Generic.PHP.ForbiddenFunctions.Found

PHP Forbidden Functions Found

The plugin uses a PHP or WordPress pattern that coding standards discourage.

medium weight

Why It Shows Up

Plugin Check found a discouraged function, forbidden function, goto, backtick operator, or similar construct.

Why It Matters

Discouraged patterns are often harder to review, less portable across hosts, or easier to misuse securely.

How to Fix

  • Identify why the construct is used and whether WordPress provides a safer API.
  • Replace shell execution, dynamic execution, or broad forbidden functions with constrained WordPress APIs.
  • If a third-party library triggers the warning, isolate and document it.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#1BulletProof Security05,0484,94920k+Output Not Escaped
#2JetBackup – Backup, Restore & Migrate101,559145100k+Exception Not Escaped
#3wpForo Forum174,0332,92220k+Unsafe Printing Function
#4WPtouch – Make your WordPress Website Mobile-Friendly171,46632550k+Text Domain Mismatch
#5Download Monitor194251,36480k+Non Prefixed Hookname Found
#6Event Organiser191,10654420k+Text Domain Mismatch
#7Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution191,218901100k+Exception Not Escaped
#8Matomo Analytics – Powerful, Privacy-First Insights for WordPress191,909878100k+Exception Not Escaped
#9Membership Plugin – Kadence Memberships195,0822,9829k+Text Domain Mismatch
#10Scrollsequence – Cinematic Scroll Image Animation Plugin198781,5284k+Non Prefixed Variable Found
#11BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot205081,40630k+Non Prefixed Variable Found
#12Brizy – Page Builder2058972070k+Output Not Escaped
#13GiveWP – Donation Plugin and Fundraising Platform203,4353,580100k+Output Not Escaped
#14Link Library201,9411,39710k+Unsafe Printing Function
#15Brevo – Email, SMS, Web Push, Chat, and more.20460646100k+Missing Unslash
#16Microthemer Lite – Visual Editor to Customize CSS201,0041,69910k+Non Prefixed Variable Found
#17Pix por Piggly (para Woocommerce)205471954k+Exception Not Escaped
#18Robin Image Optimizer – Unlimited Image Optimization, WebP & AVIF20557541100k+Output Not Escaped
#19Razorpay for WooCommerce20974855100k+Non Prefixed Function Found
#20WPJAM Basic203283564k+Output Not Escaped
#21Backup Migration219811,09380k+Non Prefixed Variable Found
#22CallTrackingMetrics219232863k+Unsafe Printing Function
#23Captcha Them All213003236k+Output Not Escaped
#24Comet Cache2185724520k+Output Not Escaped
#25FileOrganizer – WordPress File Manager21536241200k+unlink unlink
#26Packeta218023338k+Exception Not Escaped
#27User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor216961,48350k+Recommended
#28PublishPress Planner – Editorial Calendar, Marketing Content, Kanban Board216038906k+Output Not Escaped
#29Five Star Restaurant Reservations – WordPress Booking Plugin211,0991,14710k+Output Not Escaped
#30Royal Addons for Elementor – Addons and Templates Kit for Elementor2113,0112,530600k+Text Domain Mismatch
#31Smart Forms – when you need more than just a contact form217765745k+Output Not Escaped
#32Accept Stripe Payments2137388220k+Missing
#33Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools217863,39530k+Non Prefixed Variable Found
#34WP phpMyAdmin214,5286,43550k+Missing Arg Domain
#35wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin211,3541,14070k+Output Not Escaped
#36Frontend Admin by DynamiApps225,9223,20810k+Text Domain Mismatch
#37Advanced Ads – Ad Manager & AdSense22578734100k+Non Prefixed Variable Found
#38Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots221,6042,01910k+Direct Query
#39BuddyPress225839,008100k+Non Prefixed Function Found
#40RegistrationMagic – User Registration Forms Plugin223,6545,0628k+Non Prefixed Variable Found
#41Download Manager222,2901,301100k+Output Not Escaped
#42Dynamic QR Code – generator222382086k+missing direct file access protection
#43E2Pdf – Export Pdf Tool for WordPress221,07583610k+Unsafe Printing Function
#44Events Manager – Calendar, Bookings, Tickets, and more!224,7225,62170k+Output Not Escaped
#45File Manager Pro – Filester22565391100k+Missing Unslash
#46Five Star Restaurant Menu and Food Ordering227526095k+Output Not Escaped
#47FunnelKit Payment Gateway for Stripe WooCommerce2224432120k+Input Not Sanitized
#48GeoDirectory – WP Business Directory Plugin and Classified Listings Directory224,4623,97210k+Output Not Escaped
#49Anti-Malware Security and Brute-Force Firewall22544965100k+Output Not Escaped
#50Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms221,03772220k+Unsafe Printing Function