Most Installed Malware WordPress Plugins

18 indexed plugins

Plugins

18

Active Installs

10m+

Average Score

40

Audited

18

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#1Wordfence Security – Firewall, Malware Scan, and Login Security211,5922,9735m+Output is not escaped
#2Jetpack – WP Security, Backup, Speed, & Growth232,8211,3033m+Text Domain Mismatch
#3Kadence Security – Password, Two Factor Authentication, and Brute Force Protection231,053967700k+Missing Translators Comment
#4Sucuri Security – Auditing, Malware Scanner and Security Hardening94525600k+Missing direct file access protection
#5Jetpack Protect30657217100k+Text Domain Mismatch
#6NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall221,2662,059100k+Non-prefixed global variable
#7Defender Security – Malware Scanner, Login Security & Firewall2430651880k+Non-prefixed namespace
#8SecuPress with Simple SSL – Simple and Performant Security231,6961,59040k+Non-prefixed global variable
#9AntiVirus992130k+Missing direct file access protection
#10NinjaScanner – Virus & Malware scan2259655130k+Non-prefixed global variable
#11Security Plugin, Firewall & Malware Scanner with Auto Removal241,19176930k+Output is not escaped
#12Jetpack VaultPress287136210k+Missing nonce verification
#13Security Ninja – WordPress Security & Firewall291493477k+Direct Query
#14DefendWP Firewall39162033k+Non-prefixed global variable
#15Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…10011k+mismatched plugin name
#16Atomic Edge Security – Firewall, Malware Scan and Login Security4012184600Non-prefixed global variable
#17WPDoctor Malware Scanner & Vulnerability Checker & IP blocker with Hack monitor Lite31133438600Non-prefixed global variable
#18Security Ninja For MainWP4724671500Text Domain Mismatch