| #1 | Intercom | 0 | 60 | 71 | 6k+ | | Non-prefixed function |
| #2 | Themify Builder | 9 | 5,195 | 2,096 | 5k+ | | Text Domain Mismatch |
| #3 | JetBackup – Backup, Restore & Migrate | 10 | 1,559 | 145 | 100k+ | | Exception output is not escaped |
| #4 | Visual Composer Website Builder | 16 | 82 | 320 | 40k+ | | Non-prefixed global variable |
| #5 | wpForo Forum | 17 | 4,033 | 2,922 | 20k+ | | Unsafe printing function |
| #6 | WPtouch – Make your WordPress Website Mobile-Friendly | 17 | 1,466 | 325 | 50k+ | | Text Domain Mismatch |
| #7 | Podlove Podcast Publisher | 18 | 2,326 | 1,429 | 3k+ | | Output is not escaped |
| #8 | Property Hive | 18 | 1,957 | 6,027 | 3k+ | | Missing nonce verification |
| #9 | Shopping Cart & eCommerce Store | 18 | 5,459 | 17,298 | 4k+ | | Non-prefixed global variable |
| #10 | WP Directory Kit | 18 | 2,119 | 2,617 | 2k+ | | Non-prefixed global variable |
| #11 | Element Pack – Widgets, Templates & Addons for Elementor | 19 | 9,448 | 517 | 100k+ | | Text Domain Mismatch |
| #12 | Download Monitor | 19 | 425 | 1,364 | 80k+ | | Non-prefixed hook name |
| #13 | Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) | 19 | 3,275 | 3,228 | 10k+ | | Output is not escaped |
| #14 | Matomo Analytics – Powerful, Privacy-First Insights for WordPress | 19 | 1,909 | 878 | 100k+ | | Exception output is not escaped |
| #15 | Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization | 19 | 1,295 | 2,679 | 9k+ | | Output is not escaped |
| #16 | Realtyna Organic IDX plugin + WPL Real Estate | 19 | 947 | 3,653 | 2k+ | | Non-prefixed global variable |
| #17 | SendPress Newsletters | 19 | 2,293 | 1,422 | 2k+ | | Output is not escaped |
| #18 | Brizy – Page Builder | 20 | 589 | 720 | 70k+ | | Output is not escaped |
| #19 | DMCA Protection Badge | 20 | 4,425 | 217 | 1k+ | | Output is not escaped |
| #20 | GiveWP – Donation Plugin and Fundraising Platform | 20 | 3,435 | 3,580 | 100k+ | | Output is not escaped |
| #21 | Brevo – Email, SMS, Web Push, Chat, and more. | 20 | 460 | 646 | 100k+ | | Request data is not unslashed |
| #22 | Quill Forms | Conversational Multi Step Forms, Surveys & quizzes | 20 | 401 | 368 | 3k+ | | Text Domain Mismatch |
| #23 | Trace My IP – Visitor IP Tracker, Stats Analytics & Page Views Counter with Email Alerts | 20 | 866 | 338 | 1k+ | | wp function not compatible with requires wp |
| #24 | Razorpay for WooCommerce | 20 | 974 | 855 | 100k+ | | Non-prefixed function |
| #25 | WPJAM Basic | 20 | 328 | 356 | 4k+ | | Output is not escaped |
| #26 | Backup Migration | 21 | 981 | 1,093 | 80k+ | | Non-prefixed global variable |
| #27 | CallTrackingMetrics | 21 | 923 | 286 | 3k+ | | Unsafe printing function |
| #28 | Captcha Them All | 21 | 300 | 323 | 6k+ | | Output is not escaped |
| #29 | Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More | 21 | 2,572 | 1,277 | 1m+ | | Output is not escaped |
| #30 | Eupago Gateway For Woocommerce | 21 | 612 | 320 | 2k+ | | Output is not escaped |
| #31 | EventPrime – Events Calendar, Bookings and Tickets | 21 | 872 | 4,297 | 7k+ | | Non-prefixed global variable |
| #32 | Feeds for YouTube (YouTube video, channel, and gallery plugin) | 21 | 558 | 978 | 100k+ | | Output is not escaped |
| #33 | Campaign Monitor for WordPress | 21 | 386 | 461 | 2k+ | | Non-prefixed global variable |
| #34 | If-So Dynamic Content – Elementor & All Page Builders Personalization | 21 | 889 | 725 | 7k+ | | Unsafe printing function |
| #35 | LA-Studio Element Kit for Elementor | 21 | 8,390 | 1,964 | 10k+ | | Text Domain Mismatch |
| #36 | MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder | 21 | 1,133 | 3,011 | 2k+ | | Non-prefixed global variable |
| #37 | Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred | 21 | 1,469 | 3,333 | 10k+ | | Non-prefixed global variable |
| #38 | Packeta | 21 | 802 | 333 | 8k+ | | Exception output is not escaped |
| #39 | Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages | 21 | 1,173 | 2,983 | 9k+ | | Non-prefixed global variable |
| #40 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | 21 | 696 | 1,483 | 50k+ | | Nonce verification recommended |
| #41 | Rocket Maintenance Mode & Coming Soon Page | 21 | 1,176 | 1,406 | 4k+ | | Non-prefixed global variable |
| #42 | Seamless Donations is Sunset | 21 | 600 | 514 | 2k+ | | Text Domain Mismatch |
| #43 | Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic | 21 | 327 | 181 | 10k+ | | Output is not escaped |
| #44 | Accept Stripe Payments | 21 | 373 | 882 | 20k+ | | Missing nonce verification |
| #45 | WCFM – Frontend Manager for WooCommerce | 21 | 4,721 | 5,067 | 20k+ | | Non-prefixed global variable |
| #46 | Wordfence Security – Firewall, Malware Scan, and Login Security | 21 | 1,592 | 2,973 | 5m+ | | Output is not escaped |
| #47 | WP-Lister Lite for eBay | 21 | 6,697 | 5,129 | 2k+ | | Output is not escaped |
| #48 | WP phpMyAdmin | 21 | 4,528 | 6,435 | 50k+ | | Missing Arg Domain |
| #49 | wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin | 21 | 1,814 | 1,461 | 70k+ | | Output is not escaped |
| #50 | Premium Packages – Sell Digital Products Securely | 21 | 2,765 | 2,444 | 3k+ | | Output is not escaped |