RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#1Contact Form 769563910m+Missing direct file access protection
#2Elementor Website Builder – more than just a page builder354642810m+Non-prefixed global variable
#3Yoast SEO – Advanced SEO with real-time guidance and built-in AI2415938610m+Non-prefixed global variable
#4Classic Editor631779m+Unsafe printing function
#5LiteSpeed Cache352868937m+Non-prefixed global variable
#6WooCommerce221,3556,1297m+Non-prefixed global variable
#7Akismet Anti-spam: Spam Protection3533996m+Non-prefixed global variable
#8All-in-One WP Migration and Backup4028615m+Missing nonce verification
#9Site Kit by Google – Analytics, Search Console, AdSense, Speed251,3042425m+Missing direct file access protection
#10Wordfence Security – Firewall, Malware Scan, and Login Security211,5922,9735m+Output is not escaped
#11WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More311652715m+Non-prefixed global variable
#12Yoast Duplicate Post708884m+Nonce verification recommended
#13Rank Math SEO – AI SEO Tools to Dominate SEO Rankings31453734m+Non-prefixed global variable
#14WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin36181464m+Direct Query
#15All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic971933m+wp function not compatible with requires wp
#16Duplicate Page4039433m+Unsafe printing function
#17Hostinger Tools8114223m+wp function not compatible with requires wp
#18WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager8921303m+wp function not compatible with requires wp
#19Jetpack – WP Security, Backup, Speed, & Growth232,8211,3033m+Text Domain Mismatch
#20Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)195413853m+Missing Translators Comment
#21UpdraftPlus: WP Backup & Migration Plugin242772993m+Non-prefixed global variable
#22Advanced Custom Fields (ACF®)232,4561,2182m+Text Domain Mismatch
#23Classic Widgets97232m+outdated tested upto header
#24Essential Addons for Elementor – Popular Elementor Templates & Widgets63781852m+wp function not compatible with requires wp
#25MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)251164412m+Nonce verification recommended
#26Ultimate Addons for Elementor35702262m+Non-prefixed hook name
#27Redirection34322932m+Non-prefixed class
#28WordPress Importer252381102m+Output is not escaped
#29WPS Hide Login4134722m+Nonce verification recommended
#30All-In-One Security (AIOS) – Security and Firewall245521,2281m+Non-prefixed global variable
#31Starter Templates – AI-Powered Templates for Elementor & Gutenberg241253961m+Non-prefixed hook name
#32Better Search Replace3996431m+Unsafe printing function
#33Code Snippets36342031m+Nonce verification recommended
#34Complianz – GDPR/CCPA Cookie Consent244874031m+Missing Arg Domain
#35CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice)8712911m+Non-prefixed global variable
#36Custom Post Type UI5316231m+Output is not escaped
#37Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]5315461m+Non-prefixed global variable
#38Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More212,5721,2771m+Output is not escaped
#39ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor40723481m+Non-prefixed global variable
#40EWWW Image Optimizer352257291m+Direct Query
#41XML Sitemap Generator for Google3743791m+Input is not validated
#42Hostinger Reach – AI-Powered Email Marketing for WordPress409461m+Direct Query
#43Image Optimizer – Optimize Images and Convert to WebP or AVIF8714241m+Missing Translators Comment
#44Imagify: Optimize Images for Top Speed (Compress & Convert to WebP/AVIF)214208611m+Non-prefixed global variable
#45Smash Balloon Social Photo Feed – Easy Social Feeds Plugin254491,3001m+Interpolated SQL is not prepared
#46Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention256216021m+Unsafe printing function
#47Loco Translate264542421m+Output is not escaped
#48Loginizer258145041m+Output is not escaped
#49MC4WP: Mailchimp for WordPress572381m+Non-prefixed global variable
#50Maintenance99301m+strip tags strip tags