Even if the plugin is old, ensure your underlying JRE is the latest version to patch known exploits.
If you must use Java plugins, use a specific browser solely for those tasks and use a modern, secure browser for your general web surfing. The Bottom Line
The Deployment Toolkit became a frequent target for "drive-by" cyberattacks. Because it had the power to launch executable code, hackers found ways to exploit it to install malware.