hidden_files

Hidden files included

The plugin package contains hidden files or directories that usually should not ship in a WordPress.org release.

critical weight

Why It Shows Up

Plugin Check found dotfiles, hidden folders, or operating-system metadata in the plugin ZIP.

Why It Matters

Hidden files can leak development metadata, repository configuration, local tooling state, or unexpected content.

How to Fix

  • Exclude dotfiles and local metadata from the release build.
  • Build release ZIPs from a clean export or packaging script.
  • Keep only files required for the plugin to run, document itself, or provide distributed assets.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#1BulletProof Security05,0484,94920k+Output is not escaped
#2JetBackup – Backup, Restore & Migrate101,559145100k+Exception output is not escaped
#3Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more1532163500k+Direct Query
#4Visual Composer Website Builder168232040k+Non-prefixed global variable
#5MDTF – Meta Data and Taxonomies Filter161,5501,9561k+Non-prefixed global variable
#6AnyComment174454495k+Output is not escaped
#7Efí Bank17886553400Exception output is not escaped
#8wpForo Forum174,0332,92220k+Unsafe printing function
#9Prime Slider Addons for Elementor183,500230100k+Text Domain Mismatch
#10JetFormBuilder — Dynamic Blocks Form Builder182,0931,58990k+Text Domain Mismatch
#11Pagopar – WooCommerce Gateway185301,215400Non-prefixed global variable
#12Podlove Podcast Publisher182,3261,4293k+Output is not escaped
#13Property Hive181,9576,0273k+Missing nonce verification
#14RestroPress – Online Food Ordering System185213,0831k+Non-prefixed global variable
#15Shopping Cart & eCommerce Store185,45917,2984k+Non-prefixed global variable
#16WP Directory Kit182,1192,6172k+Non-prefixed global variable
#17WPPizza – A Restaurant Plugin184,6892,7031k+Text Domain Mismatch
#18Block Slider – Responsive Image Slider, Video Slider & Post Slider195551,2913k+Non-prefixed global variable
#19Download Monitor194251,36480k+Non-prefixed hook name
#20Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution191,218901100k+Exception output is not escaped
#21Go Fetch Jobs (for WP Job Manager)191,4101,741700Non-prefixed global variable
#22AI Infographic Maker191,517599600Output is not escaped
#23Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)193,2753,22810k+Output is not escaped
#24Matomo Analytics – Powerful, Privacy-First Insights for WordPress191,909878100k+Exception output is not escaped
#25Netgsm193382981k+Setting is missing a sanitization callback
#26Razorpay Payment Button Plugin19486982k+Exception output is not escaped
#27Realtyna Organic IDX plugin + WPL Real Estate199473,6532k+Non-prefixed global variable
#28Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)195413853m+Missing Translators Comment
#29Membership Plugin – Kadence Memberships195,0822,9829k+Text Domain Mismatch
#30Scrollsequence – Cinematic Scroll Image Animation Plugin198781,5284k+Non-prefixed global variable
#31SendPress Newsletters192,2931,4222k+Output is not escaped
#32SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments195261,11990k+Non-prefixed global variable
#33WordLift – AI powered SEO – Schema19393946400Non-prefixed hook name
#34WP Email Template193423502k+Exception output is not escaped
#35WP Import Export Lite1973797940k+Non-prefixed global variable
#36WPOSS阿里云对象存储192693151k+Non-prefixed namespace
#37WPQiNiu七牛云对象存储19138612400Non-prefixed global variable
#38AweBooking – Hotel Booking System203095141k+Non-prefixed global variable
#39Brizy – Page Builder2058972070k+Output is not escaped
#40Broadstreet20434273700Output is not escaped
#41Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)207362,112900Non-prefixed global variable
#42SysBasics Customize My Account for WooCommerce – Live My Account Customizer207448528k+Non-prefixed global variable
#43Event Espresso – Event Registration & Ticketing Sales2012,6982,135600Text Domain Mismatch
#44Event Organiser201,10454420k+Text Domain Mismatch
#45Filter Everything — WordPress & WooCommerce Filters2056873050k+Output is not escaped
#46GiveWP – Donation Plugin and Fundraising Platform203,4373,577100k+Output is not escaped
#47GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership201,832720800Non Singular String Literal Domain
#48Leaky Paywall20320776700Nonce verification recommended
#49Link Library201,9411,39710k+Unsafe printing function
#50MBE eShip205277401k+Non-prefixed global variable