| #2251 | Ajaxify Comments – Ajax and Lazy Loading Comments | 65 | 20 | 38 | 3k+ | | | Non-prefixed hook name |
| #2252 | WP Change Default From Email | 65 | 51 | 7 | 10k+ | | | Non Singular String Literal Domain |
| #2253 | WP SEO HTML Sitemap | 65 | 22 | 15 | 6k+ | | | Output is not escaped |
| #2254 | Admin CSS MU | 64 | 30 | 582 | 10k+ | | | Non-prefixed global variable |
| #2255 | Beautiful taxonomy filters | 64 | 38 | 78 | 2k+ | | | Non-prefixed global variable |
| #2256 | UniqueID for Contact Form 7 | 64 | 21 | 18 | 2k+ | | | Text Domain Mismatch |
| #2257 | Channel.io | 64 | 14 | 3 | 1k+ | | | Output is not escaped |
| #2258 | Collapsing Archives | 64 | 36 | 9 | 3k+ | | | date date |
| #2259 | Advanced Comment Form | 64 | 68 | 6 | 4k+ | | | Output is not escaped |
| #2260 | Download Theme | 64 | 18 | 20 | 4k+ | | | wp function not compatible with requires wp |
| #2261 | ELEX WooCommerce Product Price Custom Text (Before & After Text) and Discount | 64 | 444 | 137 | 2k+ | | | Missing Arg Domain |
| #2262 | Embed Google Fonts | 64 | 28 | 7 | 5k+ | | | Output is not escaped |
| #2263 | Estonian Shipping Methods for WooCommerce | 64 | 97 | 16 | 1k+ | | | Text Domain Mismatch |
| #2264 | Favicon XT-Manager | 64 | 9 | 12 | 2k+ | | | Output is not escaped |
| #2265 | Icon Element – Icon Pack for Elementor Page Builder (6718 icons) | 64 | 30 | 16 | 40k+ | | | wp function not compatible with requires wp |
| #2266 | Inactive Logout | 64 | 30 | 71 | 10k+ | | | Non-prefixed global variable |
| #2267 | Inline Related Posts | 64 | 17 | 39 | 100k+ | | | Nonce verification recommended |
| #2268 | Kama SpamBlock | 64 | 29 | 7 | 5k+ | | | Short PHP open tag found |
| #2269 | Layouts for Divi | 64 | 3 | 27 | 1k+ | | | Non-prefixed global variable |
| #2270 | Master Post Advert | 64 | 26 | 4 | 1k+ | | | Unsafe printing function |
| #2271 | Meks Easy Social Share | 64 | 26 | 3 | 10k+ | | | Output is not escaped |
| #2272 | Moosend Website Connector | 64 | 15 | 12 | 1k+ | | | Non Singular String Literal Domain |
| #2273 | MultiSafepay plugin for WooCommerce | 64 | 13 | 35 | 2k+ | | | Missing nonce verification |
| #2274 | Nofollow for external link | 64 | 8 | 5 | 10k+ | | | Output is not escaped |
| #2275 | Page in Widget | 64 | 26 | 0 | 2k+ | | | Output is not escaped |
| #2276 | PHP Code Widget | 64 | 22 | 1 | 80k+ | | | Output is not escaped |
| #2277 | Product Import Export for WooCommerce – Import Export Product CSV Suite | 64 | 246 | 766 | 80k+ | | | Non-prefixed global variable |
| #2278 | Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini | 64 | 6 | 32 | 5k+ | | | Interpolated SQL is not prepared |
| #2279 | Click to Call Button | 64 | 58 | 3 | 1k+ | | | Output is not escaped |
| #2280 | SMK Sidebar Generator | 64 | 19 | 5 | 10k+ | | | Output is not escaped |
| #2281 | Stag Custom Sidebars | 64 | 10 | 12 | 2k+ | | | Text Domain Mismatch |
| #2282 | Oceanwp sticky header | 64 | 8 | 13 | 10k+ | | | Missing nonce verification |
| #2283 | Sticky Side Buttons | 64 | 27 | 4 | 10k+ | | | Unsafe printing function |
| #2284 | Thumbnail Crop Position | 64 | 43 | 1 | 2k+ | | | Output is not escaped |
| #2285 | Twitter | 64 | 27 | 23 | 9k+ | | | Missing Translators Comment |
| #2286 | WProofreader spell & grammar check plugin for WordPress | 64 | 12 | 43 | 4k+ | | | Non-prefixed global variable |
| #2287 | JTL-Connector for WooCommerce | 64 | 7 | 166 | 1k+ | | | Direct Query |
| #2288 | WP REST API Controller | 64 | 8 | 22 | 8k+ | | | Nonce verification recommended |
| #2289 | WP REST Cache | 64 | 11 | 113 | 10k+ | | | Direct Query |
| #2290 | WP Search with Algolia | 64 | 33 | 12 | 7k+ | | | Missing direct file access protection |
| #2291 | WP Term Order | 64 | 2 | 26 | 6k+ | | | Nonce verification recommended |
| #2292 | YaMaps for WordPress Plugin | 64 | 21 | 30 | 10k+ | | | Non-prefixed global variable |
| #2293 | Automatic Featured Images from Videos | 63 | 14 | 13 | 7k+ | | | Missing direct file access protection |
| #2294 | DW Block User Account | 63 | 6 | 11 | 1k+ | | | Unsafe printing function |
| #2295 | Categories Images | 63 | 10 | 21 | 50k+ | | | wp function not compatible with requires wp |
| #2296 | Category Sticky Post | 63 | 4 | 24 | 3k+ | | | Missing nonce verification |
| #2297 | Christmasify! | 63 | 18 | 7 | 3k+ | | | Output is not escaped |
| #2298 | Classic Editor | 63 | 17 | 7 | 9m+ | | | Unsafe printing function |
| #2299 | Classic Editor and Classic Widgets | 63 | 18 | 41 | 20k+ | | | Nonce verification recommended |
| #2300 | Classic Text Widget | 63 | 25 | 1 | 2k+ | | | Output is not escaped |