WordPress.DB.PreparedSQL.NotPrepared
SQL query is not prepared
A database query includes dynamic data without using `$wpdb->prepare()` or an equivalent safe pattern.
Why It Shows Up
The scan found a SQL string passed to `$wpdb` where variables appear to be interpolated or concatenated directly.
Why It Matters
Unprepared SQL can allow SQL injection when user-controlled values reach the query.
How to Fix
- Move dynamic values into placeholders such as `%s`, `%d`, `%f`, or `%i` where supported.
- Pass the values as separate arguments to `$wpdb->prepare()`.
- For table names, column names, and sort directions, use strict allowlists instead of raw user input.
References
Affected Plugins
| Rank | Plugin | Score | Errors | Warnings | Installs | Added | Updated | Top Issue |
|---|---|---|---|---|---|---|---|---|
| #1651 | Bulk Delete Comments | 41 | 15 | 61 | 5k+ | Direct Query | ||
| #1652 | Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) | 41 | 16 | 37 | 900 | Missing nonce verification | ||
| #1653 | Collapsed Archives | 41 | 54 | 4 | 1k+ | Output is not escaped | ||
| #1654 | Maspik – Multi-Layer Spam Protection | 41 | 8 | 115 | 30k+ | Missing nonce verification | ||
| #1655 | Custom Post Type Cleanup | 41 | 70 | 12 | 1k+ | Output is not escaped | ||
| #1656 | Duplicate Post Page Menu & Custom Post Type | 41 | 35 | 11 | 10k+ | Text Domain Mismatch | ||
| #1657 | Duplicate Page and Post | 41 | 26 | 21 | 70k+ | Unsafe printing function | ||
| #1658 | SNORDIAN's H5PxAPIkatchu | 41 | 119 | 88 | 500 | SQL query is not prepared | ||
| #1659 | Log cleaner for Solid Security | 41 | 65 | 47 | 8k+ | Text Domain Mismatch | ||
| #1660 | Most Popular Categories | 41 | 67 | 2 | 600 | Output is not escaped | ||
| #1661 | Omnibus — show the lowest price | 41 | 35 | 37 | 10k+ | Output is not escaped | ||
| #1662 | Optimus – WordPress Image Optimizer | 41 | 52 | 20 | 30k+ | Unsafe printing function | ||
| #1663 | Page & Post Notes | 41 | 12 | 77 | 1k+ | Non-prefixed global variable | ||
| #1664 | Plugin Activation Tracker | 41 | 36 | 24 | 1k+ | Text Domain Mismatch | ||
| #1665 | Product Expiry for WooCommerce | 41 | 33 | 89 | 2k+ | Request data is not unslashed | ||
| #1666 | Simple Google Photos Grid | 41 | 48 | 2 | 1k+ | Output is not escaped | ||
| #1667 | Simple Lightbox | 41 | 21 | 48 | 100k+ | Nonce verification recommended | ||
| #1668 | Simple Revision Control | 41 | 22 | 42 | 1k+ | Dynamic hook name | ||
| #1669 | SQL Chart Builder | 41 | 38 | 52 | 500 | Text Domain Mismatch | ||
| #1670 | StifLi Flex MCP – MCP Server with undo for ChatGPT, Claude & Gemini | 41 | 2 | 116 | 1k+ | Interpolated SQL is not prepared | ||
| #1671 | Feedback Company | 41 | 63 | 36 | 800 | Output is not escaped | ||
| #1672 | Threat Scan Plugin | 41 | 29 | 17 | 400 | Output is not escaped | ||
| #1673 | Visibility Logic for Elementor | 41 | 27 | 43 | 30k+ | Output is not escaped | ||
| #1674 | WC Price History | 41 | 18 | 24 | 4k+ | Database parameter is not escaped | ||
| #1675 | M-Pesa(Kenya) Checkout for Woocommerce | 41 | 46 | 38 | 1k+ | Text Domain Mismatch | ||
| #1676 | WP Lorem ipsum | 41 | 37 | 29 | 500 | Unsafe printing function | ||
| #1677 | WP Media folders | 41 | 19 | 74 | 3k+ | Direct Query | ||
| #1678 | WP Test Email | 41 | 32 | 28 | 20k+ | Unsafe printing function | ||
| #1679 | WPC Smart Price Filter for WooCommerce | 41 | 19 | 53 | 600 | Nonce verification recommended | ||
| #1680 | Contador de Visitas | 42 | 37 | 25 | 500 | SQL query is not prepared | ||
| #1681 | Custom Admin Page by BestWebSoft – Configurable WordPress Dashboard Pages Plugin | 42 | 472 | 181 | 400 | Text Domain Mismatch | ||
| #1682 | Custom Fields for Gutenberg | 42 | 24 | 24 | 1k+ | Output is not escaped | ||
| #1683 | Link Manager – Analyze, Automate, and Monitor Links | 42 | 31 | 67 | 1k+ | Direct Query | ||
| #1684 | Delete Expired Transients | 42 | 49 | 65 | 5k+ | Direct Query | ||
| #1685 | Exclude Pages | 42 | 31 | 14 | 20k+ | Non Singular String Literal Domain | ||
| #1686 | Geo Blocker – Control Site Access by Region and IP | 42 | 10 | 64 | 1k+ | Direct Query | ||
| #1687 | Hide Cart Functions | 42 | 12 | 50 | 3k+ | Nonce verification recommended | ||
| #1688 | LeadSnap | 42 | 14 | 84 | 1k+ | Input is not validated | ||
| #1689 | Manage User Columns | 42 | 15 | 27 | 1k+ | Request data is not unslashed | ||
| #1690 | Mass Delete Unused Tags | 42 | 21 | 9 | 800 | Output is not escaped | ||
| #1691 | Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers | 42 | 171 | 501 | 20k+ | SQL query is not prepared | ||
| #1692 | Republish Old Posts | 42 | 83 | 24 | 2k+ | Output is not escaped | ||
| #1693 | Sendcloud Shipping | 42 | 78 | 56 | 5k+ | Output is not escaped | ||
| #1694 | Set All First Images As Featured | 42 | 44 | 13 | 600 | Text Domain Mismatch | ||
| #1695 | Speed Contact Bar | 42 | 53 | 20 | 4k+ | Output is not escaped | ||
| #1696 | Transients Manager | 42 | 45 | 50 | 20k+ | Output is not escaped | ||
| #1697 | Auto Coupons for WooCommerce | 42 | 82 | 68 | 3k+ | Output is not escaped | ||
| #1698 | Ultimate Gift Cards for WooCommerce | 42 | 10 | 453 | 7k+ | Non-prefixed global variable | ||
| #1699 | WP Author Security | 42 | 40 | 13 | 400 | Output is not escaped | ||
| #1700 | WP Fingerprint | 42 | 34 | 47 | 9k+ | Direct Query |