| #51 | Post to Google My Business (Google Business Profile) | 23 | 845 | 1,452 | 10k+ | | | Non-prefixed global variable |
| #52 | Postie | 23 | 407 | 261 | 10k+ | | | Output is not escaped |
| #53 | UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP | 23 | 695 | 2,434 | 20k+ | | | Non-prefixed hook name |
| #54 | Advanced Booking & Appointment System – Webba Booking Calendar | 23 | 1,615 | 3,300 | 2k+ | | | Non-prefixed global variable |
| #55 | WP STAGING – WordPress Backup, Migration, Clone & Duplicate | 23 | 1,489 | 1,549 | 100k+ | | | Non-prefixed global variable |
| #56 | 404 Solution | 24 | 479 | 1,333 | 10k+ | | | Non-prefixed class |
| #57 | TermsFeed AutoTerms: Privacy Policy Generator, Cookie Consent, GDPR, CCPA, Terms & Conditions, Disclaimers, Cookies Policy, EULA | 24 | 939 | 161 | 80k+ | | | Non Singular String Literal Domain |
| #58 | Message Filter for Contact Form 7 | 24 | 1,057 | 1,594 | 1k+ | | | Non-prefixed global variable |
| #59 | FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution | 24 | 193 | 747 | 80k+ | | | Direct Query |
| #60 | Mailjet Email Marketing | 24 | 435 | 206 | 10k+ | | | Unsafe printing function |
| #61 | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | 24 | 406 | 2,581 | 40k+ | | | Non-prefixed hook name |
| #62 | Timber | 24 | 85 | 128 | 20k+ | | | Non-prefixed hook name |
| #63 | User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder | 24 | 664 | 3,318 | 60k+ | | | Non-prefixed global variable |
| #64 | XT Floating Cart for WooCommerce | 24 | 1,249 | 2,023 | 4k+ | | | Non-prefixed global variable |
| #65 | Fluid Checkout for WooCommerce – Lite | 25 | 370 | 841 | 20k+ | | | Non-prefixed hook name |
| #66 | Gallery Images Ape | 25 | 588 | 341 | 1k+ | | | Output is not escaped |
| #67 | Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more | 25 | 4,010 | 1,262 | 2k+ | | | Text Domain Mismatch |
| #68 | NOWPayments for WooCommerce – Crypto Payment Gateway | 25 | 534 | 1,306 | 4k+ | | | Non-prefixed global variable |
| #69 | Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content | 25 | 680 | 1,513 | 300k+ | | | Non-prefixed global variable |
| #70 | Timeline Express | 25 | 531 | 147 | 9k+ | | | Text Domain Mismatch |
| #71 | weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot | 25 | 279 | 518 | 4k+ | | | Non-prefixed global variable |
| #72 | weForms – Easy Drag & Drop Contact Form Builder For WordPress | 25 | 916 | 450 | 10k+ | | | Output is not escaped |
| #73 | SlimStat Analytics | 25 | 1,177 | 870 | 70k+ | | | Exception output is not escaped |
| #74 | Ray Enterprise Translation | 27 | 87 | 606 | 8k+ | | | Non-prefixed global variable |
| #75 | Login Security Solution | 27 | 216 | 154 | 4k+ | | | Output is not escaped |
| #76 | MLSImport – Download and synchronize real estate data from various MLS (Multiple Listing Services) | 27 | 154 | 551 | 5k+ | | | Non-prefixed global variable |
| #77 | PublishPress Permissions: Control User Access for Posts, Pages, Categories, Tags | 27 | 424 | 323 | 10k+ | | | Missing Translators Comment |
| #78 | WP Events Manager | 27 | 294 | 415 | 30k+ | | | Output is not escaped |
| #79 | Redis Object Cache | 28 | 151 | 103 | 400k+ | | | Exception output is not escaped |
| #80 | Connect Matomo – Analytics Dashboard for WordPress | 28 | 100 | 102 | 60k+ | | | Missing Translators Comment |
| #81 | Product Carousel Slider & Grid Ultimate for WooCommerce | 29 | 719 | 122 | 6k+ | | | Text Domain Mismatch |
| #82 | Mailrelay | 30 | 318 | 170 | 1k+ | | | Text Domain Mismatch |
| #83 | User Access Manager | 30 | 393 | 171 | 10k+ | | | Output is not escaped |
| #84 | CleverReach® WP | 31 | 103 | 93 | 4k+ | | | Non-prefixed global variable |
| #85 | My Private Site | 31 | 425 | 190 | 20k+ | | | Text Domain Mismatch |
| #86 | Mailgun for WordPress | 31 | 144 | 78 | 80k+ | | | Unsafe printing function |
| #87 | reCAPTCHA in WP comments form | 31 | 264 | 60 | 8k+ | | | Output is not escaped |
| #88 | WPGatsby | 31 | 125 | 55 | 3k+ | | | Text Domain Mismatch |
| #89 | OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. | 32 | 211 | 64 | 300k+ | | | Output is not escaped |
| #90 | WP Mobile Menu – The Mobile-Friendly Responsive Menu | 32 | 990 | 195 | 80k+ | | | Output is not escaped |
| #91 | jQuery Manager for WordPress | 33 | 86 | 24 | 7k+ | | | Output is not escaped |
| #92 | Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid | 33 | 274 | 106 | 3k+ | | | Text Domain Mismatch |
| #93 | Mollie Payments for WooCommerce | 33 | 70 | 123 | 100k+ | | | Dynamic hook name |
| #94 | GDPR CCPA Compliance & Cookie Consent Banner | 33 | 622 | 87 | 1k+ | | | Non Singular String Literal Domain |
| #95 | PostNL for WooCommerce | 33 | 598 | 108 | 3k+ | | | Text Domain Mismatch |
| #96 | affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display | 34 | 326 | 75 | 2k+ | | | Output is not escaped |
| #97 | JS Archive List | 34 | 99 | 31 | 3k+ | | | Output is not escaped |
| #98 | ACF Content Analysis for Yoast SEO | 35 | 9 | 17 | 100k+ | | | Non-prefixed constant |
| #99 | AnsPress – Question and answer | 35 | 22 | 778 | 3k+ | | | Non-prefixed function |
| #100 | Archive Content with Archived Post Status | 35 | 3 | 2 | 5k+ | | | Discouraged text-domain loading |