, and verify that the version deployed across your fleet matches what the directory lists as current.
Plugins that fail the check fall into one of three buckets: replace, review further, or accept documented risk. Replacement is the cleanest outcome but not always the fastest. Review further means you have a reasonable expectation the plugin is sound but need more information before deciding. Accepting documented risk means you have reviewed the plugin, identified the gaps, and logged the decision with a plan to revisit it on a defined schedule, not indefinitely.
Fleet audits like this are easier to run and easier to repeat when the plugin inventory is centralized. An agency that has to log into each client site individually to answer the question of what is installed will find fleet audits impractical at any real scale. An agency that can query its full fleet from a single Command Center can run the same audit in a fraction of the time. The new directory standards are a good reason to close that gap if it exists.