RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#201WP Crontrol412091300k+Nonce verification recommended
#202WP Go Maps – Google Map, OpenStreetMap, Leaflet Map254,9961,008300k+Unsafe printing function
#203Insert Headers And Footers3483113300k+Non-prefixed global variable
#204WP Mail Logging3476258300k+Nonce verification recommended
#205WP Reset96831300k+Non-prefixed global variable
#206WP Rollback – Rollback Plugins and Themes9819300k+Non-prefixed hook name
#207WP Activity Log2796230300k+Nonce verification recommended
#208SEOPress – AI SEO Plugin & On-site SEO32138429300k+Non-prefixed global variable
#209DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer921011200k+Missing direct file access protection
#210Admin and Site Enhancements (ASE)23136330200k+Nonce verification recommended
#211Adminimize29296691200k+Non-prefixed global variable
#212Advanced Google reCAPTCHA97315200k+Non-prefixed global variable
#213All 404 Redirect to Homepage25140301200k+date date
#214Activity Log – Monitor & Record User Changes3881149200k+Nonce verification recommended
#215Astra Widgets861015200k+Missing direct file access protection
#216The SEO Framework – Fast, Automated, Effortless.31363609200k+Non-prefixed global variable
#217Black Studio TinyMCE Widget403928200k+Output is not escaped
#218Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative)6933368200k+Direct Query
#219Call Now Button – The #1 Click to Call Button for WordPress371,2735200k+Exception output is not escaped
#220CartFlows – Funnel Builder & Checkout Plugin for WooCommerce21462654200k+Text Domain Mismatch
#221CleanTalk Anti-Spam. Spam Firewall & Bot protection248251,079200k+Missing nonce verification
#222Cloudflare352785200k+Non-prefixed namespace
#223CMP – Coming Soon & Maintenance Plugin by NiteoThemes249491,336200k+Non-prefixed global variable
#224Crowdsignal Forms1000200k+No open findings
#225Smash Balloon Social Post Feed – Simple Social Feeds for WordPress25554982200k+Output is not escaped
#226Custom Post Type Permalinks3584200k+Setting is missing a sanitization callback
#227Disable XML-RPC10010200k+Missing direct file access protection
#228Firelight Lightbox517897200k+Non-prefixed global variable
#229Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns24120684200k+Non-prefixed global variable
#230Instant Indexing for Google351362200k+Non-prefixed global variable
#231Favicon by RealFaviconGenerator971018200k+Non-prefixed constant
#232FileBird – WordPress Media Library Folders & File Manager24239377200k+wp function not compatible with requires wp
#233FileOrganizer – WordPress File Manager21536241200k+unlink unlink
#234Force Regenerate Thumbnails351217200k+unlink unlink
#235GenerateBlocks9798200k+file system operations is writable
#236Header and Footer Scripts9921200k+Non-prefixed class
#237Imsanity353229200k+Direct Query
#238iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more60405271200k+Text Domain Mismatch
#239InfiniteWP Client222,2861,812200k+Exception output is not escaped
#240Jetpack Boost – Website Speed, Performance and Critical CSS29659247200k+Text Domain Mismatch
#241Layout Grid Block9851200k+Missing direct file access protection
#242HubSpot All-In-One Marketing – Forms, Popups, Live Chat9764200k+Missing direct file access protection
#243LoginPress | wp-login Custom Login Page Customizer55124301200k+Non-prefixed function
#244Mailchimp for WooCommerce24523663200k+Non-prefixed global variable
#245MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall825522200k+Missing direct file access protection
#246Microsoft Clarity3648163200k+Nonce verification recommended
#247Migrate Guru – Site Migration & Cloning8178200k+Database parameter is not escaped
#248MW WP Form27334219200k+Output is not escaped
#249Newsletter – Send awesome emails from WordPress248982,214200k+Non-prefixed global variable
#250Nextend Social Login and Register271,668243200k+Output is not escaped