WordPress.Security.ValidatedSanitizedInput.InputNotSanitized

Input is not sanitized

Request data is used without being cleaned for the expected type or format.

critical weight

Why It Shows Up

The scan found superglobal input flowing into code without a sanitizer such as `sanitize_text_field()`, `absint()`, `sanitize_key()`, `esc_url_raw()`, or a custom allowlist.

Why It Matters

Unsanitized input can pollute stored settings, alter logic, break queries, or become part of a later security issue.

How to Fix

  • Unslash request data with `wp_unslash()` first.
  • Choose the sanitizer for the expected value, such as `absint()` for IDs or `sanitize_key()` for keys.
  • Use allowlists for actions, sort fields, file names, option names, and other constrained values.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#2101AfterSalesPro Plugin3524111400Nonce verification recommended
#2102AMIMOTO Plugin Dashboard358282900Non Singular String Literal Domain
#2103Amministrazione Trasparente3580461k+Output is not escaped
#2104Antideo Email Validator353898800Missing nonce verification
#2105Tuskcode Map Pro for Bing Maps3559359600Direct Query
#2106AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker)35165377k+Missing Arg Domain
#2107Aquila Admin Theme351513293k+Non-prefixed global variable
#2108Author Box WP Lens3516949900Unsafe printing function
#2109Authors Widget35170191k+Output is not escaped
#2110Automatic Internal Links for SEO by Pagup35301661k+error log error log
#2111Avif Express3526167400Input is not validated
#2112Awin – Advertiser Tracking for WooCommerce3546391k+Non Singular String Literal Domain
#2113Basic Google Maps Placemarks35189803k+Output is not escaped
#2114Before After Image Comparison Slider for WPBakery Page Builder3558591k+Output is not escaped
#2115belingoGeo351361331k+Output is not escaped
#2116Better Recent Comments35127292k+Text Domain Mismatch
#2117Bicycles by falbar3542665600Output is not escaped
#2118Lord of the Files: Enhanced Upload Security3562421k+Non-prefixed global variable
#2119Block Comment Spam Bots353117800Output is not escaped
#2120Gutenberg Block Editor Toolkit – EditorsKit35612520k+Text Domain Mismatch
#2121Block User Account352801431k+Unsafe printing function
#2122Blogsqode – Blog Layouts and News Post Design3543063400Text Domain Mismatch
#2123BlossomThemes Toolkit353475230k+Output is not escaped
#2124Bluehost Site Migrator3511184k+Missing direct file access protection
#2125Tooltipy (tooltips for WP)353701251k+Text Domain Mismatch
#2126Bootstrap for Contact Form 735357310k+Nonce verification recommended
#2127BORICA Payments by BORICA AD35537196500Text Domain Mismatch
#2128BuddyPress Activity Filter352566400Nonce verification recommended
#2129Custom Order Status Manager for WooCommerce356306730k+Text Domain Mismatch
#2130Registration Options for BuddyPress35471321k+Non-prefixed function
#2131Brightcove Video Connect35580235600Text Domain Mismatch
#2132Brozzme DB Prefix & Tools Addons35244210k+Request data is not unslashed
#2133BSK Forms Blacklist358315501k+Output is not escaped
#2134BTCPay Server – Accept Bitcoin payments in WooCommerce3548861k+Missing nonce verification
#2135Buying Buddy IDX CRM – Real Estate MLS Plugin3571240500Request data is not unslashed
#2136C3 Cloudfront Cache Controller35109603k+Non Singular String Literal Domain
#2137Cache Enabler35447590k+Input is not sanitized
#2138CatFolders – WordPress Media Library Folders & Categories3535766k+Direct Query
#2139CF7 Spreadsheets3510062400Text Domain Mismatch
#2140CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more35161192k+Non-prefixed global variable
#2141Popup for CF7 with Sweet Alert3526122k+Text Domain Mismatch
#2142CF7 Views – Complete Entry Management for Contact Form 7351721811k+Output is not escaped
#2143Change Quantity on Checkout for WooCommerce35270324k+wp function not compatible with requires wp
#2144Change Username357104k+Direct Query
#2145ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form35311881k+Non-prefixed global variable
#2146Payment Gateway Based Fees and Discounts for WooCommerce35246830k+Non-prefixed hook name
#2147CHP Ads Block Detector3510835900Output is not escaped
#2148Cloudflare352885200k+Non-prefixed namespace
#2149Flexible SSL for CloudFlare3596100k+Output is not escaped
#2150CM E-Mail Blacklist – Simple email filtering for safer registration35269205800Output is not escaped