| #251 | Nginx Helper | 71 | 47 | 60 | 200k+ | | | Non-prefixed global variable |
| #252 | Fonts Plugin | Google Fonts, Adobe Fonts & Upload Fonts | 35 | 41 | 8 | 200k+ | | | Missing direct file access protection |
| #253 | Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization | 29 | 80 | 162 | 200k+ | | | Nonce verification recommended |
| #254 | Page Optimize | 35 | 70 | 41 | 200k+ | | | Non Singular String Literal Domain |
| #255 | PHP Compatibility Checker | 97 | 42 | 5 | 200k+ | | | Text Domain Mismatch |
| #256 | Crowdsignal Dashboard – Polls, Surveys & more | 26 | 486 | 489 | 200k+ | | | Unsafe printing function |
| #257 | Popup Builder – Create highly converting, mobile friendly marketing popups. | 30 | 26 | 722 | 200k+ | | | Non-prefixed global variable |
| #258 | Post Duplicator | 60 | 33 | 24 | 200k+ | | | Missing direct file access protection |
| #259 | Post Type Switcher | 75 | 3 | 18 | 200k+ | | | Direct Query |
| #260 | Post Views Counter | 29 | 179 | 398 | 200k+ | | | Non-prefixed hook name |
| #261 | PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin | 24 | 449 | 1,137 | 200k+ | | | Nonce verification recommended |
| #262 | Qi Addons For Elementor | 79 | 33 | 339 | 200k+ | | | Non-prefixed global variable |
| #263 | Query Monitor | 31 | 44 | 273 | 200k+ | | | Non-prefixed class |
| #264 | Site Mailer – SMTP Replacement, Email API Deliverability & Email Log | 74 | 8 | 23 | 200k+ | | | Output is not escaped |
| #265 | Skyboot Custom Icons for Elementor | 60 | 90 | 8 | 200k+ | | | Text Domain Mismatch |
| #266 | Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder | 36 | 162 | 40 | 200k+ | | | Output is not escaped |
| #267 | SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers | 80 | 45 | 65 | 200k+ | | | Non-prefixed hook name |
| #268 | Table of Contents Plus | 95 | 29 | 9 | 200k+ | | | wp function not compatible with requires wp |
| #269 | TikTok | 35 | 31 | 22 | 200k+ | | | Missing Arg Domain |
| #270 | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin | 24 | 938 | 2,935 | 200k+ | | | Non-prefixed global variable |
| #271 | Use Any Font | Custom Font Uploader | 39 | 36 | 55 | 200k+ | | | Request data is not unslashed |
| #272 | User Switching | 63 | 2 | 47 | 200k+ | | | Nonce verification recommended |
| #273 | UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds | 22 | 444 | 243 | 200k+ | | | Text Domain Mismatch |
| #274 | Variation Swatches for WooCommerce – Color, Image & Size Swatches | 86 | 2 | 17 | 200k+ | | | Request data is not unslashed |
| #275 | White Label CMS | 33 | 409 | 207 | 200k+ | | | Unsafe printing function |
| #276 | Widget Importer & Exporter | 98 | 9 | 1 | 200k+ | | | wp function not compatible with requires wp |
| #277 | WP Consent API | 86 | 2 | 10 | 200k+ | | | Input is not sanitized |
| #278 | WP Migrate Lite – Migration Made Easy | 23 | 368 | 254 | 200k+ | | | Exception output is not escaped |
| #279 | WP Sitemap Page | 49 | 43 | 14 | 200k+ | | | Missing Translators Comment |
| #280 | Social Chat – Click To Chat App Button | 56 | 81 | 45 | 200k+ | | | Text Domain Mismatch |
| #281 | ReCaptcha v2 for Contact Form 7 | 44 | 12 | 30 | 200k+ | | | Nonce verification recommended |
| #282 | Redirection for Contact Form 7 | 27 | 34 | 374 | 200k+ | | | Non-prefixed global variable |
| #283 | WPFront Scroll Top | 100 | | 4 | 200k+ | | | trademarked term |
| #284 | 404 to 301 – Redirect Manager, 404 Error Logs & Notifications | 85 | | 24 | 100k+ | | | Database parameter is not escaped |
| #285 | Smart Custom 404 Error Page | 39 | 90 | 44 | 100k+ | | | Output is not escaped |
| #286 | ACF Content Analysis for Yoast SEO | 35 | 9 | 17 | 100k+ | | | Non-prefixed constant |
| #287 | Advanced Custom Fields: Extended | 23 | 1,885 | 329 | 100k+ | | | Text Domain Mismatch |
| #288 | Ivory Search – WordPress Search Plugin | 24 | 1,173 | 1,688 | 100k+ | | | Non-prefixed global variable |
| #289 | AddQuicktag | 41 | 86 | 10 | 100k+ | | | Output is not escaped |
| #290 | Ads.txt Manager | 92 | 4 | 4 | 100k+ | | | Missing direct file access protection |
| #291 | Advanced Access Manager – Access Governance for WordPress | 32 | 849 | 62 | 100k+ | | | Output is not escaped |
| #292 | Advanced Ads – Ad Manager & AdSense | 22 | 578 | 734 | 100k+ | | | Non-prefixed global variable |
| #293 | Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance | 30 | 164 | 439 | 100k+ | | | Interpolated SQL is not prepared |
| #294 | CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress | 35 | 20 | 10 | 100k+ | | | Missing Arg Domain |
| #295 | AI Engine – The Chatbot, AI Framework & MCP for WordPress | 23 | 411 | 544 | 100k+ | | | error log error log |
| #296 | FiboSearch – Ajax Search for WooCommerce | 25 | 603 | 302 | 100k+ | | | Output is not escaped |
| #297 | Aruba HiSpeed Cache | 97 | 12 | 5 | 100k+ | | | wp function not compatible with requires wp |
| #298 | Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) | 41 | 175 | 26 | 100k+ | | | Unsafe printing function |
| #299 | JetBackup – Backup, Restore & Migrate | 10 | 1,559 | 145 | 100k+ | | | Exception output is not escaped |
| #300 | bbPress | 21 | 929 | 3,672 | 100k+ | | | Non-prefixed function |