| #10001 | AnyComment | 17 | 445 | 449 | 5k+ | | | Output is not escaped |
| #10002 | Efí Bank | 17 | 886 | 553 | 400 | | | Exception output is not escaped |
| #10003 | wpForo Forum | 17 | 4,033 | 2,922 | 20k+ | | | Unsafe printing function |
| #10004 | WPtouch – Make your WordPress Website Mobile-Friendly | 17 | 1,466 | 325 | 50k+ | | | Text Domain Mismatch |
| #10005 | Visual Composer Website Builder | 16 | 82 | 320 | 40k+ | | | Non-prefixed global variable |
| #10006 | MDTF – Meta Data and Taxonomies Filter | 16 | 1,550 | 1,956 | 1k+ | | | Non-prefixed global variable |
| #10007 | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more | 15 | 45 | 166 | 500k+ | | | Database parameter is not escaped |
| #10008 | JetBackup – Backup, Restore & Migrate | 10 | 1,559 | 145 | 100k+ | | | Exception output is not escaped |
| #10009 | Themify Builder | 9 | 5,195 | 2,096 | 5k+ | | | Text Domain Mismatch |
| #10010 | BulletProof Security | 0 | 5,048 | 4,949 | 20k+ | | | Output is not escaped |
| #10011 | Intercom | 0 | 60 | 71 | 6k+ | | | Non-prefixed function |
| #10012 | Live Shopping & Shoppable Videos For WooCommerce | 0 | 78 | 175 | 400 | | | Non-prefixed global variable |
| #10013 | Plugin Check (PCP) | 0 | 128 | 132 | 10k+ | | | Exception output is not escaped |