| #1 | JetBackup – Backup, Restore & Migrate | 10 | 1,559 | 145 | 100k+ | | Exception output is not escaped |
| #2 | Podlove Podcast Publisher | 18 | 2,326 | 1,429 | 3k+ | | Output is not escaped |
| #3 | Property Hive | 18 | 1,957 | 6,027 | 3k+ | | Missing nonce verification |
| #4 | Shopping Cart & eCommerce Store | 18 | 5,459 | 17,298 | 4k+ | | Non-prefixed global variable |
| #5 | WP Import Export Lite | 18 | 738 | 979 | 40k+ | | Non-prefixed global variable |
| #6 | Block Slider – Responsive Image Slider, Video Slider & Post Slider | 19 | 555 | 1,291 | 3k+ | | Non-prefixed global variable |
| #7 | Download Monitor | 19 | 425 | 1,364 | 80k+ | | Non-prefixed hook name |
| #8 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution | 19 | 1,218 | 901 | 100k+ | | Exception output is not escaped |
| #9 | Matomo Analytics – Powerful, Privacy-First Insights for WordPress | 19 | 1,909 | 878 | 100k+ | | Exception output is not escaped |
| #10 | Razorpay Payment Button Plugin | 19 | 486 | 98 | 2k+ | | Exception output is not escaped |
| #11 | Membership Plugin – Kadence Memberships | 19 | 5,082 | 2,982 | 9k+ | | Text Domain Mismatch |
| #12 | Scrollsequence – Cinematic Scroll Image Animation Plugin | 19 | 878 | 1,528 | 4k+ | | Non-prefixed global variable |
| #13 | BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot | 20 | 508 | 1,406 | 30k+ | | Non-prefixed global variable |
| #14 | DMCA Protection Badge | 20 | 4,425 | 217 | 1k+ | | Output is not escaped |
| #15 | GiveWP – Donation Plugin and Fundraising Platform | 20 | 3,435 | 3,580 | 100k+ | | Output is not escaped |
| #16 | Pix por Piggly (para Woocommerce) | 20 | 547 | 195 | 4k+ | | Exception output is not escaped |
| #17 | Powered Cache – Caching and Optimization for WordPress – Easily Improve PageSpeed & Web Vitals Score | 20 | 147 | 231 | 3k+ | | Exception output is not escaped |
| #18 | Robin Image Optimizer – Unlimited Image Optimization, WebP & AVIF | 20 | 557 | 541 | 100k+ | | Output is not escaped |
| #19 | SpeakOut! Email Petitions | 20 | 850 | 994 | 3k+ | | Missing nonce verification |
| #20 | Razorpay for WooCommerce | 20 | 974 | 855 | 100k+ | | Non-prefixed function |
| #21 | WPJAM Basic | 20 | 328 | 356 | 4k+ | | Output is not escaped |
| #22 | Store Locator WordPress | 21 | 2,372 | 1,572 | 10k+ | | Text Domain Mismatch |
| #23 | Pinpoint Booking System – Version 2 | 21 | 634 | 328 | 3k+ | | Missing direct file access protection |
| #24 | Captcha Them All | 21 | 300 | 323 | 6k+ | | Output is not escaped |
| #25 | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce | 21 | 461 | 614 | 200k+ | | Text Domain Mismatch |
| #26 | Smart Grid-Layout Design for Contact Form 7 | 21 | 1,126 | 734 | 10k+ | | Output is not escaped |
| #27 | Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More | 21 | 2,572 | 1,277 | 1m+ | | Output is not escaped |
| #28 | Envo Extra | 21 | 878 | 600 | 20k+ | | Text Domain Mismatch |
| #29 | FileOrganizer – WordPress File Manager | 21 | 536 | 241 | 200k+ | | unlink unlink |
| #30 | JCH Optimize | 21 | 953 | 133 | 4k+ | | Output is not escaped |
| #31 | MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder | 21 | 1,133 | 3,011 | 2k+ | | Non-prefixed global variable |
| #32 | MotoPress Hotel Booking | 21 | 3,061 | 1,037 | 10k+ | | Text Domain Mismatch |
| #33 | Packeta | 21 | 802 | 333 | 8k+ | | Exception output is not escaped |
| #34 | Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages | 21 | 1,173 | 2,983 | 9k+ | | Non-prefixed global variable |
| #35 | Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | 21 | 1,918 | 5,065 | 10k+ | | Non-prefixed hook name |
| #36 | Razorpay Quick Payments | 21 | 399 | 63 | 3k+ | | Exception output is not escaped |
| #37 | Five Star Restaurant Reservations – WordPress Booking Plugin | 21 | 1,099 | 1,147 | 10k+ | | Output is not escaped |
| #38 | Seamless Donations is Sunset | 21 | 600 | 514 | 2k+ | | Text Domain Mismatch |
| #39 | Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic | 21 | 327 | 181 | 10k+ | | Output is not escaped |
| #40 | Smart Forms – when you need more than just a contact form | 21 | 776 | 574 | 5k+ | | Output is not escaped |
| #41 | Accept Stripe Payments | 21 | 373 | 882 | 20k+ | | Missing nonce verification |
| #42 | Buckaroo Woocommerce Payments Plugin | 21 | 563 | 326 | 2k+ | | Exception output is not escaped |
| #43 | Wise Chat | 21 | 470 | 506 | 5k+ | | Output is not escaped |
| #44 | Paysera Payment Gateway for WooCommerce | 21 | 1,866 | 195 | 7k+ | | Exception output is not escaped |
| #45 | Wordfence Security – Firewall, Malware Scan, and Login Security | 21 | 1,592 | 2,973 | 5m+ | | Output is not escaped |
| #46 | WP-Lister Lite for eBay | 21 | 6,697 | 5,129 | 2k+ | | Output is not escaped |
| #47 | WP phpMyAdmin | 21 | 4,528 | 6,435 | 50k+ | | Missing Arg Domain |
| #48 | wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin | 21 | 1,814 | 1,461 | 70k+ | | Output is not escaped |
| #49 | WPScan – WordPress Security Scanner | 21 | 527 | 265 | 8k+ | | Text Domain Mismatch |
| #50 | Advanced Ads – Ad Manager & AdSense | 22 | 578 | 734 | 100k+ | | Non-prefixed global variable |