| #101 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | 24 | 826 | 1,314 | 600k+ | | | Non-prefixed global variable |
| #102 | Header Footer Code Manager | 36 | 81 | 180 | 600k+ | | | Non-prefixed global variable |
| #103 | Hello Dolly | 85 | 9 | 2 | 600k+ | | | Output is not escaped |
| #104 | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | 23 | 55 | 2,127 | 600k+ | | | Non-prefixed global variable |
| #105 | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | 30 | 63 | 227 | 600k+ | | | Non-prefixed global variable |
| #106 | Ninja Forms – The Contact Form Builder That Grows With You | 23 | 754 | 1,525 | 600k+ | | | Nonce verification recommended |
| #107 | Post Types Order | 42 | 45 | 43 | 600k+ | | | wp function not compatible with requires wp |
| #108 | Royal Addons for Elementor – Addons and Templates Kit for Elementor | 21 | 13,011 | 2,530 | 600k+ | | | Text Domain Mismatch |
| #109 | SpeedyCache – Cache, Optimization, Performance | 31 | 65 | 118 | 600k+ | | | Input is not validated |
| #110 | Sucuri Security – Auditing, Malware Scanner and Security Hardening | 94 | 52 | 5 | 600k+ | | | Missing direct file access protection |
| #111 | TablePress – Tables in WordPress made easy | 25 | 847 | 2,174 | 600k+ | | | Non-prefixed global variable |
| #112 | Under Construction | 35 | 3 | 0 | 600k+ | | | Hidden files included |
| #113 | WooCommerce Tax (formerly WooCommerce Shipping & Tax) | 30 | 103 | 198 | 600k+ | | | Non-prefixed class |
| #114 | WP Statistics – Simple, privacy-friendly Google Analytics alternative | 25 | 610 | 2,465 | 600k+ | | | Non-prefixed global variable |
| #115 | BackWPup – WordPress Backup & Restore Plugin | 35 | 12 | 779 | 500k+ | | | Non-prefixed global variable |
| #116 | Broken Link Checker | 25 | 727 | 600 | 500k+ | | | Output is not escaped |
| #117 | Disable Gutenberg | 43 | 23 | 47 | 500k+ | | | Nonce verification recommended |
| #118 | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more | 15 | 32 | 163 | 500k+ | | | Direct Query |
| #119 | Extendify | 35 | 117 | 168 | 500k+ | | | Non-prefixed global variable |
| #120 | GoSMTP – SMTP for WordPress | 39 | 59 | 42 | 500k+ | | | Output is not escaped |
| #121 | Kirki – Freeform Page Builder, Website Builder & Customizer | 35 | 1 | 773 | 500k+ | | | Nonce verification recommended |
| #122 | MailPoet – Newsletters, Email Marketing, and Automation | 23 | 931 | 719 | 500k+ | | | Exception output is not escaped |
| #123 | Meta Box | 96 | 5 | 16 | 500k+ | | | Non-prefixed hook name |
| #124 | Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider | 22 | 207 | 323 | 500k+ | | | Non-prefixed global variable |
| #125 | Ocean Extra | 23 | 1,494 | 2,106 | 500k+ | | | Non-prefixed global variable |
| #126 | PixelYourSite – Your smart PIXEL (TAG) & API Manager | 24 | 1,160 | 2,407 | 500k+ | | | Non-prefixed namespace |
| #127 | Ally – Web Accessibility & Usability | 41 | 47 | 35 | 500k+ | | | Output is not escaped |
| #128 | SiteGuard WP Plugin | 24 | 359 | 350 | 500k+ | | | Output is not escaped |
| #129 | SiteSEO – SEO Simplified | 41 | 20 | 110 | 500k+ | | | Nonce verification recommended |
| #130 | SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator | 29 | 336 | 198 | 500k+ | | | Text Domain Mismatch |
| #131 | Category Order and Taxonomy Terms Order | 76 | 35 | 10 | 500k+ | | | wp function not compatible with requires wp |
| #132 | Converter for Media – Optimize images | Convert WebP & AVIF | 35 | 133 | 53 | 500k+ | | | curl curl setopt |
| #133 | WP-PageNavi | 35 | 84 | 95 | 500k+ | | | Non Singular String Literal Domain |
| #134 | AMP | 43 | 63 | 362 | 400k+ | | | Non-prefixed hook name |
| #135 | Breeze Cache | 25 | 217 | 790 | 400k+ | | | Non-prefixed global variable |
| #136 | Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty | 26 | 113 | 671 | 400k+ | | | Non-prefixed global variable |
| #137 | CookieAdmin – Cookie Consent Banner | 37 | 43 | 86 | 400k+ | | | Nonce verification recommended |
| #138 | Custom Fonts – Host Your Fonts Locally | 77 | 14 | 20 | 400k+ | | | Request data is not unslashed |
| #139 | Meta for WooCommerce | 34 | 66 | 186 | 400k+ | | | Non-prefixed hook name |
| #140 | Font Awesome | 89 | 21 | 3 | 400k+ | | | Missing direct file access protection |
| #141 | GA Google Analytics – Connect Google Analytics to WordPress | 42 | 46 | 30 | 400k+ | | | Output is not escaped |
| #142 | Happy Addons for Elementor | 23 | 573 | 444 | 400k+ | | | Output is not escaped |
| #143 | WP Armour – Honeypot Anti Spam | 40 | 55 | 66 | 400k+ | | | Missing nonce verification |
| #144 | Intuitive Custom Post Order | 75 | 19 | 96 | 400k+ | | | Direct Query |
| #145 | Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery | 23 | 2,119 | 986 | 400k+ | | | Text Domain Mismatch |
| #146 | Meta pixel for WordPress | 34 | 91 | 38 | 400k+ | | | Exception output is not escaped |
| #147 | Page Builder: Pagelayer – Drag and Drop website builder | 24 | 769 | 556 | 400k+ | | | Output is not escaped |
| #148 | Redis Object Cache | 28 | 151 | 103 | 400k+ | | | Exception output is not escaped |
| #149 | Shortcodes Ultimate – Content Elements | 24 | 656 | 1,552 | 400k+ | | | Non-prefixed global variable |
| #150 | Page Builder by SiteOrigin | 31 | 226 | 214 | 400k+ | | | Output is not escaped |