Most Installed Page WordPress Plugins
50 indexed plugins
Plugins
50
Active Installs
960k+
Average Score
63
Audited
50
Most Installed
| Rank | Plugin | Score | Errors | Warnings | Installs | Updated | Top Issue |
|---|---|---|---|---|---|---|---|
| #1 | Post Type Switcher | 75 | 3 | 18 | 200k+ | Direct Query | |
| #2 | Page Links To | 38 | 31 | 40 | 100k+ | Unsafe printing function | |
| #3 | Simple Page Ordering | 82 | 11 | 9 | 100k+ | Missing Arg Domain | |
| #4 | Display Posts – Easy lists, grids, navigation, and more | 92 | 11 | 23 | 80k+ | Non-prefixed function | |
| #5 | Fast Page & Post Duplicator | 55 | 12 | 25 | 60k+ | Direct Query | |
| #6 | Pages with category and tag | 100 | 0 | 60k+ | No open findings | ||
| #7 | CMS Tree Page View | 38 | 135 | 104 | 50k+ | Output is not escaped | |
| #8 | Reveal IDs | 35 | 23 | 13 | 40k+ | Output is not escaped | |
| #9 | VK Link Target Controller | 65 | 13 | 10 | 30k+ | Output is not escaped | |
| #10 | WP Admin UI Customize | 30 | 629 | 390 | 30k+ | Non-prefixed global variable | |
| #11 | Add Category to Pages | 97 | 3 | 2 | 20k+ | Missing direct file access protection | |
| #12 | WP-Paginate | 35 | 37 | 55 | 20k+ | Input is not validated | |
| #13 | Admin Menu Tree Page View | 43 | 17 | 69 | 10k+ | Nonce verification recommended | |
| #14 | Canvas | 89 | 19 | 112 | 10k+ | Non-prefixed global variable | |
| #15 | Duplicate PP | 90 | 8 | 10k+ | Non-prefixed constant | ||
| #16 | HTML Page Sitemap (Block and Shortcode) | 98 | 3 | 4 | 10k+ | wp function not compatible with requires wp | |
| #17 | Link Library | 20 | 1,941 | 1,397 | 10k+ | Unsafe printing function | |
| #18 | Search and Replace | 70 | 7 | 9 | 10k+ | Input is not sanitized | |
| #19 | Iptanus File Upload | 24 | 509 | 1,325 | 10k+ | Non-prefixed function | |
| #20 | Attachments | 38 | 238 | 66 | 8k+ | Unsafe printing function | |
| #21 | Posts List | 77 | 11 | 15 | 7k+ | Non-prefixed hook name | |
| #22 | Redirector | 40 | 48 | 32 | 7k+ | Output is not escaped | |
| #23 | WP Theme Test | 40 | 21 | 39 | 7k+ | Input is not sanitized | |
| #24 | Disable Author Pages | 48 | 23 | 5 | 6k+ | Unsafe printing function | |
| #25 | Posts Like Dislike | 42 | 157 | 39 | 6k+ | Non Singular String Literal Domain | |
| #26 | Front Page Category | 97 | 4 | 2 | 5k+ | Missing direct file access protection | |
| #27 | Remove noreferrer | 79 | 17 | 14 | 5k+ | Missing Arg Domain | |
| #28 | Admin Collapse Subpages | 82 | 4 | 12 | 4k+ | Nonce verification recommended | |
| #29 | Companion Revision Manager – Revision Control | 42 | 18 | 28 | 4k+ | Unsafe printing function | |
| #30 | Autoremove Attachments | 98 | 2 | 5 | 3k+ | Non-prefixed function | |
| #31 | HeadSpace2 SEO | 22 | 940 | 360 | 3k+ | Text Domain Mismatch | |
| #32 | Page Excerpt | 81 | 11 | 1 | 3k+ | Missing Arg Domain | |
| #33 | Pages In Widgets | 41 | 131 | 6 | 3k+ | Output is not escaped | |
| #34 | Custom Post Exporter | 99 | 7 | 1 | 3k+ | Text Domain Mismatch | |
| #35 | Disable Title | 72 | 20 | 15 | 2k+ | Text Domain Mismatch | |
| #36 | Embed Iframe | 69 | 25 | 6 | 2k+ | wp function not compatible with requires wp | |
| #37 | Enhanced Category Pages | 55 | 23 | 25 | 2k+ | Direct Query | |
| #38 | HiFi (Head Injection, Foot Injection) | 66 | 13 | 11 | 2k+ | Output is not escaped | |
| #39 | Multiple Post Passwords | 61 | 13 | 15 | 2k+ | Output is not escaped | |
| #40 | Page in Widget | 64 | 26 | 0 | 2k+ | Output is not escaped | |
| #41 | Post Lists View Custom | 33 | 462 | 150 | 2k+ | Missing Arg Domain | |
| #42 | Quick Bulk Post & Page Creator | 55 | 43 | 1 | 2k+ | Text Domain Mismatch | |
| #43 | Smart Passworded Pages | 80 | 11 | 8 | 2k+ | wp function not compatible with requires wp | |
| #44 | Smooth Page Scroll Up/Down Buttons | 91 | 1 | 5 | 2k+ | Non-prefixed function | |
| #45 | Custom 404 Error Page | 82 | 12 | 3 | 1k+ | Text Domain Mismatch | |
| #46 | WordPress.com Editing Toolkit | 67 | 52 | 90 | 1k+ | Missing direct file access protection | |
| #47 | PRyC WP: Add custom content to post and page (top/bottom) | 61 | 63 | 7 | 1k+ | Text Domain Mismatch | |
| #48 | Simple Revision Control | 41 | 34 | 43 | 1k+ | Dynamic hook name | |
| #49 | Ultimate Under Construction | 75 | 22 | 2 | 1k+ | Non Enqueued Script | |
| #50 | Which Template | 98 | 4 | 1 | 1k+ | wp function not compatible with requires wp |