| #201 | TranslatePress – Translate Multilingual sites with AI Translation | 25 | 452 | 1,541 | 400k+ | | | Non-prefixed hook name |
| #202 | Spectra Gutenberg Blocks – Website Builder for the Block Editor | 25 | 253 | 3,227 | 1m+ | | | Non-prefixed global variable |
| #203 | Social Media Share Buttons & Social Sharing Icons | 25 | 2,433 | 1,383 | 100k+ | | | Unsafe printing function |
| #204 | Social Share Icons & Social Share Buttons | 25 | 2,365 | 1,357 | 10k+ | | | Output is not escaped |
| #205 | VikBooking Hotel Booking Engine & PMS | 25 | 13,232 | 8,312 | 8k+ | | | Output is not escaped |
| #206 | VikRentCar Car Rental Management System | 25 | 5,537 | 5,048 | 4k+ | | | Non-prefixed global variable |
| #207 | W3 Total Cache | 25 | 617 | 1,345 | 900k+ | | | Non-prefixed global variable |
| #208 | weForms – Easy Drag & Drop Contact Form Builder For WordPress | 25 | 916 | 450 | 10k+ | | | Output is not escaped |
| #209 | Wordfence Login Security | 25 | 248 | 418 | 70k+ | | | Output is not escaped |
| #210 | Super Page Cache – Cloudflare Cache, Page Speed & Core Web Vitals | 25 | 137 | 353 | 60k+ | | | Input is not sanitized |
| #211 | Smush – Image Optimization, Compression, Lazy Load, WebP & CDN | 25 | 252 | 566 | 1m+ | | | Non-prefixed hook name |
| #212 | Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar | 26 | 526 | 263 | 5k+ | | | Output is not escaped |
| #213 | Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty | 26 | 113 | 671 | 400k+ | | | Non-prefixed global variable |
| #214 | ezCache | 26 | 127 | 269 | 10k+ | | | Direct Query |
| #215 | Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager | 26 | 113 | 597 | 90k+ | | | Non-prefixed global variable |
| #216 | Omise Payments | 26 | 358 | 256 | 2k+ | | | Output is not escaped |
| #217 | Virtue/Ascend/Pinnacle Toolkit | 26 | 605 | 300 | 30k+ | | | Output is not escaped |
| #218 | WP Flashy Marketing Automation | 26 | 432 | 186 | 2k+ | | | Text Domain Mismatch |
| #219 | Duplicate Post | 27 | 447 | 274 | 300k+ | | | Unsafe printing function |
| #220 | Gallery – Photo Albums Plugin | 27 | 647 | 252 | 2k+ | | | Output is not escaped |
| #221 | CM Tooltip Glossary | 27 | 611 | 188 | 8k+ | | | Output is not escaped |
| #222 | Ray Enterprise Translation | 27 | 87 | 606 | 8k+ | | | Non-prefixed global variable |
| #223 | picu – Online Photo Proofing Gallery | 27 | 613 | 322 | 2k+ | | | Output is not escaped |
| #224 | Speed Booster Pack ⚡ PageSpeed Optimization Suite | 27 | 108 | 187 | 9k+ | | | Missing Translators Comment |
| #225 | Under Construction, Coming Soon & Maintenance Mode | 27 | 401 | 148 | 10k+ | | | Output is not escaped |
| #226 | VOD Infomaniak | 27 | 797 | 385 | 20k+ | | | Output is not escaped |
| #227 | Watu Quiz | 27 | 1,089 | 1,014 | 3k+ | | | Output is not escaped |
| #228 | WP Hide & Security Enhancer | 27 | 124 | 375 | 50k+ | | | Input is not sanitized |
| #229 | WP Activity Log | 27 | 96 | 230 | 300k+ | | | Nonce verification recommended |
| #230 | گیتلند | درگاه پرداخت هوشمند گیتلند | 28 | 327 | 235 | 2k+ | | | Output is not escaped |
| #231 | Loginfy – Custom Login Page Customizer | 28 | 338 | 398 | 2k+ | | | Output is not escaped |
| #232 | My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) | 28 | 161 | 400 | 100k+ | | | Non-prefixed global variable |
| #233 | Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor | 28 | 291 | 292 | 20k+ | | | Output is not escaped |
| #234 | Dynamic Product Gallery for WooCommerce | 28 | 414 | 303 | 1k+ | | | Output is not escaped |
| #235 | Product Sort and Display for WooCommerce | 28 | 199 | 235 | 2k+ | | | Output is not escaped |
| #236 | DoLogin Security | 29 | 312 | 305 | 7k+ | | | Output is not escaped |
| #237 | Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier ) | 29 | 20 | 825 | 20k+ | | | Non-prefixed namespace |
| #238 | Page View Count | 29 | 108 | 247 | 10k+ | | | Dynamic hook name |
| #239 | Recipe Card Blocks Lite | 29 | 151 | 408 | 10k+ | | | Non-prefixed global variable |
| #240 | Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce | 29 | 148 | 246 | 5k+ | | | Unsafe printing function |
| #241 | WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics | 29 | 118 | 128 | 5k+ | | | Output is not escaped |
| #242 | ApplyOnline – Application Form Builder and Manager | 30 | 354 | 260 | 2k+ | | | Output is not escaped |
| #243 | Buy Me a Coffee – Button and Widget Plugin | 30 | 139 | 140 | 6k+ | | | Output is not escaped |
| #244 | Easy Custom Auto Excerpt | 30 | 84 | 166 | 6k+ | | | Non-prefixed global variable |
| #245 | Formzu WP | 30 | 167 | 163 | 3k+ | | | Text Domain Mismatch |
| #246 | Taboola | 30 | 89 | 147 | 1k+ | | | Output is not escaped |
| #247 | Themify Portfolio Post | 30 | 214 | 102 | 30k+ | | | Text Domain Mismatch |
| #248 | Urvanov Syntax Highlighter | 30 | 221 | 87 | 3k+ | | | Output is not escaped |
| #249 | Widgetize Pages Light | 30 | 145 | 104 | 3k+ | | | Output is not escaped |
| #250 | WCPOS – Point of Sale (POS) plugin for WooCommerce | 30 | 77 | 228 | 5k+ | | | Nonce verification recommended |