WordPress.Security.ValidatedSanitizedInput.InputNotValidatedNotSanitized

Input is not validated or sanitized

Request data is used without both cleanup and an allowability check.

critical weight

Why It Shows Up

The scan found a request value moving into code without sanitization and without validation.

Why It Matters

This combines two common input-handling failures: the value may contain unsafe content, and the code has not proven that the value is acceptable for the operation.

How to Fix

  • Call `wp_unslash()` on request input first.
  • Sanitize for the expected type or format.
  • Validate against allowed values, ranges, capabilities, and nonces before using the value.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#51Post Slider and Post Carousel with Post Vertical Scrolling Widget – A Responsive Post Slider245991,53210k+Non Prefixed Variable Found
#52SEO Engine – Smart SEO with AI, Schema & Redirection for WordPress242363041k+Direct Query
#53Shortcodes Ultimate – Content Elements246561,552400k+Non Prefixed Variable Found
#54ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization2492632210k+Output Not Escaped
#55Ultra Addons for Contact Form 7241,53846060k+Text Domain Mismatch
#56Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin249382,935200k+Non Prefixed Variable Found
#57Video Conferencing with Zoom241,10544010k+Unsafe Printing Function
#58CSS & JavaScript Toolbox2515561710k+Non Prefixed Class Found
#59Smash Balloon Social Post Feed – Simple Social Feeds for WordPress25554982200k+Output Not Escaped
#60Smash Balloon Social Photo Feed – Easy Social Feeds Plugin254491,3001m+Interpolated Not Prepared
#61Bulk Page Generator – LPagery256701,9263k+Non Prefixed Variable Found
#62LWS Optimize – All-in-One Speed Booster & Cache Tools2543076420k+Non Prefixed Variable Found
#63My Calendar – Accessible Event Manager25102,19120k+Non Prefixed Function Found
#64Piotnet Forms251873743k+Output Not Escaped
#65Quiz Maker by AYS255053,01520k+Non Prefixed Variable Found
#66Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator256471,0161k+Output Not Escaped
#67Survey Maker by AYS255662,3976k+Non Prefixed Variable Found
#68Super Page Cache – Cloudflare Cache, Page Speed & Core Web Vitals2513735360k+Input Not Sanitized
#69WP Popups – WordPress Popup builder2544034230k+Output Not Escaped
#70Perfect Images: Regenerate Thumbnails, Image Sizes, WebP & AVIF2515411860k+Non Prefixed Variable Found
#71WP Statistics – Simple, privacy-friendly Google Analytics alternative256102,465600k+Non Prefixed Variable Found
#72WP Super Cache258009891m+Output Not Escaped
#73Database for Contact Form 7, WPforms, Elementor forms2631748960k+Non Prefixed Variable Found
#74Translate WordPress with ConveyThis – AI Multilingual Plugin261592971k+Non Prefixed Variable Found
#75Paytium: Mollie payment forms & donations265065513k+Unsafe Printing Function
#76Rate My Post – Star Rating Plugin by FeedbackWP2722236020k+Output Not Escaped
#77Watu Quiz271,0891,0143k+Output Not Escaped
#78WP Hide & Security Enhancer2712437550k+Input Not Sanitized
#79Countdown, Coming Soon, Maintenance – Countdown & Clock291,73514310k+Non Singular String Literal Domain
#80PhastPress29955210k+Exception Not Escaped
#81Contact Form 7 – PayPal & Stripe Add-on303852338k+Unsafe Printing Function
#82Taboola30891471k+Output Not Escaped
#83FOX – Currency Switcher Professional for WooCommerce302111,02250k+Non Prefixed Variable Found
#84Zoho CRM Lead Magnet301011,0253k+Missing Unslash
#85افزونه پیامک حرفه ای فراز اس ام اس31891802k+wp function not compatible with requires wp
#86Split Test For Elementor32981323k+Non Prefixed Variable Found
#87Stock Sync for WooCommerce323622321k+Text Domain Mismatch
#88Ultimate Before After Image Slider & Gallery – BEAF334888730k+Text Domain Mismatch
#89Clicky Analytics331669210k+Output Not Escaped
#90Lenix Leads Collector3441424210k+Text Domain Mismatch
#91Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers3426186330k+Non Prefixed Variable Found
#92Responsive Filterable Portfolio344411561k+Output Not Escaped
#93Search Engine Insights for Google Search Console341741132k+Output Not Escaped
#94Thumbnail carousel slider342771432k+Output Not Escaped
#95CrowdSec351301192k+Output Not Escaped
#96Full Width Banner Slider Wp352391402k+Output Not Escaped
#97Kaya QR Code Generator351934020k+Non Singular String Literal Domain
#98Keyring352332031k+Output Not Escaped
#99WP Responsive Tabs horizontal vertical and accordion Tabs355982122k+Output Not Escaped
#100Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons353329310k+Non Prefixed Variable Found