| #1 | Themify Builder | 9 | 5,195 | 2,096 | 5k+ | | | Text Domain Mismatch |
| #2 | JetBackup – Backup, Restore & Migrate | 10 | 1,559 | 145 | 100k+ | | | Exception output is not escaped |
| #3 | Shopping Cart & eCommerce Store | 18 | 5,459 | 17,298 | 4k+ | | | Non-prefixed global variable |
| #4 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution | 19 | 1,218 | 901 | 100k+ | | | Exception output is not escaped |
| #5 | Matomo Analytics – Powerful, Privacy-First Insights for WordPress | 19 | 1,909 | 878 | 100k+ | | | Exception output is not escaped |
| #6 | Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization | 19 | 1,293 | 2,679 | 9k+ | | | Output is not escaped |
| #7 | Membership Plugin – Kadence Memberships | 19 | 5,082 | 2,982 | 9k+ | | | Text Domain Mismatch |
| #8 | SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments | 19 | 526 | 1,119 | 90k+ | | | Non-prefixed global variable |
| #9 | Brevo – Email, SMS, Web Push, Chat, and more. | 20 | 460 | 646 | 100k+ | | | Request data is not unslashed |
| #10 | Pix por Piggly (para Woocommerce) | 20 | 547 | 195 | 4k+ | | | Exception output is not escaped |
| #11 | Powered Cache – Caching and Optimization for WordPress – Easily Improve PageSpeed & Web Vitals Score | 20 | 147 | 231 | 3k+ | | | Exception output is not escaped |
| #12 | Robin Image Optimizer – Unlimited Image Optimization, WebP & AVIF | 20 | 557 | 541 | 100k+ | | | Output is not escaped |
| #13 | Razorpay for WooCommerce | 20 | 974 | 855 | 100k+ | | | Non-prefixed function |
| #14 | WPJAM Basic | 20 | 328 | 356 | 4k+ | | | Output is not escaped |
| #15 | Pinpoint Booking System – Version 2 | 21 | 634 | 328 | 3k+ | | | Missing direct file access protection |
| #16 | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce | 21 | 461 | 614 | 200k+ | | | Text Domain Mismatch |
| #17 | Smart Grid-Layout Design for Contact Form 7 | 21 | 1,126 | 734 | 10k+ | | | Output is not escaped |
| #18 | Free Downloads WooCommerce | 21 | 430 | 359 | 4k+ | | | Output is not escaped |
| #19 | Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More | 21 | 2,572 | 1,277 | 1m+ | | | Output is not escaped |
| #20 | MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder | 21 | 1,133 | 3,011 | 2k+ | | | Non-prefixed global variable |
| #21 | Modular DS: Monitor, update, and backup multiple websites | 21 | 161 | 81 | 40k+ | | | Exception output is not escaped |
| #22 | OneLogin SAML SSO | 21 | 508 | 330 | 7k+ | | | wp function not compatible with requires wp |
| #23 | Packeta | 21 | 802 | 333 | 8k+ | | | Exception output is not escaped |
| #24 | Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages | 21 | 1,173 | 2,983 | 9k+ | | | Non-prefixed global variable |
| #25 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | 21 | 696 | 1,483 | 50k+ | | | Nonce verification recommended |
| #26 | Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic | 21 | 327 | 181 | 10k+ | | | Output is not escaped |
| #27 | Smart Forms – when you need more than just a contact form | 21 | 776 | 574 | 5k+ | | | Output is not escaped |
| #28 | Buckaroo Woocommerce Payments Plugin | 21 | 563 | 326 | 2k+ | | | Exception output is not escaped |
| #29 | Paysera Payment Gateway for WooCommerce | 21 | 1,866 | 195 | 7k+ | | | Exception output is not escaped |
| #30 | Pay For Post with WooCommerce | 21 | 960 | 1,474 | 1k+ | | | Non-prefixed global variable |
| #31 | Wordfence Security – Firewall, Malware Scan, and Login Security | 21 | 1,592 | 2,973 | 5m+ | | | Output is not escaped |
| #32 | WP Compress – Instant Performance & Speed Optimization | 21 | 3,349 | 3,218 | 10k+ | | | Non Singular String Literal Domain |
| #33 | WP phpMyAdmin | 21 | 4,528 | 6,435 | 50k+ | | | Missing Arg Domain |
| #34 | wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin | 21 | 1,814 | 1,461 | 70k+ | | | Output is not escaped |
| #35 | WPScan – WordPress Security Scanner | 21 | 527 | 265 | 8k+ | | | Text Domain Mismatch |
| #36 | Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots | 22 | 1,604 | 2,019 | 10k+ | | | Direct Query |
| #37 | Better WordPress Minify | 22 | 412 | 484 | 8k+ | | | Non Singular String Literal Domain |
| #38 | Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer | 22 | 2,858 | 1,270 | 50k+ | | | Text Domain Mismatch |
| #39 | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | 22 | 3,654 | 5,061 | 8k+ | | | Non-prefixed global variable |
| #40 | WP Customer Area | 22 | 3,308 | 941 | 10k+ | | | Text Domain Mismatch |
| #41 | Events Manager – Calendar, Bookings, Tickets, and more! | 22 | 4,722 | 5,621 | 70k+ | | | Output is not escaped |
| #42 | FireBox Popups – Increase Sales and Grow Your Email List | 22 | 153 | 812 | 7k+ | | | Non-prefixed global variable |
| #43 | InfiniteWP Client | 22 | 2,286 | 1,812 | 200k+ | | | Exception output is not escaped |
| #44 | Import WP – Export and Import CSV and XML files to WordPress | 22 | 580 | 330 | 4k+ | | | Exception output is not escaped |
| #45 | Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider | 22 | 207 | 323 | 500k+ | | | Non-prefixed global variable |
| #46 | PagBank / PagSeguro Connect para WooCommerce | 22 | 504 | 743 | 4k+ | | | Non-prefixed global variable |
| #47 | Smart Popup by Supsystic | 22 | 3,172 | 503 | 10k+ | | | Non Singular String Literal Domain |
| #48 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | 22 | 1,581 | 2,326 | 300k+ | | | Non-prefixed global variable |
| #49 | Prime Mover – Migrate WordPress Website & Backups | 22 | 1,326 | 1,600 | 10k+ | | | Non-prefixed global variable |
| #50 | PageSpeed Ninja – Cache, Minify, Defer CSS JavaScript, Critical CSS, Optimize Images, Convert WebP | 22 | 984 | 407 | 5k+ | | | Unsafe printing function |