Most Installed Admin WordPress Plugins
132 indexed plugins
Plugins
132
Active Installs
4m+
Average Score
58
Audited
132
Most Installed
| Rank | Plugin | Score | Errors | Warnings | Installs | Updated | Top Issue |
|---|---|---|---|---|---|---|---|
| #1 | Loginizer | 25 | 814 | 504 | 1m+ | Output is not escaped | |
| #2 | Redux Framework | 93 | 222 | 0 | 900k+ | Missing direct file access protection | |
| #3 | Admin Menu Editor | 32 | 159 | 233 | 300k+ | Non-prefixed global variable | |
| #4 | White Label CMS | 33 | 411 | 207 | 200k+ | Unsafe printing function | |
| #5 | Advanced Custom Fields: Extended | 23 | 1,885 | 329 | 100k+ | Text Domain Mismatch | |
| #6 | Disable REST API | 65 | 12 | 15 | 90k+ | Output is not escaped | |
| #7 | Nested Pages | 25 | 674 | 560 | 90k+ | Non-prefixed global variable | |
| #8 | Add From Server | 37 | 52 | 20 | 60k+ | Output is not escaped | |
| #9 | All In One Favicon | 34 | 214 | 62 | 60k+ | Output is not escaped | |
| #10 | Conditional Menus | 35 | 92 | 28 | 60k+ | Text Domain Mismatch | |
| #11 | Cryout Serious Theme Settings | 40 | 332 | 51 | 40k+ | Output is not escaped | |
| #12 | Revision Control | 41 | 60 | 28 | 40k+ | Output is not escaped | |
| #13 | WP Revisions Control | 85 | 9 | 6 | 40k+ | wp function not compatible with requires wp | |
| #14 | AJAX Thumbnail Rebuild | 40 | 38 | 14 | 30k+ | Unsafe printing function | |
| #15 | Display PHP Version | 96 | 6 | 2 | 30k+ | Missing direct file access protection | |
| #16 | Login as User | 36 | 101 | 64 | 30k+ | Output is not escaped | |
| #17 | Scripts n Styles | 39 | 150 | 92 | 30k+ | Output is not escaped | |
| #18 | Site Offline Or Coming Soon Or Maintenance Mode | 37 | 127 | 138 | 30k+ | Unsafe printing function | |
| #19 | WP Admin UI Customize | 30 | 629 | 390 | 30k+ | Non-prefixed global variable | |
| #20 | WP Custom Admin Interface | 34 | 263 | 118 | 30k+ | Unsafe printing function | |
| #21 | WP Updates Notifier | 35 | 23 | 4 | 30k+ | Missing Translators Comment | |
| #22 | Catch IDs | 88 | 16 | 20k+ | Non-prefixed global variable | ||
| #23 | Desert Companion | 68 | 410 | 830 | 20k+ | Non-prefixed global variable | |
| #24 | Error Log Monitor | 23 | 694 | 1,414 | 20k+ | Non-prefixed global variable | |
| #25 | Featured Image Admin Thumb | 90 | 7 | 10 | 20k+ | Non-prefixed hook name | |
| #26 | Hide Admin Bar | 51 | 35 | 17 | 20k+ | Unsafe printing function | |
| #27 | Radio Buttons for Taxonomies | 39 | 40 | 24 | 20k+ | Output is not escaped | |
| #28 | SEO Friendly Images | 39 | 292 | 20 | 20k+ | Output is not escaped | |
| #29 | Simple Taxonomy Ordering | 75 | 7 | 10 | 20k+ | Direct Query | |
| #30 | SpiceBox | 24 | 828 | 1,816 | 20k+ | Non-prefixed global variable | |
| #31 | Add Admin CSS | 98 | 4 | 2 | 10k+ | Not Allowed | |
| #32 | Adjust Admin Categories | 51 | 30 | 12 | 10k+ | Output is not escaped | |
| #33 | Admin CSS MU | 64 | 30 | 582 | 10k+ | Non-prefixed global variable | |
| #34 | Admin Menu Tree Page View | 43 | 17 | 69 | 10k+ | Nonce verification recommended | |
| #35 | Arile Extra | 29 | 538 | 566 | 10k+ | Non-prefixed global variable | |
| #36 | Audit Trail | 34 | 90 | 107 | 10k+ | Unsafe printing function | |
| #37 | Automatic Domain Changer | 69 | 37 | 14 | 10k+ | Text Domain Mismatch | |
| #38 | Bogo | 39 | 30 | 139 | 10k+ | Request data is not unslashed | |
| #39 | Custom Login | 42 | 36 | 116 | 10k+ | Non-prefixed global variable | |
| #40 | LWS Tools | 31 | 104 | 134 | 10k+ | Request data is not unslashed | |
| #41 | Slim Maintenance Mode | 68 | 9 | 10 | 10k+ | Output is not escaped | |
| #42 | Term Management Tools | 43 | 9 | 26 | 10k+ | Non-prefixed hook name | |
| #43 | Uber Login Logo | 62 | 16 | 5 | 10k+ | Unsafe printing function | |
| #44 | WP Last Login | 98 | 2 | 4 | 10k+ | trademarked term | |
| #45 | WP-Memory-Usage | 89 | 4 | 9 | 10k+ | Interpolated SQL is not prepared | |
| #46 | Widget Disable | 46 | 19 | 19 | 10k+ | Output is not escaped | |
| #47 | WPCore Plugin Manager | 35 | 118 | 38 | 10k+ | Text Domain Mismatch | |
| #48 | WPS Bidouille | 28 | 472 | 215 | 10k+ | Output is not escaped | |
| #49 | ACF qTranslate | 40 | 184 | 25 | 9k+ | Output is not escaped | |
| #50 | Daddy Plus | 90 | 35 | 552 | 9k+ | Non-prefixed global variable |