| #3351 | Search shortcode | 98 | 3 | 0 | 1k+ | | | Missing direct file access protection |
| #3352 | Disable Payment Methods based on cart conditions for WooCommerce | 36 | 158 | 57 | 1k+ | | | Non Singular String Literal Domain |
| #3353 | Local Pickup for WooCommerce | 24 | 550 | 1,388 | 1k+ | | | Non-prefixed global variable |
| #3354 | WiserNotify – Social Proof & FOMO Notifications, WooCommerce Sales Popups, Reviews & Announcement Bar | 62 | 13 | 32 | 1k+ | | | Request data is not unslashed |
| #3355 | Hatom/hentry remover (Fixes errors in Google Webmaster Tools) | 98 | 2 | 2 | 1k+ | | | mismatched plugin name |
| #3356 | Repeater Fields for Gravity Forms | 46 | 134 | 41 | 1k+ | | | wp function not compatible with requires wp |
| #3357 | MerPress | 96 | 6 | 3 | 1k+ | | | block api version too low |
| #3358 | Responsive Like Box, Like Box Widget | 54 | 43 | 4 | 1k+ | | | Output is not escaped |
| #3359 | Shortcode Preview Block | 97 | 5 | 3 | 1k+ | | | Missing Version |
| #3360 | Background Music Manager | 98 | 2 | 0 | 1k+ | | | outdated tested upto header |
| #3361 | Civist – Petitions and Fundraising | 100 | | 0 | 1k+ | | | No open findings |
| #3362 | Popular Posts by Webline | 38 | 256 | 8 | 1k+ | | | Output is not escaped |
| #3363 | Links With Icons Widget | 49 | 53 | 2 | 1k+ | | | Output is not escaped |
| #3364 | WC Call For Price | 57 | 19 | 55 | 1k+ | | | Non-prefixed global variable |
| #3365 | Memberful – Membership Plugin | 27 | 351 | 336 | 1k+ | | | Text Domain Mismatch |
| #3366 | Mouse cursor customizer | 67 | 5 | 38 | 1k+ | | | Missing nonce verification |
| #3367 | SALESmanago & Leadoo | 22 | 645 | 429 | 1k+ | | | Unsafe printing function |
| #3368 | 3B Meteo | 36 | 50 | 76 | 1k+ | | | Output is not escaped |
| #3369 | List Last Changes | 58 | 50 | 15 | 1k+ | | | Output is not escaped |
| #3370 | Instant AI Image Generator – Create & Import Images | 78 | | 23 | 1k+ | | | Non-prefixed constant |
| #3371 | Posts Order | 59 | 59 | 20 | 1k+ | | | Text Domain Mismatch |
| #3372 | Post views Stats | 38 | 37 | 51 | 1k+ | | | Non-prefixed global variable |
| #3373 | Github Embed | 44 | 18 | 35 | 1k+ | | | Non-prefixed global variable |
| #3374 | DarkMySite – Advanced Dark Mode Plugin for WordPress | 46 | 22 | 100 | 1k+ | | | Request data is not unslashed |
| #3375 | WP OAuth Server ( Login with WordPress ) | 92 | 29 | 10 | 1k+ | | | wp function not compatible with requires wp |
| #3376 | Advanced GeoIP Redirect | 99 | | 13 | 1k+ | | | Non-prefixed global variable |
| #3377 | Extended User Search In WP-Admin | 54 | 14 | 17 | 1k+ | | | SQL query is not prepared |
| #3378 | Arvow AI SEO Writer | 95 | 1 | 6 | 1k+ | | | Non-prefixed global variable |
| #3379 | List Products By Category Widget for WooCommerce | 42 | 84 | 5 | 1k+ | | | Output is not escaped |
| #3380 | Ad Auto Insert H | 41 | 496 | 15 | 1k+ | | | Non Singular String Literal Domain |
| #3381 | Type Attribute Warnings Removal | 98 | 3 | 1 | 1k+ | | | mismatched plugin name |
| #3382 | Chartbeat | 42 | 33 | 18 | 1k+ | | | Output is not escaped |
| #3383 | Shoutcast Icecast HTML5 Radio Player | 67 | 17 | 10 | 1k+ | | | Input is not validated |
| #3384 | Simple Photo Feed | 87 | 4 | 48 | 1k+ | | | Non-prefixed global variable |
| #3385 | Boei – AI Chatbot, Live Chat & 50+ Channels for WordPress | 78 | 9 | 4 | 1k+ | | | Output is not escaped |
| #3386 | Floating Action Button | 39 | 164 | 69 | 1k+ | | | Unsafe printing function |
| #3387 | WP Site Verification tool | 35 | 34 | 37 | 1k+ | | | Non-prefixed global variable |
| #3388 | Open Currency Converter | 42 | 59 | 19 | 1k+ | | | Unsafe printing function |
| #3389 | Plugins Condition | 96 | 3 | 30 | 1k+ | | | Non-prefixed global variable |
| #3390 | Preload Images | 76 | 8 | 6 | 1k+ | | | Output is not escaped |
| #3391 | WPC Smart Messages for WooCommerce | 55 | 6 | 84 | 1k+ | | | Non-prefixed global variable |
| #3392 | Wikipedia Preview | 96 | 8 | 15 | 1k+ | | | Non-prefixed function |
| #3393 | If Modified Since | 91 | 2 | 4 | 1k+ | | | Request data is not unslashed |
| #3394 | Clever Mega Menu for Visual Composer | 38 | 500 | 87 | 1k+ | | | Output is not escaped |
| #3395 | Easy Tabs Block – Smart, Lightweight & Responsive Tabs for the Block Editor | 35 | 2 | 0 | 1k+ | | | Hidden files included |
| #3396 | Simple Mortgage Calculator | 43 | 67 | 3 | 1k+ | | | Text Domain Mismatch |
| #3397 | Daisy Comments — Disable Comments & Stop Spam | 95 | 1 | 3 | 1k+ | | | Non-prefixed class |
| #3398 | WPWaterMark 轻水印插件 | 73 | 24 | 17 | 1k+ | | | Request data is not unslashed |
| #3399 | MAS Elementor | 89 | 19 | 216 | 1k+ | | | Non-prefixed hook name |
| #3400 | Stock Locations for WooCommerce | 32 | 548 | 360 | 1k+ | | | Output is not escaped |