RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#1Yoast SEO – Advanced SEO with real-time guidance and built-in AI2415938610m+Non-prefixed global variable
#2Elementor Website Builder – more than just a page builder354642810m+Non-prefixed global variable
#3Jetpack – WP Security, Backup, Speed, & Growth232,8211,3033m+Text Domain Mismatch
#4WooCommerce221,3556,1297m+Non-prefixed global variable
#5Wordfence Security – Firewall, Malware Scan, and Login Security211,5922,9735m+Output is not escaped
#6Contact Form 769563910m+Missing direct file access protection
#7Akismet Anti-spam: Spam Protection3533996m+Non-prefixed global variable
#8WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More311652715m+Non-prefixed global variable
#9MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)251164412m+Nonce verification recommended
#10Site Kit by Google – Analytics, Search Console, AdSense, Speed251,3042425m+Missing direct file access protection
#11Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)195413853m+Missing Translators Comment
#12All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic971933m+wp function not compatible with requires wp
#13Rank Math SEO – AI SEO Tools to Dominate SEO Rankings31453734m+Non-prefixed global variable
#14All-in-One WP Migration and Backup4028615m+Missing nonce verification
#15UpdraftPlus: WP Backup & Migration Plugin242772993m+Non-prefixed global variable
#16LiteSpeed Cache352868937m+Non-prefixed global variable
#17Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation32462411m+Text Domain Mismatch
#18Essential Addons for Elementor – Popular Elementor Templates & Widgets63781852m+wp function not compatible with requires wp
#19Speed Optimizer – The All-In-One Performance-Boosting Plugin3645961m+Non-prefixed hook name
#20Starter Templates – AI-Powered Templates for Elementor & Gutenberg241253961m+Non-prefixed hook name
#21Classic Editor631779m+Unsafe printing function
#22Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention256216021m+Unsafe printing function
#23WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager8921303m+wp function not compatible with requires wp
#24The Events Calendar233,5123,848700k+Text Domain Mismatch
#25WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin36181464m+Direct Query
#26MC4WP: Mailchimp for WordPress572381m+Non-prefixed global variable
#27Redirection34322932m+Non-prefixed class
#28Advanced Custom Fields (ACF®)232,4561,2182m+Text Domain Mismatch
#29WordPress Importer252381102m+Output is not escaped
#30Smush – Image Optimization, Compression, Lazy Load, WebP & CDN252525661m+Non-prefixed hook name
#31MailPoet – Newsletters, Email Marketing, and Automation23858711500k+Exception output is not escaped
#32Ultimate Addons for Elementor35702262m+Non-prefixed hook name
#33WP Fastest Cache – WordPress Cache Plugin245417531m+Unsafe printing function
#34WP Super Cache258009891m+Output is not escaped
#35W3 Total Cache256171,345900k+Non-prefixed global variable
#36Premium Addons for Elementor – Powerful Elementor Templates & Widgets23206997700k+Non-prefixed hook name
#37Ninja Forms – The Contact Form Builder That Grows With You237541,525600k+Nonce verification recommended
#38Page Builder by SiteOrigin32224212500k+Output is not escaped
#39WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance5657691m+Non-prefixed global variable
#40Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More212,5721,2771m+Output is not escaped
#41ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)24118442300k+Nonce verification recommended
#42Smash Balloon Social Photo Feed – Easy Social Feeds Plugin254491,3001m+Interpolated SQL is not prepared
#43ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor40723481m+Non-prefixed global variable
#44Gutenberg22628342300k+Missing direct file access protection
#45WooCommerce Tax (formerly WooCommerce Shipping & Tax)30103198600k+Non-prefixed class
#46Meta for WooCommerce3466186400k+Non-prefixed hook name
#47WooCommerce Stripe Payment Gateway30173591700k+Non-prefixed hook name
#48CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice)8712911m+Non-prefixed global variable
#49EWWW Image Optimizer352257291m+Direct Query
#50SiteOrigin Widgets Bundle23607455400k+Output is not escaped