Most Installed Admin WordPress Plugins
247 indexed plugins
Plugins
247
Active Installs
4m+
Average Score
62
Audited
233
Most Installed
| Rank | Plugin | Score | Errors | Warnings | Installs | Added | Updated | Top Issue |
|---|---|---|---|---|---|---|---|---|
| #151 | Bulk Edit YOAST SEO fields in Spreadsheet | 61 | 56 | 16 | 1k+ | Non Singular String Literal Domain | ||
| #152 | WPC Admin Columns | 88 | 30 | 1k+ | Direct Query | |||
| #153 | WPPerformanceTester | 35 | 94 | 44 | 1k+ | Output is not escaped | ||
| #154 | Advanced Custom Fields – Location Field add-on | 48 | 51 | 6 | 900 | Output is not escaped | ||
| #155 | AMIMOTO Plugin Dashboard | 35 | 82 | 82 | 900 | Non Singular String Literal Domain | ||
| #156 | Custom Posts Per Page | 66 | 20 | 2 | 900 | Unsafe printing function | ||
| #157 | Dashboard Commander | 69 | 13 | 2 | 900 | Output is not escaped | ||
| #158 | Mass Delete Unused Tags | 42 | 21 | 9 | 900 | Output is not escaped | ||
| #159 | MS Custom Login | 41 | 117 | 6 | 900 | Unsafe printing function | ||
| #160 | Noted! | 35 | 5 | 22 | 900 | Non-prefixed global variable | ||
| #161 | Dobby | 97 | 3 | 2 | 900 | Dynamic hook name | ||
| #162 | WP Revisions Limit | 74 | 16 | 14 | 900 | Missing Arg Domain | ||
| #163 | WP Updates Settings | 79 | 7 | 8 | 900 | Unsafe printing function | ||
| #164 | Admin Menu Groups | 60 | 26 | 10 | 800 | Output is not escaped | ||
| #165 | Admin Page Notes | 58 | 17 | 15 | 800 | Text Domain Mismatch | ||
| #166 | Admin Sticky Sidebar | 98 | 2 | 3 | 800 | Missing direct file access protection | ||
| #167 | ACF: Google Map Extended | 41 | 141 | 8 | 800 | Text Domain Mismatch | ||
| #168 | Auto Subpage Menu | 85 | 5 | 6 | 800 | Database parameter is not escaped | ||
| #169 | Bulk Actions Select All | 53 | 26 | 22 | 800 | Text Domain Mismatch | ||
| #170 | Bulk Add Terms | 40 | 74 | 27 | 800 | Text Domain Mismatch | ||
| #171 | Custom Background Extended | 48 | 13 | 23 | 800 | Input is not validated | ||
| #172 | Default Admin Color Scheme | 100 | 0 | 800 | No open findings | |||
| #173 | Disable Admin Bar | 96 | 5 | 1 | 800 | Missing direct file access protection | ||
| #174 | Easy WP Page Navigation | 52 | 60 | 8 | 800 | Non Singular String Literal Domain | ||
| #175 | More Types | 33 | 227 | 198 | 800 | Non-prefixed global variable | ||
| #176 | Posts Columns Manager | 56 | 47 | 2 | 800 | Output is not escaped | ||
| #177 | Purchased Items Column for WooCommerce Orders | 70 | 10 | 8 | 800 | Output is not escaped | ||
| #178 | PWD WP Favicon | 95 | 3 | 8 | 800 | trademarked term | ||
| #179 | SimpleModal Login | 39 | 50 | 12 | 800 | Unsafe printing function | ||
| #180 | Taxonomy Filter | 41 | 143 | 40 | 800 | Output is not escaped | ||
| #181 | Thin Out Revisions | 40 | 93 | 35 | 800 | Non Singular String Literal Domain | ||
| #182 | Username | 77 | 5 | 8 | 800 | Deprecated function: screen_icon | ||
| #183 | Webdzier Companion | 32 | 539 | 89 | 800 | Text Domain Mismatch | ||
| #184 | whatwedo ACF Cleaner | 61 | 8 | 20 | 800 | Input is not validated | ||
| #185 | Wpazure Kit | 44 | 136 | 140 | 800 | Missing direct file access protection | ||
| #186 | Change Administrator Email Address | 71 | 12 | 9 | 700 | Output is not escaped | ||
| #187 | Better User Search | 39 | 24 | 44 | 700 | SQL query is not prepared | ||
| #188 | Custom Posts Per Page Reloaded | 66 | 40 | 3 | 700 | Text Domain Mismatch | ||
| #189 | Dashboard quick links widget | 49 | 22 | 16 | 700 | Output is not escaped | ||
| #190 | PostLinks | 38 | 107 | 10 | 700 | Output is not escaped | ||
| #191 | Update Notifier | 86 | 8 | 1 | 700 | Output is not escaped | ||
| #192 | WP Login Timeout Settings | 54 | 27 | 7 | 700 | Output is not escaped | ||
| #193 | Admin Notice | 86 | 7 | 1 | 600 | Output is not escaped | ||
| #194 | Chap Secure Password Login | 72 | 13 | 7 | 600 | Input is not validated | ||
| #195 | Clean WP Admin Menu | 74 | 19 | 13 | 600 | Non Singular String Literal Domain | ||
| #196 | Collapsible Categories in the Dashboard | 98 | 3 | 0 | 600 | Missing direct file access protection | ||
| #197 | Dashboard Notes | 42 | 27 | 34 | 600 | Missing Arg Domain | ||
| #198 | Default Media Uploader View | 98 | 3 | 1 | 600 | Missing direct file access protection | ||
| #199 | Flexible Layout Preview Image for ACF | 99 | 1 | 1 | 600 | outdated tested upto header | ||
| #200 | Fusion Page Builder : Extension – Gallery | 42 | 29 | 30 | 600 | Output is not escaped |