| #5901 | GoSMTP – SMTP for WordPress | 39 | 59 | 42 | 500k+ | | Output is not escaped |
| #5902 | Disable Gutenberg | 43 | 23 | 47 | 500k+ | | Nonce verification recommended |
| #5903 | WP Statistics – Simple, privacy-friendly Google Analytics alternative | 25 | 610 | 2,465 | 600k+ | | Non-prefixed global variable |
| #5904 | FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider | 29 | 74 | 78 | 600k+ | | Missing Translators Comment |
| #5905 | Database Addon for Contact Form 7 – CFDB7 | 40 | 35 | 56 | 600k+ | | Nonce verification recommended |
| #5906 | SpeedyCache – Cache, Optimization, Performance | 31 | 65 | 115 | 600k+ | | Input is not validated |
| #5907 | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | 30 | 63 | 227 | 600k+ | | Non-prefixed global variable |
| #5908 | Hello Dolly | 85 | 9 | 2 | 600k+ | | Output is not escaped |
| #5909 | Easy Table of Contents | 99 | 4 | 4 | 600k+ | | Non-prefixed constant |
| #5910 | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | 23 | 55 | 2,127 | 600k+ | | Non-prefixed global variable |
| #5911 | Under Construction | 35 | 3 | 0 | 600k+ | | Hidden files included |
| #5912 | Header Footer Code Manager | 36 | 81 | 180 | 600k+ | | Non-prefixed global variable |
| #5913 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | 24 | 826 | 1,314 | 600k+ | | Non-prefixed global variable |
| #5914 | Sucuri Security – Auditing, Malware Scanner and Security Hardening | 94 | 52 | 5 | 600k+ | | Missing direct file access protection |
| #5915 | Post Types Order | 42 | 45 | 43 | 600k+ | | wp function not compatible with requires wp |
| #5916 | Enable Media Replace | 24 | 214 | 276 | 600k+ | | Output is not escaped |
| #5917 | Royal Addons for Elementor – Addons and Templates Kit for Elementor | 21 | 13,011 | 2,530 | 600k+ | | Text Domain Mismatch |
| #5918 | Simple Custom CSS and JS | 37 | 168 | 69 | 600k+ | | Output is not escaped |
| #5919 | TablePress – Tables in WordPress made easy | 25 | 847 | 2,174 | 600k+ | | Non-prefixed global variable |
| #5920 | The Events Calendar | 23 | 3,512 | 3,848 | 700k+ | | Text Domain Mismatch |
| #5921 | Backuply – Backup, Restore, Migrate and Clone | 24 | 704 | 551 | 700k+ | | Non-prefixed global variable |
| #5922 | Click to Chat – HoliThemes | 99 | 6 | 2 | 700k+ | | badly named files |
| #5923 | Premium Addons for Elementor – Powerful Elementor Templates & Widgets | 23 | 206 | 997 | 700k+ | | Non-prefixed hook name |
| #5924 | Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode | 25 | 99 | 1,035 | 700k+ | | Non-prefixed global variable |
| #5925 | Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder | 66 | 51 | 690 | 700k+ | | Non-prefixed hook name |
| #5926 | User Role Editor | 43 | 117 | 145 | 700k+ | | Output is not escaped |
| #5927 | Joinchat – Enhanced "click to chat" | 81 | 18 | 32 | 700k+ | | wp function not compatible with requires wp |
| #5928 | MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites | 38 | 3 | 136 | 700k+ | | Non-prefixed hook name |
| #5929 | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | 22 | 409 | 236 | 700k+ | | Text Domain Mismatch |
| #5930 | Antispam Bee | 80 | 4 | 38 | 700k+ | | Nonce verification recommended |
| #5931 | Kadence Security – Password, Two Factor Authentication, and Brute Force Protection | 23 | 1,053 | 967 | 700k+ | | Missing Translators Comment |
| #5932 | GTM4WP – A Google Tag Manager (GTM) plugin for WordPress | 91 | 59 | 79 | 700k+ | | Non-prefixed global variable |
| #5933 | Flamingo | 40 | 15 | 228 | 800k+ | | Nonce verification recommended |
| #5934 | WooCommerce PayPal Payments | 37 | 179 | 101 | 800k+ | | Exception output is not escaped |
| #5935 | Breadcrumb NavXT | 36 | 102 | 111 | 800k+ | | Non Singular String Literal Domain |
| #5936 | Smart Slider 3 | 23 | 261 | 268 | 800k+ | | Non-prefixed global variable |
| #5937 | Polylang | 26 | 36 | 564 | 800k+ | | Non-prefixed hook name |
| #5938 | Autoptimize | 23 | 288 | 191 | 800k+ | | Output is not escaped |
| #5939 | Google for WooCommerce | 37 | 328 | 121 | 800k+ | | Exception output is not escaped |
| #5940 | WooPayments: Integrated WooCommerce Payments | 30 | 177 | 298 | 900k+ | | Exception output is not escaped |
| #5941 | Translate WordPress with GTranslate | 32 | 82 | 364 | 900k+ | | Non-prefixed global variable |
| #5942 | Compliance by Hu-manity.co | 31 | 154 | 336 | 900k+ | | Missing nonce verification |
| #5943 | W3 Total Cache | 25 | 617 | 1,345 | 900k+ | | Non-prefixed global variable |
| #5944 | WPvivid — Backup, Migration & Staging | 25 | 899 | 1,461 | 900k+ | | Non-prefixed namespace |
| #5945 | Widgets for Google Reviews | 95 | | 340 | 900k+ | | Non-prefixed global variable |
| #5946 | WP Multibyte Patch | 39 | 24 | 55 | 1m+ | | Input is not sanitized |
| #5947 | Regenerate Thumbnails | 82 | 10 | 9 | 1m+ | | Direct Query |
| #5948 | All-In-One Security (AIOS) – Security and Firewall | 24 | 552 | 1,228 | 1m+ | | Non-prefixed global variable |
| #5949 | EWWW Image Optimizer | 35 | 225 | 729 | 1m+ | | Direct Query |
| #5950 | Smash Balloon Social Photo Feed – Easy Social Feeds Plugin | 25 | 449 | 1,300 | 1m+ | | Interpolated SQL is not prepared |