| #1 | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more | 15 | 32 | 163 | 500k+ | 2026-04-01 | Direct Query |
| #2 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution | 19 | 1,218 | 901 | 100k+ | 2026-06-09 | Exception Not Escaped |
| #3 | Matomo Analytics – Powerful, Privacy-First Insights for WordPress | 19 | 1,909 | 878 | 100k+ | 2026-06-16 | Exception Not Escaped |
| #4 | Microthemer Lite – Visual Editor to Customize CSS | 20 | 1,004 | 1,699 | 10k+ | 2026-04-15 | Non Prefixed Variable Found |
| #5 | Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More | 21 | 2,572 | 1,277 | 1m+ | 2026-05-22 | Output Not Escaped |
| #6 | FileOrganizer – WordPress File Manager | 21 | 536 | 241 | 200k+ | 2026-06-10 | unlink unlink |
| #7 | Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | 21 | 1,918 | 5,065 | 10k+ | 2026-06-02 | Non Prefixed Hookname Found |
| #8 | Captcha by BestWebSoft – Advanced Spam Protection, Math & OCR-Friendly Captcha for Site Forms | 22 | 493 | 295 | 10k+ | 2026-03-26 | Text Domain Mismatch |
| #9 | Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer | 22 | 2,858 | 1,270 | 50k+ | 2026-04-23 | Text Domain Mismatch |
| #10 | File Manager Pro – Filester | 22 | 565 | 391 | 100k+ | 2026-05-23 | Missing Unslash |
| #11 | InfiniteWP Client | 22 | 2,286 | 1,812 | 200k+ | 2026-02-26 | Exception Not Escaped |
| #12 | Prime Mover – Migrate WordPress Website & Backups | 22 | 1,326 | 1,600 | 10k+ | 2026-06-06 | Non Prefixed Variable Found |
| #13 | Simple Job Board | 22 | 634 | 1,355 | 10k+ | 2026-06-04 | Non Prefixed Variable Found |
| #14 | WooCommerce | 22 | 1,355 | 6,129 | 7m+ | 2026-05-27 | Non Prefixed Variable Found |
| #15 | File Manager | 22 | 740 | 520 | 1m+ | 2026-04-21 | Unsafe Printing Function |
| #16 | Wp-Insert | 22 | 267 | 301 | 10k+ | 2023-02-08 | Output Not Escaped |
| #17 | Advanced Contact form 7 DB | 23 | 761 | 1,959 | 70k+ | 2026-04-20 | Non Prefixed Variable Found |
| #18 | NitroPack – Performance, Page Speed & Cache Plugin for Core Web Vitals, CDN & Image Optimization | 23 | 315 | 631 | 100k+ | 2026-06-15 | Output Not Escaped |
| #19 | Strong Testimonials | 23 | 192 | 393 | 90k+ | 2026-05-21 | Recommended |
| #20 | UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP | 23 | 695 | 2,434 | 20k+ | 2026-06-12 | Non Prefixed Hookname Found |
| #21 | WP Migrate Lite – Migration Made Easy | 23 | 368 | 254 | 200k+ | 2026-06-02 | Exception Not Escaped |
| #22 | WP STAGING – WordPress Backup, Restore & Migration | 23 | 1,414 | 1,327 | 100k+ | 2026-05-22 | Non Prefixed Variable Found |
| #23 | Backuply – Backup, Restore, Migrate and Clone | 24 | 704 | 551 | 700k+ | 2026-05-27 | Non Prefixed Variable Found |
| #24 | Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN | 24 | 3,410 | 866 | 70k+ | 2026-05-18 | Text Domain Mismatch |
| #25 | Import and export users and customers | 24 | 1,046 | 356 | 70k+ | 2026-06-18 | Unsafe Printing Function |
| #26 | Stripe Payment Forms by WP Simple Pay – Accept Credit Card Payments + Subscriptions with Stripe | 24 | 634 | 652 | 9k+ | 2026-06-18 | Exception Not Escaped |
| #27 | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | 24 | 2,576 | 2,103 | 100k+ | 2026-06-04 | Output Not Escaped |
| #28 | AdRotate Banner Manager | 25 | 1,365 | 846 | 20k+ | 2026-06-18 | Unsafe Printing Function |
| #29 | All 404 Redirect to Homepage | 25 | 140 | 301 | 200k+ | 2026-04-06 | date date |
| #30 | CSS & JavaScript Toolbox | 25 | 155 | 617 | 10k+ | 2025-10-28 | Non Prefixed Class Found |
| #31 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin | 25 | 960 | 738 | 60k+ | 2026-06-16 | Text Domain Mismatch |
| #32 | WPvivid — Backup, Migration & Staging | 25 | 899 | 1,461 | 900k+ | 2026-06-01 | Non Prefixed Namespace Found |
| #33 | Backup, Restore and Migrate your sites with XCloner | 25 | 238 | 864 | 10k+ | 2026-05-26 | Input Not Sanitized |
| #34 | Translate WordPress – Google Language Translator | 26 | 200 | 317 | 100k+ | 2026-05-21 | Non Prefixed Variable Found |
| #35 | WP Hide & Security Enhancer | 27 | 124 | 375 | 50k+ | 2026-06-08 | Input Not Sanitized |
| #36 | Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress | 28 | 465 | 338 | 30k+ | 2026-05-16 | Text Domain Mismatch |
| #37 | reCaptcha by BestWebSoft | 29 | 474 | 272 | 100k+ | 2026-04-24 | Text Domain Mismatch |
| #38 | SmartCrawl SEO checker, analyzer & optimizer | 30 | 347 | 1,307 | 20k+ | 2026-06-18 | Non Prefixed Variable Found |
| #39 | Titan Anti-spam & Security – Brute Force Protection, 2FA & Spam Filter | 31 | 57 | 196 | 50k+ | 2026-05-19 | Recommended |
| #40 | Elementor Website Builder – more than just a page builder | 34 | 47 | 427 | 10m+ | 2026-06-10 | Non Prefixed Variable Found |
| #41 | One User Avatar | User Profile Picture | 34 | 68 | 190 | 100k+ | 2026-06-01 | Non Prefixed Variable Found |
| #42 | Enlighter – Customizable Syntax Highlighter | 35 | 50 | 10 | 10k+ | 2026-04-13 | Output Not Escaped |
| #43 | String locator | 35 | 52 | 319 | 100k+ | 2025-01-15 | Non Prefixed Variable Found |
| #44 | WP-Paginate | 35 | 37 | 55 | 20k+ | 2026-05-21 | Input Not Validated |
| #45 | Custom PHP Settings | 36 | 153 | 76 | 10k+ | 2025-11-20 | Output Not Escaped |
| #46 | WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin | 36 | 18 | 146 | 4m+ | 2026-04-16 | Direct Query |
| #47 | Multiple Themes | 41 | 112 | 41 | 10k+ | 2025-03-06 | Output Not Escaped |
| #48 | Easy SSL Plugin for SAKURA Rental Server | 62 | 23 | 17 | 50k+ | 2019-11-25 | Input Not Sanitized |
| #49 | OptionTree | 93 | 165 | 2 | 50k+ | 2019-05-19 | Text Domain Mismatch |