Malware WordPress Plugins That Need Review

14 indexed plugins

Plugins

14

Active Installs

10m+

Average Score

36

Audited

14

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#1Wordfence Security – Firewall, Malware Scan, and Login Security211,5922,9735m+Output is not escaped
#2NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall221,2652,065100k+Non-prefixed global variable
#3NinjaScanner – Virus & Malware scan2259655130k+Non-prefixed global variable
#4Kadence Security – Password, Two Factor Authentication, and Brute Force Protection231,053967700k+Missing Translators Comment
#5Jetpack – WP Security, Backup, Speed, & Growth232,8211,3033m+Text Domain Mismatch
#6SecuPress with Simple SSL – Simple and Performant Security231,6961,59040k+Non-prefixed global variable
#7Defender Security – Malware Scanner, Login Security & Firewall2430651880k+Non-prefixed namespace
#8Security Plugin, Firewall & Malware Scanner with Auto Removal241,19277030k+Output is not escaped
#9Jetpack VaultPress287136210k+Missing nonce verification
#10Security Ninja – WordPress Security & Firewall291493477k+Direct Query
#11Jetpack Protect30657217100k+Text Domain Mismatch
#12DefendWP Firewall39162033k+Non-prefixed global variable
#13Sucuri Security – Auditing, Malware Scanner and Security Hardening94525600k+Missing direct file access protection
#14AntiVirus992130k+Missing direct file access protection