| #1 | Wordfence Security – Firewall, Malware Scan, and Login Security | 21 | 1,592 | 2,973 | 5m+ | | | Output is not escaped |
| #2 | Security Plugin, Firewall & Malware Scanner with Auto Removal | 24 | 1,192 | 770 | 30k+ | | | Output is not escaped |
| #3 | Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning | 23 | 1,118 | 202 | 40k+ | | | Missing Translators Comment |
| #4 | Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention | 25 | 621 | 602 | 1m+ | | | Unsafe printing function |
| #5 | Login With Ajax – Fast Logins, 2FA, Redirects | 23 | 623 | 520 | 10k+ | | | Output is not escaped |
| #6 | Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) | 19 | 541 | 385 | 3m+ | | | Missing Translators Comment |
| #7 | Wordfence Login Security | 25 | 248 | 418 | 70k+ | | | Output is not escaped |
| #8 | WP 2FA – Two-factor authentication for WordPress | 30 | 269 | 380 | 100k+ | | | Exception output is not escaped |
| #9 | miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) | 88 | 611 | 5 | 10k+ | | | wp function not compatible with requires wp |
| #10 | WP Hide & Security Enhancer | 27 | 124 | 375 | 50k+ | | | Input is not sanitized |
| #11 | OTP Login & Register Woocommerce | 34 | 148 | 202 | 1k+ | | | Missing nonce verification |
| #12 | Two Factor Authentication | 35 | 108 | 139 | 20k+ | | | Output is not escaped |
| #13 | WP 2-step verification | 32 | 154 | 65 | 1k+ | | | Output is not escaped |
| #14 | Advanced IP Blocker | 40 | 94 | 44 | 2k+ | | | Exception output is not escaped |
| #15 | Two Factor | 42 | 18 | 70 | 100k+ | | | Nonce verification recommended |
| #16 | Two Factor (2FA) Authentication via Email | 61 | 12 | 27 | 9k+ | | | Request data is not unslashed |
| #17 | WebAuthn Provider for Two Factor | 91 | 6 | 14 | 1k+ | | | Missing Arg Domain |