WordPress.DB.PreparedSQLPlaceholders.LikeWildcardsInQueryWithPlaceholder
Like Wildcards In Query With Placeholder
A SQL query is built in a way that Plugin Check cannot verify as safely prepared.
Why It Shows Up
The scan found missing, incorrect, quoted, unsupported, or mismatched SQL placeholders around `$wpdb->prepare()` usage.
Why It Matters
Broken preparation can leave dynamic SQL values unsafe or make queries behave differently than intended.
How to Fix
- Keep placeholders in the SQL string and pass dynamic values as separate arguments.
- Use the placeholder that matches the value type.
- Do not quote placeholders manually, and use allowlists for identifiers or SQL fragments.
References
Affected Plugins
| Rank | Plugin | Score | Errors | Warnings | Installs | Added | Updated | Top Issue |
|---|---|---|---|---|---|---|---|---|
| #1 | Go Fetch Jobs (for WP Job Manager) | 19 | 1,410 | 1,741 | 700 | Non-prefixed global variable | ||
| #2 | SendPress Newsletters | 19 | 2,293 | 1,422 | 1k+ | Output is not escaped | ||
| #3 | Pix por Piggly (para Woocommerce) | 20 | 547 | 195 | 4k+ | Exception output is not escaped | ||
| #4 | WPScan – WordPress Security Scanner | 21 | 527 | 265 | 8k+ | Text Domain Mismatch | ||
| #5 | Knowledge Base documentation & wiki plugin – BasePress Docs | 22 | 671 | 1,767 | 2k+ | Non-prefixed global variable | ||
| #6 | DirectoryPress – Business Directory And Classified Ad Listing | 22 | 4,787 | 2,795 | 700 | Text Domain Mismatch | ||
| #7 | Business Directory Plugin – Easy Listing Directories for WordPress | 23 | 611 | 1,064 | 10k+ | Non-prefixed global variable | ||
| #8 | GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress | 23 | 3,594 | 2,775 | 10k+ | Output is not escaped | ||
| #9 | IP Geo Block | 23 | 399 | 589 | 8k+ | Output is not escaped | ||
| #10 | Restaurant Menu and Food Ordering | 23 | 385 | 853 | 2k+ | Non-prefixed global variable | ||
| #11 | Seriously Simple Podcasting | 23 | 548 | 629 | 30k+ | Non-prefixed hook name | ||
| #12 | RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress | 24 | 842 | 3,717 | 500 | Request data is not unslashed | ||
| #13 | Media Library Folders | 24 | 889 | 807 | 10k+ | Text Domain Mismatch | ||
| #14 | Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors | 24 | 369 | 820 | 20k+ | Nonce verification recommended | ||
| #15 | Spotlight Social Feeds – Block, Shortcode, and Widget | 24 | 411 | 147 | 60k+ | Output is not escaped | ||
| #16 | GEO Plugin by Squirrly SEO | 24 | 1,202 | 230 | 30k+ | Missing Translators Comment | ||
| #17 | Online Scheduling and Appointment Booking System – Bookly | 25 | 1,095 | 900 | 60k+ | SQL query is not prepared | ||
| #18 | Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation | 25 | 789 | 313 | 30k+ | Text Domain Mismatch | ||
| #19 | IP Location Block | 25 | 521 | 624 | 10k+ | Output is not escaped | ||
| #20 | Pz-LinkCard | 25 | 949 | 1,614 | 20k+ | Non-prefixed global variable | ||
| #21 | MaxGalleria | 26 | 278 | 560 | 2k+ | Non-prefixed global variable | ||
| #22 | Advanced Shipping Rates for WooCommerce: Flexible Table Rate Shipping Rules | 28 | 187 | 505 | 2k+ | Non-prefixed global variable | ||
| #23 | ووکامرس فارسی | 28 | 157 | 215 | 100k+ | Output is not escaped | ||
| #24 | AppPresser – Mobile App Framework | 29 | 262 | 214 | 1k+ | Text Domain Mismatch | ||
| #25 | WP Inventory Manager | 30 | 869 | 232 | 1k+ | Output is not escaped | ||
| #26 | Keywords to Links Converter | 31 | 288 | 144 | 800 | Text Domain Mismatch | ||
| #27 | Cooked – Recipe Management | 32 | 462 | 275 | 3k+ | Output is not escaped | ||
| #28 | MapPress – Google Maps, OpenStreetMap & Leaflet | 32 | 696 | 129 | 30k+ | Missing Arg Domain | ||
| #29 | Related Posts for WordPress | 35 | 207 | 180 | 10k+ | Output is not escaped | ||
| #30 | REST API Log | 35 | 79 | 124 | 5k+ | Non-prefixed hook name | ||
| #31 | Decent Comments | 38 | 93 | 28 | 2k+ | Output is not escaped | ||
| #32 | Coding Chicken – JetEngine Importer | 38 | 55 | 29 | 400 | Missing direct file access protection | ||
| #33 | Zippy | 40 | 43 | 31 | 9k+ | Output is not escaped | ||
| #34 | Gelato Integration for WooCommerce | 42 | 36 | 32 | 5k+ | Output is not escaped | ||
| #35 | Search by SKU for Woocommerce | 69 | 13 | 10 | 10k+ | Direct Query | ||
| #36 | Vanilla PDF Embed | 85 | 8 | 3 | 3k+ | parse url parse url |