Plugins accumulate: an experiment ends and its plugin stays, still receiving advisories. An audit starts with the plugins nothing else depends on, the only ones you can remove alone, then asks whether any job uses them:
J=http://localhost:32080; AUTH="admin:$JENKINS_TOKEN"
curl -sg -u "$AUTH" -o deps.json \
"$J/pluginManager/api/json?depth=2&tree=plugins[shortName,dependencies[shortName]]"
jq -r '[.plugins[].dependencies[].shortName] as $needed | .plugins[].shortName
| select(. as $p | $needed | index($p) | not)' deps.json | sort | paste -sd' ' | fold -sw 90ant build-timeout dark-theme email-ext github-checks gradle ldap matrix-auth pipeline-github-lib pipeline-graph-view ssh-slaves timestamper workflow-aggregator ws-cleanup
A grep for plugin=" across jobs/*/config.xml finds what jobs use; steps inside Pipeline scripts, such as cleanWs(), need a search of the Jenkinsfiles. No job used Ant or Gradle 19,597 , so both went:
for p in ant gradle; do
curl -s -u "$AUTH" -X POST "$J/manage/pluginManager/plugin/$p/doUninstall"; done
curl -s -u "$AUTH" -X POST "$J/safeRestart"; sleep 60
curl -sg -u "$AUTH" "$J/pluginManager/api/json?tree=plugins[shortName]" | jq '.plugins | length'91
Uninstalling deletes the .jpi; settings it wrote stay until Manage Jenkins 8,793 > Manage Old Data purges them. When unsure, disable instead, which keeps the files. Also watch the update center's deprecations (267 on 25 September 2026, none installed here) and low health scores (the lowest here, 80, were dependencies).