WordPress.Security.EscapeOutput.OutputNotEscaped

Output is not escaped

Dynamic data is printed to the page without an escaping function for the output context.

critical weight

Why It Shows Up

WordPress Coding Standards detected a variable, option, request value, or function result reaching HTML output without a nearby escaping call.

Why It Matters

Unescaped output can become cross-site scripting when attackers control any part of the value being printed.

How to Fix

  • Use `esc_html()` for plain text, `esc_attr()` for attributes, and `esc_url()` for URLs.
  • Use `wp_kses()` or `wp_kses_post()` when limited HTML is intentionally allowed.
  • Escape as late as possible, right before output, so the selected escaping function matches the final context.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#1601Nobs • Share Buttons35314853k+Output Not Escaped
#1602JWT Auth – WordPress JSON Web Token Authentication3514186k+Output Not Escaped
#1603Kadence for WooCommerce and Elementor3539213k+Output Not Escaped
#1604Kargo Takip35841423k+Missing
#1605Kaya QR Code Generator351934020k+Non Singular String Literal Domain
#1606KBoard 위젯 – 워드프레스 게시판3553323k+Output Not Escaped
#1607Kustom Checkout for WooCommerce358249710k+Dynamic Hookname Found
#1608Lead Call Buttons35113816k+Output Not Escaped
#1609Lead Form Builder & Contact Form354003459k+Output Not Escaped
#1610Less PHP Compiler35163473k+Exception Not Escaped
#1611Login-Logout3510483k+Output Not Escaped
#1612Login Page Styler – Custom WordPress Login Page Customizer & Security351251682k+Missing Arg Domain
#1613Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )352731275k+Output Not Escaped
#1614MapSVG – Vector maps, Image maps, Google Maps3574471k+missing direct file access protection
#1615Mechanic Visitor Counter35240668k+Output Not Escaped
#1616Media Library Downloader3521164k+Output Not Escaped
#1617Restaurant Menu – Food Ordering System – Table Reservation353171868k+Unsafe Printing Function
#1618MetaSlider Gallery – Image Gallery, Lightbox Galleries, Modal Windows351574910k+Output Not Escaped
#1619MotoPress Hotel Booking Styles & Templates35371910k+block api version too low
#1620One Page Express Companion351326510k+Output Not Escaped
#1621ONet Regenerate Thumbnails35190641k+Text Domain Mismatch
#1622Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce351171442k+Output Not Escaped
#1623OPcache Manager35155751k+Output Not Escaped
#1624Order Delivery Date for WooCommerce352,0607310k+wp function not compatible with requires wp
#1625OT Flatsome Vertical Menu351262610k+Text Domain Mismatch
#1626Page Optimize357041200k+Non Singular String Literal Domain
#1627Page Visits Counter – Lite3528355k+Output Not Escaped
#1628Paytm Payment Gateway35921043k+Missing Arg Domain
#1629Paytrail for WooCommerce3528463k+Non Prefixed Variable Found
#1630Perfecty Push Notifications352042134k+Not Prepared
#1631Piwik PRO352233k+Output Not Escaped
#1632Pochipp352710220k+Non Prefixed Variable Found
#1633Poptin – Email Marketing Automation, Newsletter & Exit Pop Ups, Email Popups351733420k+Output Not Escaped
#1634Post Content Shortcodes35205562k+Output Not Escaped
#1635Posts Table with Search & Sort35143333k+Text Domain Mismatch
#1636PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)3565680k+Post Not In exclude
#1637Print, PDF, Email by PrintFriendly352202920k+Unsafe Printing Function
#1638Product Input Fields for WooCommerce3518844k+Non Prefixed Function Found
#1639Min Max Step Quantity Limits Manager for WooCommerce35671583k+Non Prefixed Variable Found
#1640Ninjalytics: Sales Reports & Order Export for WooCommerce and EDD3515306k+Non Prefixed Variable Found
#1641Push Notifications by LaraPush3532764k+Non Prefixed Variable Found
#1642ReactPress – Create React App for WordPress3526433k+Missing Unslash
#1643Real Time Validation for Gravity Forms35185302k+Output Not Escaped
#1644Really Simple Google Tag Manager (GTM)35115154k+Text Domain Mismatch
#1645Recurio – Ultimate Subscription for WooCommerce35413001k+Direct Query
#1646Related Posts by Taxonomy351319710k+Output Not Escaped
#1647Related Posts for WordPress3520718010k+Output Not Escaped
#1648Remove Dashboard Access35162330k+wp function not compatible with requires wp
#1649ReOrder Posts within Categories35392077k+Non Prefixed Variable Found
#1650WP Responsive Tabs horizontal vertical and accordion Tabs355982122k+Output Not Escaped