| #1 | JetBackup – Backup, Restore & Migrate | 10 | 1,559 | 145 | 100k+ | | Exception output is not escaped |
| #2 | Podlove Podcast Publisher | 18 | 2,326 | 1,429 | 3k+ | | Output is not escaped |
| #3 | Download Monitor | 19 | 425 | 1,364 | 80k+ | | Non-prefixed hook name |
| #4 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution | 19 | 1,218 | 901 | 100k+ | | Exception output is not escaped |
| #5 | Matomo Analytics – Powerful, Privacy-First Insights for WordPress | 19 | 1,909 | 878 | 100k+ | | Exception output is not escaped |
| #6 | Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization | 19 | 1,295 | 2,679 | 9k+ | | Output is not escaped |
| #7 | Razorpay Payment Button Plugin | 19 | 486 | 98 | 2k+ | | Exception output is not escaped |
| #8 | Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) | 19 | 541 | 385 | 3m+ | | Missing Translators Comment |
| #9 | Membership Plugin – Kadence Memberships | 19 | 5,082 | 2,982 | 9k+ | | Text Domain Mismatch |
| #10 | SendPress Newsletters | 19 | 2,293 | 1,422 | 2k+ | | Output is not escaped |
| #11 | WP Email Template | 19 | 342 | 350 | 2k+ | | Exception output is not escaped |
| #12 | DMCA Protection Badge | 20 | 4,425 | 217 | 1k+ | | Output is not escaped |
| #13 | Brevo – Email, SMS, Web Push, Chat, and more. | 20 | 460 | 646 | 100k+ | | Request data is not unslashed |
| #14 | Pix por Piggly (para Woocommerce) | 20 | 547 | 195 | 4k+ | | Exception output is not escaped |
| #15 | Razorpay for WooCommerce | 20 | 974 | 855 | 100k+ | | Non-prefixed function |
| #16 | Backup Migration | 21 | 981 | 1,093 | 80k+ | | Non-prefixed global variable |
| #17 | Pinpoint Booking System – Version 2 | 21 | 634 | 328 | 3k+ | | Missing direct file access protection |
| #18 | Eupago Gateway For Woocommerce | 21 | 612 | 320 | 2k+ | | Output is not escaped |
| #19 | FileOrganizer – WordPress File Manager | 21 | 536 | 241 | 200k+ | | unlink unlink |
| #20 | MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder | 21 | 1,133 | 3,011 | 2k+ | | Non-prefixed global variable |
| #21 | OneLogin SAML SSO | 21 | 508 | 330 | 7k+ | | wp function not compatible with requires wp |
| #22 | Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages | 21 | 1,173 | 2,983 | 9k+ | | Non-prefixed global variable |
| #23 | Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | 21 | 1,918 | 5,065 | 10k+ | | Non-prefixed hook name |
| #24 | Razorpay Quick Payments | 21 | 399 | 63 | 3k+ | | Exception output is not escaped |
| #25 | Five Star Restaurant Reservations – WordPress Booking Plugin | 21 | 1,099 | 1,147 | 10k+ | | Output is not escaped |
| #26 | Rocket Maintenance Mode & Coming Soon Page | 21 | 1,176 | 1,406 | 4k+ | | Non-prefixed global variable |
| #27 | Seamless Donations is Sunset | 21 | 600 | 514 | 2k+ | | Text Domain Mismatch |
| #28 | Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic | 21 | 327 | 181 | 10k+ | | Output is not escaped |
| #29 | Accept Stripe Payments | 21 | 373 | 882 | 20k+ | | Missing nonce verification |
| #30 | Revive Social – Social Media Auto Post and Scheduling Automation Plugin | 21 | 255 | 425 | 20k+ | | Non-prefixed hook name |
| #31 | Buckaroo Woocommerce Payments Plugin | 21 | 563 | 326 | 2k+ | | Exception output is not escaped |
| #32 | Paysera Payment Gateway for WooCommerce | 21 | 1,866 | 195 | 7k+ | | Exception output is not escaped |
| #33 | WP-Lister Lite for eBay | 21 | 6,697 | 5,129 | 2k+ | | Output is not escaped |
| #34 | wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin | 21 | 1,814 | 1,461 | 70k+ | | Output is not escaped |
| #35 | Premium Packages – Sell Digital Products Securely | 21 | 2,765 | 2,444 | 3k+ | | Output is not escaped |
| #36 | Booking for Appointments and Events Calendar – Amelia | 22 | 1,489 | 480 | 90k+ | | Exception output is not escaped |
| #37 | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | 22 | 3,654 | 5,061 | 8k+ | | Non-prefixed global variable |
| #38 | Data Tables Generator by Supsystic | 22 | 156 | 144 | 10k+ | | Exception output is not escaped |
| #39 | Falang multilanguage for WordPress | 22 | 716 | 769 | 1k+ | | Output is not escaped |
| #40 | File Manager Pro – Filester | 22 | 565 | 391 | 100k+ | | Request data is not unslashed |
| #41 | FireBox Popups – Increase Sales and Grow Your Email List | 22 | 153 | 812 | 7k+ | | Non-prefixed global variable |
| #42 | Five Star Restaurant Menu and Food Ordering | 22 | 752 | 609 | 5k+ | | Output is not escaped |
| #43 | FunnelKit Payment Gateway for Stripe WooCommerce | 22 | 244 | 321 | 20k+ | | Input is not sanitized |
| #44 | Anti-Malware Security and Brute-Force Firewall | 22 | 544 | 965 | 100k+ | | Output is not escaped |
| #45 | Számlázz.hu integráció WooCommerce-hez | 22 | 1,169 | 460 | 7k+ | | Text Domain Mismatch |
| #46 | InfiniteWP Client | 22 | 2,286 | 1,812 | 200k+ | | Exception output is not escaped |
| #47 | MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. | 22 | 2,619 | 2,453 | 10k+ | | Output is not escaped |
| #48 | Smart Popup by Supsystic | 22 | 3,172 | 503 | 10k+ | | Non Singular String Literal Domain |
| #49 | Quick Contact Form | 22 | 260 | 623 | 1k+ | | Non-prefixed function |
| #50 | RabbitLoader Cache: Optimize your Website for Speed | 22 | 241 | 163 | 2k+ | | Output is not escaped |