| #301 | Simple Giveaways – Grow your business, email lists and traffic with contests | 25 | 956 | 2,384 | 400 | | | Non-prefixed global variable |
| #302 | HashBar – Announcement, Notification Bar & Popup Campaign | 25 | 2,718 | 610 | 8k+ | | | Text Domain Mismatch |
| #303 | Hydra Booking — Appointment Scheduling & Booking Calendar | 25 | 238 | 707 | 2k+ | | | Non-prefixed global variable |
| #304 | Smash Balloon Social Photo Feed – Easy Social Feeds Plugin | 25 | 449 | 1,300 | 1m+ | | | Interpolated SQL is not prepared |
| #305 | Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more | 25 | 4,019 | 1,265 | 2k+ | | | Text Domain Mismatch |
| #306 | Live Composer – Free WordPress Website Builder | 25 | 1,216 | 427 | 10k+ | | | Output is not escaped |
| #307 | Login Widget With Shortcode | 25 | 335 | 198 | 6k+ | | | wp function not compatible with requires wp |
| #308 | LWS Optimize – All-in-One Speed Booster & Cache Tools | 25 | 430 | 764 | 20k+ | | | Non-prefixed global variable |
| #309 | Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails | 25 | 4,675 | 1,455 | 5k+ | | | Text Domain Mismatch |
| #310 | Create | 25 | 1,558 | 769 | 6k+ | | | Text Domain Mismatch |
| #311 | Nexter Extension – Security, Performance, Code Snippets & Site Toolkit | 25 | 198 | 710 | 10k+ | | | Nonce verification recommended |
| #312 | NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar | 25 | 257 | 400 | 40k+ | | | Non-prefixed hook name |
| #313 | Quttera ThreatSign – Web Malware Scanner for WordPress | 25 | 334 | 471 | 10k+ | | | Non-prefixed global variable |
| #314 | BerqWP – All-In-One Optimization for Core Web Vitals, Cache, CDN, Images, CSS & JavaScript | 25 | 198 | 501 | 3k+ | | | Non-prefixed global variable |
| #315 | Seers Ai | Consent Management Platform (Easy to set up GDPR/CCPA Compliant Cookie Consent) | 25 | 1,446 | 421 | 1k+ | | | Output is not escaped |
| #316 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin | 25 | 960 | 738 | 60k+ | | | Text Domain Mismatch |
| #317 | Simply Static – The Static Site Generator | 25 | 163 | 448 | 30k+ | | | Non-prefixed hook name |
| #318 | Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers | 25 | 348 | 1,481 | 1k+ | | | Nonce verification recommended |
| #319 | Timeline Express | 25 | 531 | 147 | 9k+ | | | Text Domain Mismatch |
| #320 | TranslatePress – Translate Multilingual sites with AI Translation | 25 | 452 | 1,541 | 400k+ | | | Non-prefixed hook name |
| #321 | Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor | 25 | 690 | 1,581 | 50k+ | | | Non-prefixed global variable |
| #322 | Social Media Share Buttons & Social Sharing Icons | 25 | 2,433 | 1,383 | 100k+ | | | Unsafe printing function |
| #323 | Social Share Icons & Social Share Buttons | 25 | 2,365 | 1,357 | 10k+ | | | Output is not escaped |
| #324 | Vayu Blocks – Website Builder for the Gutenberg Block Editor | 25 | 174 | 233 | 1k+ | | | Text Domain Mismatch |
| #325 | VikAppointments Services Booking Calendar | 25 | 9,753 | 5,207 | 500 | | | Output is not escaped |
| #326 | VikBooking Hotel Booking Engine & PMS | 25 | 13,232 | 8,312 | 8k+ | | | Output is not escaped |
| #327 | VikRentCar Car Rental Management System | 25 | 5,537 | 5,048 | 4k+ | | | Non-prefixed global variable |
| #328 | VikRestaurants Table Reservations and Take-Away | 25 | 11,644 | 4,932 | 600 | | | Output is not escaped |
| #329 | weForms – Easy Drag & Drop Contact Form Builder For WordPress | 25 | 916 | 450 | 10k+ | | | Output is not escaped |
| #330 | PDF Builder for WooCommerce. Create invoices,packing slips and more | 25 | 372 | 503 | 2k+ | | | Non-prefixed global variable |
| #331 | Wordfence Login Security | 25 | 248 | 418 | 70k+ | | | Output is not escaped |
| #332 | WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards | 25 | 1,431 | 1,270 | 10k+ | | | Output is not escaped |
| #333 | WPCargo Track & Trace | 25 | 239 | 557 | 10k+ | | | Non-prefixed global variable |
| #334 | Video Gallery – YouTube Gallery, Playlist & Video Grid | 25 | 275 | 1,066 | 2k+ | | | Non-prefixed hook name |
| #335 | Translate WordPress with ConveyThis – AI Multilingual Plugin | 26 | 159 | 297 | 1k+ | | | Non-prefixed global variable |
| #336 | CP Multi View Events Calendar | 26 | 86 | 439 | 1k+ | | | Non-prefixed global variable |
| #337 | WP Frontend Admin – Display WP Admin Pages in the Frontend | 26 | 347 | 337 | 500 | | | Non Singular String Literal Domain |
| #338 | Accept Donations with PayPal & Stripe | 26 | 916 | 572 | 10k+ | | | Unsafe printing function |
| #339 | Event Monster – Event Manager, Ticket Booking & Registration | 26 | 781 | 781 | 700 | | | Non-prefixed global variable |
| #340 | ezCache | 26 | 127 | 269 | 10k+ | | | Direct Query |
| #341 | RSS Redirect & Feedburner Alternative | 26 | 277 | 272 | 1k+ | | | Output is not escaped |
| #342 | MakeStories (for Google Web Stories) | 26 | 117 | 416 | 600 | | | Nonce verification recommended |
| #343 | Hotel Booking | 26 | 690 | 940 | 4k+ | | | Unsafe printing function |
| #344 | Omise Payments | 26 | 358 | 256 | 2k+ | | | Output is not escaped |
| #345 | Online Contact Widget-多合一在线客服插件 | 26 | 708 | 80 | 800 | | | Non Singular String Literal Domain |
| #346 | Organic Builder Widgets – Simple WordPress Page Builder | 26 | 1,034 | 125 | 4k+ | | | Output is not escaped |
| #347 | Crowdsignal Dashboard – Polls, Surveys & more | 26 | 486 | 489 | 200k+ | | | Unsafe printing function |
| #348 | Pressidium Cookie Consent | 26 | 203 | 95 | 10k+ | | | Exception output is not escaped |
| #349 | Virtue/Ascend/Pinnacle Toolkit | 26 | 605 | 300 | 30k+ | | | Output is not escaped |
| #350 | Parcel Pro | 26 | 171 | 220 | 600 | | | Output is not escaped |