| #101 | MailPoet – Newsletters, Email Marketing, and Automation | 23 | 926 | 710 | 500k+ | | | Exception output is not escaped |
| #102 | MasterStudy LMS WordPress Plugin – for Online Courses and Education | 23 | 1,419 | 4,875 | 10k+ | | | Non-prefixed global variable |
| #103 | Restaurant Menu and Food Ordering | 23 | 385 | 853 | 2k+ | | | Non-prefixed global variable |
| #104 | MStore API – Create Native Android & iOS Apps On The Cloud | 23 | 618 | 764 | 3k+ | | | SQL query is not prepared |
| #105 | MultiParcels Shipping For WooCommerce | 23 | 179 | 356 | 4k+ | | | Request data is not unslashed |
| #106 | MyWorks Sync for WooCommerce & QuickBooks Online | 23 | 2,292 | 9,101 | 5k+ | | | Non-prefixed global variable |
| #107 | Next Active Directory Integration | 23 | 683 | 284 | 2k+ | | | Exception output is not escaped |
| #108 | Postie | 23 | 407 | 261 | 10k+ | | | Output is not escaped |
| #109 | PowerPress Podcasting plugin by Blubrry | 23 | 4,807 | 2,394 | 20k+ | | | Output is not escaped |
| #110 | Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management | 23 | 295 | 298 | 4k+ | | | Non-prefixed global variable |
| #111 | Image Optimizer, Resizer and CDN – Sirv | 23 | 616 | 1,004 | 1k+ | | | Output is not escaped |
| #112 | Trinity Audio – Text to Speech AI audio player to convert content into audio | 23 | 119 | 227 | 2k+ | | | Non-prefixed global variable |
| #113 | Directory Listings WordPress plugin – uListing | 23 | 947 | 1,573 | 1k+ | | | Non-prefixed global variable |
| #114 | W3 Total Cache | 23 | 307 | 678 | 900k+ | | | Non-prefixed global variable |
| #115 | Cart PDF for WooCommerce | 23 | 531 | 172 | 1k+ | | | Exception output is not escaped |
| #116 | Peach Payments Gateway | 23 | 298 | 129 | 1k+ | | | Non Singular String Literal Domain |
| #117 | Billingo Plus integráció WooCommerce-hez | 23 | 1,119 | 507 | 800 | | | Text Domain Mismatch |
| #118 | PostFinance Checkout | 23 | 979 | 214 | 1k+ | | | Text Domain Mismatch |
| #119 | WP Free SSL | 23 | 735 | 1,345 | 1k+ | | | Non-prefixed global variable |
| #120 | Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions | 23 | 1,123 | 1,860 | 9k+ | | | Output is not escaped |
| #121 | پارسی دیت – Parsi Date | 23 | 102 | 289 | 100k+ | | | Non-prefixed hook name |
| #122 | Subscribe Forms – Beautiful Email Forms, Embedded Newsletter Forms & MailChimp Form | 23 | 419 | 542 | 2k+ | | | Non-prefixed global variable |
| #123 | WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel | 23 | 1,119 | 3,516 | 20k+ | | | Interpolated SQL is not prepared |
| #124 | Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress | 23 | 2,317 | 1,714 | 5k+ | | | Output is not escaped |
| #125 | AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress | 24 | 5,230 | 1,464 | 7k+ | | | Output is not escaped |
| #126 | Advanced iFrame | 24 | 887 | 1,120 | 40k+ | | | Non-prefixed global variable |
| #127 | Auto-Install Free SSL – Generate & Install Free SSL Certificates | 24 | 991 | 1,495 | 8k+ | | | Non-prefixed global variable |
| #128 | Backuply – Backup, Restore, Migrate and Clone | 24 | 704 | 551 | 700k+ | | | Non-prefixed global variable |
| #129 | Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) | 24 | 1,837 | 1,063 | 1k+ | | | Text Domain Mismatch |
| #130 | Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces | 24 | 2,248 | 3,338 | 10k+ | | | slow db query meta key |
| #131 | Message Filter for Contact Form 7 | 24 | 1,057 | 1,594 | 1k+ | | | Non-prefixed global variable |
| #132 | Business Essentials for Contact Form 7 | 24 | 674 | 403 | 8k+ | | | Text Domain Mismatch |
| #133 | CleanTalk Anti-Spam. Spam Firewall & Bot protection | 24 | 825 | 1,079 | 200k+ | | | Missing nonce verification |
| #134 | Smart Online Order for Clover | 24 | 1,746 | 1,246 | 1k+ | | | Text Domain Mismatch |
| #135 | CM Pop-Up – Create engaging popups to capture attention and boost interaction | 24 | 466 | 408 | 8k+ | | | Output is not escaped |
| #136 | Complianz – GDPR/CCPA Cookie Consent | 24 | 487 | 403 | 1m+ | | | Missing Arg Domain |
| #137 | Customer Reviews for WooCommerce | 24 | 2,206 | 2,443 | 80k+ | | | Output is not escaped |
| #138 | FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution | 24 | 193 | 747 | 80k+ | | | Direct Query |
| #139 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | 24 | 826 | 1,314 | 600k+ | | | Non-prefixed global variable |
| #140 | Photo Gallery – Responsive Image Galleries by Supsystic | 24 | 240 | 91 | 20k+ | | | Text Domain Mismatch |
| #141 | Simple Calendar – Google Calendar Plugin | 24 | 2,053 | 592 | 50k+ | | | Missing direct file access protection |
| #142 | Generate Images (AI) – Magic Post Thumbnail | 24 | 1,940 | 1,761 | 6k+ | | | Non-prefixed global variable |
| #143 | Mailchimp for WooCommerce | 24 | 523 | 663 | 200k+ | | | Non-prefixed global variable |
| #144 | MxChat – AI Chatbot & Content Generation for WordPress | 24 | 3,157 | 1,385 | 2k+ | | | Text Domain Mismatch |
| #145 | Newsletter Subscription Form – User Subscriptions Form, Capture Email | 24 | 385 | 829 | 1k+ | | | Non-prefixed global variable |
| #146 | Paymob for WooCommerce | 24 | 359 | 288 | 6k+ | | | Text Domain Mismatch |
| #147 | PDF Generator for WordPress Elementor | 24 | 513 | 271 | 1k+ | | | Exception output is not escaped |
| #148 | PixelYourSite – Your smart PIXEL (TAG) & API Manager | 24 | 1,160 | 2,407 | 500k+ | | | Non-prefixed namespace |
| #149 | Pz-LinkCard | 24 | 951 | 1,581 | 20k+ | | | Non-prefixed global variable |
| #150 | Security Plugin, Firewall & Malware Scanner with Auto Removal | 24 | 1,191 | 769 | 30k+ | | | Output is not escaped |