How can I have more confidence that WP plugins aren’t getting and storing user data?

GDPR is about data collection, if a theme, plugin or any other software for that matter is not collecting any data especially personal data aka data and/or information that could potentially refer to a natural person than you don’t need to worry about GDPR. If you or the plugin and/or theme aren’t collecting anything than you automatically comply with the law.

For example:

If a page builder is collecting data than it needs to state which data it is collecting and how it handles this. (stores this) and before collecting the plugin needs to ask you permission to collect this. This permission needs to ask for everything the plugin wants to collect.

Another example would be if you’re buying a theme, the developers need your contact information, like your email to send you a license key or something to prove that you have bought the theme, this handling of personal data needs to be documented (how they store the data, how you could file a complain and for how long they store the data)

You have always a right to demand erasure, meaning deleting all the data they got on you.

So again: if you don’t collect any data you don’t need to do something. You need to check which plugins and/or theme is collecting (personal) data. The law is about collecting data, how you handle this (store this) and for how long. And giving people an option of how to contact you for any complaints and/or demands.