WordPress.DB.PreparedSQLPlaceholders.UnsupportedIdentifierPlaceholder
Unsupported Identifier Placeholder
A SQL query is built in a way that Plugin Check cannot verify as safely prepared.
Why It Shows Up
The scan found missing, incorrect, quoted, unsupported, or mismatched SQL placeholders around `$wpdb->prepare()` usage.
Why It Matters
Broken preparation can leave dynamic SQL values unsafe or make queries behave differently than intended.
How to Fix
- Keep placeholders in the SQL string and pass dynamic values as separate arguments.
- Use the placeholder that matches the value type.
- Do not quote placeholders manually, and use allowlists for identifiers or SQL fragments.
References
Affected Plugins
| Rank | Plugin | Score | Errors | Warnings | Installs | Added | Updated | Top Issue |
|---|---|---|---|---|---|---|---|---|
| #51 | Geo Blocker – Control Site Access by Region and IP | 42 | 10 | 64 | 1k+ | Direct Query | ||
| #52 | hCaptcha for WP | 42 | 115 | 18 | 70k+ | Exception output is not escaped | ||
| #53 | User Role Editor | 43 | 117 | 145 | 700k+ | Output is not escaped | ||
| #54 | WP Mail Log | 43 | 40 | 29 | 10k+ | Text Domain Mismatch | ||
| #55 | wp-Monalisa | 48 | 56 | 94 | 700 | Direct Query | ||
| #56 | Subscriptions for WooCommerce with Stripe Recurring Payments | 56 | 9 | 467 | 900 | Non-prefixed global variable | ||
| #57 | Social Media Auto Poster – Schedule & Publish to Buffer | 58 | 23 | 211 | 7k+ | Dynamic hook name | ||
| #58 | Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages | 62 | 81 | 104 | 40k+ | Missing direct file access protection | ||
| #59 | Sublium Subscriptions – Subscriptions for WooCommerce – Recurring Payments, Subscription Plans & Installments | 74 | 35 | 22 | 500 | wp function not compatible with requires wp | ||
| #60 | Interlinks Manager – Internal Links Optimizer | 80 | 17 | 13 | 7k+ | Database parameter is not escaped |