WordPress.Security.NonceVerification.Recommended

Nonce verification recommended

The code reads request data in a place where Plugin Check recommends a nonce check.

critical weight

Why It Shows Up

The scan saw request handling that may not always mutate state, but still looks like a user-triggered action that should usually be protected by a nonce.

Why It Matters

Adding a nonce reduces accidental or forged requests and documents that the action is expected to originate from the plugin UI.

How to Fix

  • For admin forms and action links, add and verify a nonce.
  • For AJAX handlers, use `check_ajax_referer()`.
  • For public read-only endpoints, document why a nonce is not required and keep input validation strict.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#3351Lazy Load Optimizer4163263k+Unsafe printing function
#3352Lockdown WP Admin41205010k+Request data is not unslashed
#3353Log cleaner for Solid Security4165478k+Text Domain Mismatch
#3354Media Grid4142442k+Missing Arg Domain
#3355Mobile Contact Bar41943610k+Unsafe printing function
#3356Mollie Forms41145653k+Request data is not unslashed
#3357MouseWheel Smooth Scroll411047100k+Text Domain Mismatch
#3358My Wp Brand – Hide menu & Hide Plugin4174502k+Non Singular String Literal Domain
#3359Social Login4181105k+Input is not sanitized
#3360Live Chat & AI Chatbot – onWebChat413085700error log error log
#3361Optimus – WordPress Image Optimizer41522030k+Unsafe printing function
#3362Passwordless Login4140241k+Output is not escaped
#3363Personalize Login414784500Nonce verification recommended
#3364Pods – Custom Content Types and Fields415233100k+Direct Query
#3365Ally – Web Accessibility & Usability414735500k+Output is not escaped
#3366Smart Post – Post Grid, Post Carousel, Post Slider Gutenberg Blocks for Blog & News4153720k+Non-prefixed global variable
#3367Post Cloner4125151k+Text Domain Mismatch
#3368Posts 2 Posts41427310k+Non Singular String Literal Domain
#3369Product Expiry for WooCommerce4131852k+Request data is not unslashed
#3370Simple Product Options for WooCommerce4162413k+Output is not escaped
#3371Variation Swatches for WooCommerce41291269k+Missing nonce verification
#3372Read More Without Refresh41260720k+Text Domain Mismatch
#3373Recurring PayPal Donations414847800Text Domain Mismatch
#3374Responsive Gallery Grid4174144k+Output is not escaped
#3375Responsive Lightbox41681010k+Output is not escaped
#3376Revision Control41602840k+Output is not escaped
#3377Revisionize4154244k+Output is not escaped
#3378Send link to friend418147400Output is not escaped
#3379Share a Draft413963k+Output is not escaped
#3380ShinyStat Analytics4188251k+Output is not escaped
#3381Simple 301 Redirects By BetterLinks – Easy WordPress Redirect Manager for Redirects, 404 Error Log & More414361100k+Request data is not unslashed
#3382Simple Cache4133591k+Input is not sanitized
#3383Simple CPT41280604k+Unsafe printing function
#3384Simple Like Page – Fast & Privacy-Friendly Page Embeds411453110k+Output is not escaped
#3385Simple Lightbox412148100k+Nonce verification recommended
#3386Simple Page Access Restriction4166516k+Unsafe printing function
#3387Simple Revision Control4134431k+Dynamic hook name
#3388SiteSEO – SEO Simplified4120110500k+Nonce verification recommended
#3389Smoove connector for Elementor forms412260600Nonce verification recommended
#3390SnapScan Payment Gateway413330700Output is not escaped
#3391Squeeze – Image Optimization & Compression, WEBP Conversion4120702k+Nonce verification recommended
#3392StifLi Flex MCP – MCP Server with undo for ChatGPT, Claude & Gemini4121111k+Interpolated SQL is not prepared
#3393tarteaucitron.io41449210k+Output is not escaped
#3394Taxonomy Converter415424600Output is not escaped
#3395Taxonomy Filter4114340800Output is not escaped
#3396Feedback Company416336800Output is not escaped
#3397Theme Blvd Importer412558500Missing nonce verification
#3398Theme Duplicator411431500Nonce verification recommended
#3399Unbloater4157185k+Output is not escaped
#3400Usersnap413717500Output is not escaped