WordPress.Security.ValidatedSanitizedInput.InputNotValidated

Input is not validated

Request data is used without checking that it is allowed for the operation.

critical weight

Why It Shows Up

The scan found input from a request superglobal being used without validation such as capability checks, allowlists, type checks, or range checks.

Why It Matters

Sanitization cleans a value, but validation proves the value is acceptable. Missing validation can allow unexpected actions, invalid states, or unsafe query choices.

How to Fix

  • Check that IDs are positive integers, enum-like values are in an allowlist, and URLs or file paths are constrained.
  • Pair state-changing requests with nonce and capability checks.
  • Reject or safely default values that do not pass validation.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#1051Theme My Login3225154960k+Non Prefixed Function Found
#1052Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor32572934k+Post Not In exclude
#1053Unbounce Landing Pages321698610k+Output Not Escaped
#1054Secure Client Portal and Private File Sharing Plugin – User Private Files321835101k+Non Prefixed Variable Found
#1055WebwinkelKeur: Webshop keurmerk & reviews for WordPress32200474k+Echo Found
#1056BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net32593340k+Non Prefixed Variable Found
#1057WP 2-step verification32154651k+Output Not Escaped
#1058WP fail2ban – Advanced Security327515360k+Dynamic Hookname Found
#1059wp-jalali322196610k+Text Domain Mismatch
#1060SEOPress – AI SEO Plugin & On-site SEO32138429300k+Non Prefixed Variable Found
#1061WP-Stats322371262k+Output Not Escaped
#1062Privacy Policy Generator – WPLP Legal Pages322639610k+Non Prefixed Variable Found
#1063Extra Product Options Builder for WooCommerce331011552k+Non Prefixed Hookname Found
#1064Advanced Forms for ACF331692783k+Non Prefixed Hookname Found
#1065Arconix Shortcodes331291074k+Output Not Escaped
#1066Premium Portfolio Features for Phlox theme3320413740k+Output Not Escaped
#1067AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth33332299k+Non Prefixed Variable Found
#1068Ultimate Before After Image Slider & Gallery – BEAF334848730k+Text Domain Mismatch
#1069Five Star Business Profile and Schema332891387k+Output Not Escaped
#1070Nexi XPay334962776k+Text Domain Mismatch
#1071Chartify – WordPress Chart Plugin33764113k+Non Prefixed Variable Found
#1072ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form33572041k+Non Prefixed Variable Found
#1073Civic Cookie Control331,8812192k+Text Domain Mismatch
#1074Clicky Analytics331669210k+Output Not Escaped
#1075Companion Auto Update3315929850k+Direct Query
#1076Companion Sitemap Generator – Simple, Smart, and SEO-Ready33118577k+Missing Translators Comment
#1077Contact Form Plugin33472202k+Non Prefixed Function Found
#1078Cooked – Recipe Management334122713k+Output Not Escaped
#1079Login & Register Customizer – Popup | Slider | Inline | WooCommerce3326523040k+Output Not Escaped
#1080Easy Timer33784501k+Non Prefixed Variable Found
#1081Flipbox – Awesomes Flip Boxes Image Overlay334007,27910k+Input Not Validated
#1082ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More3310128930k+Non Prefixed Variable Found
#1083ImageLinks – Interactive Image Builder with Hotspots33517901k+Text Domain Mismatch
#1084WPZOOM Social Feed Widget & Block3331027860k+Unsafe Printing Function
#1085Intagrate Lite33941524k+date date
#1086IP2Location Redirection331941158k+Output Not Escaped
#1087ITRO Popup Plugin335911356k+Output Not Escaped
#1088jQuery Manager for WordPress3386247k+Output Not Escaped
#1089Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid332741063k+Text Domain Mismatch
#1090LWSCache33471046k+Non Prefixed Variable Found
#1091Forms for Mailchimp by Optin Cat – Grow Your MailChimp List33711332k+missing direct file access protection
#1092MailUp for WordPress – Email and Newsletter Subscription Form332511002k+Text Domain Mismatch
#1093MAS Companies For WP Job Manager33623081k+Non Prefixed Hookname Found
#1094Members – Membership & User Role Editor Plugin33234244300k+Output Not Escaped
#1095Merge + Minify + Refresh3378264k+date date
#1096News Announcement Scroll332372592k+Non Prefixed Variable Found
#1097Payflex Payment Gateway33181611k+Text Domain Mismatch
#1098PeproDev WooCommerce Receipt Uploader33325491k+Non Singular String Literal Domain
#1099PhonePe Payment Solutions337610510k+missing direct file access protection
#1100Pixelgrade Assistant336651412k+Text Domain Mismatch