WordPress.Security.ValidatedSanitizedInput.MissingUnslash

Request data is not unslashed

Input from a WordPress request superglobal is used before removing WordPress-added slashes.

critical weight

Why It Shows Up

WordPress adds slashes to request data for historical compatibility. The scan found `$_GET`, `$_POST`, `$_REQUEST`, or similar input used without `wp_unslash()`.

Why It Matters

Sanitizing slashed data can produce incorrect values, failed comparisons, broken validation, or stored data that does not match what the user submitted.

How to Fix

  • Read the specific request key, then call `wp_unslash()` on it.
  • Sanitize the unslashed value with a function that matches the expected data type.
  • Validate the sanitized value before using it in permissions, queries, redirects, or stored settings.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#2051WP Sticky Button – Click to Chat40736410k+Non Prefixed Variable Found
#2052Widget Visibility Without Jetpack4074475k+Text Domain Mismatch
#2053Preview E-mails for WooCommerce40353730k+Unsafe Printing Function
#2054Country Based Restrictions for WooCommerce4021655k+Missing Unslash
#2055NP Quote Request for WooCommerce40911459k+Non Prefixed Variable Found
#2056All In One SEO Pack for WooCommerce4057253k+Text Domain Mismatch
#2057Simple Registration for WooCommerce4027554k+Missing
#2058WooSidebars404337100k+Missing Translators Comment
#2059Word Balloon402012510k+Missing Unslash
#2060WP Date and Time Shortcode40901210k+Output Not Escaped
#2061Easy PayPal & Stripe Buy Now Button403889610k+Unsafe Printing Function
#2062WP Help40495410k+Unsafe Printing Function
#2063WP All Import – Job Listing Import for WP Job Manager4035272k+Output Not Escaped
#2064Media Library Categories40294920k+Output Not Escaped
#2065WP Meteor Website Speed Optimization Addon40341920k+Output Not Escaped
#2066WP Paint – WordPress Image Editor4030296k+Missing Arg Domain
#2067QR code MeCard/vCard generator40322212k+Unsafe Printing Function
#2068Sentry for WordPress40804010k+Text Domain Mismatch
#2069Social Share Buttons & Analytics Plugin – GetSocial.io4097252k+Output Not Escaped
#2070WP Tab Widget401283210k+Output Not Escaped
#2071WP Theme Test4021397k+Input Not Sanitized
#2072WPC Estimated Delivery Date for WooCommerce401310610k+Non Prefixed Variable Found
#2073WPC Grouped Product for WooCommerce4019953k+Missing Unslash
#2074WPFront Notification Bar402224450k+Output Not Escaped
#2075My YouTube Channel4054385k+Output Not Escaped
#2076Zippy4043319k+Output Not Escaped
#2077AMP for WP – Accelerated Mobile Pages416562,40180k+Non Prefixed Variable Found
#2078Add-on Contact Form 7 – MailPoet 34188123k+Output Not Escaped
#2079Advanced Excerpt41694380k+Unsafe Printing Function
#2080AH Display Widgets4152169k+Text Domain Mismatch
#2081Schema – All In One Schema Rich Snippets4159818030k+Text Domain Mismatch
#2082Amazon Link Engine4138172k+Output Not Escaped
#2083Amazon Web Services4153215k+Missing Translators Comment
#2084Announcer – Sticky Message Banner & Notification Bar411102710k+Output Not Escaped
#2085Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)4117526100k+Unsafe Printing Function
#2086Avatar Manager4129415k+Unsafe Printing Function
#2087Beautiful Cookie Consent Banner41337640k+Non Prefixed Variable Found
#2088BuddyPress Xprofile Custom Field Types41391894k+Missing
#2089Carbon Copy4164893k+Text Domain Mismatch
#2090Easy Social Like Box – Popup – Sidebar Widget41218917k+Text Domain Mismatch
#2091Conditional Fields for Contact Form 74111352100k+Output Not Escaped
#2092CF7 Invisible reCAPTCHA4119527k+Missing Unslash
#2093Colorful Categories4120202k+Output Not Escaped
#2094Comments Like Dislike41172205k+Non Singular String Literal Domain
#2095Contact Form 7 Captcha41775100k+Missing Unslash
#2096Controlled Admin Access41224010k+Recommended
#2097Dashboard Notepad41293410k+Missing
#2098Database for CF74137322k+Text Domain Mismatch
#2099Debug Bar41642520k+Output Not Escaped
#2100Disable Everything41901630k+Output Not Escaped