Best Security WordPress Plugins

137 indexed plugins

Plugins

137

Active Installs

27m+

Average Score

47

Audited

122

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#1Login Security Captcha100010k+No open findings
#2Stop XML-RPC Attacks10016k+Non Prefixed Class Found
#3BotBlocker Security – Firewall & Bot Protection9953k+Non Prefixed Constant Found
#4Protect Uploads992140k+missing direct file access protection
#5Stop User Enumeration991150k+Dynamic Hookname Found
#6WPMasterToolKit (WPMTK) – All in one plugin99144k+trademarked term
#7Manage XML-RPC98316k+file system operations is writable
#8Prevent XSS Vulnerability981016k+Missing Arg Domain
#9Safe SVG98741m+Missing Arg Domain
#10WP Author Slug961662k+Text Domain Mismatch
#11WPVulnerability96410k+trademarked term
#12MilesWeb Tools9544910k+Non Prefixed Variable Found
#13Malcure Malware Shield — Removal, Repair, Monitor9575610k+wp function not compatible with requires wp
#14Stop Spammers Classic94185130k+wp function not compatible with requires wp
#15Sucuri Security – Auditing, Malware Scanner and Security Hardening94525600k+missing direct file access protection
#16XO Security945330k+wp function not compatible with requires wp
#17Restricted Site Access91141110k+Missing Arg Domain
#18Password Strength Settings for WooCommerce8917610k+Missing Arg Domain
#19WP Admin Basic Auth87562k+Input Not Sanitized
#20AntiSpam for Contact Form 78614810k+Text Domain Mismatch
#21WP Ghost (Hide My WP Ghost) – Security & Firewall856373100k+Non Prefixed Variable Found
#22HSTS Ready853113k+Input Not Validated
#23Salt Shaker8515136k+Interpolated Not Prepared
#24Simple Automatic Updates851812k+Missing Translators Comment
#25WP Fail2Ban Redux821107k+trademarked term
#26Hostinger Tools8114223m+wp function not compatible with requires wp
#27Smart Passworded Pages801182k+wp function not compatible with requires wp
#28Melapress File Monitor8016906k+Non Prefixed Variable Found
#29OpenID Connect Generic Client7395910k+Non Prefixed Hookname Found
#30Simple Login Captcha70201910k+date date
#31Simple Login Lockdown691364k+Output Not Escaped
#32Content Security Policy Manager681922k+Output Not Escaped
#33Protection Against DDoS682253k+Output Not Escaped
#34Forget Spam Comment675109k+Input Not Sanitized
#35WP Anti-Clickjack664424k+Recommended
#36Inactive Logout64307110k+Non Prefixed Variable Found
#37Meta Generator and Version Info Remover52202810k+Non Prefixed Function Found
#38TrustedSite50291420k+Output Not Escaped
#39LWS Hide Login4555820k+Missing Unslash
#40BBQ Firewall – Fast & Powerful Firewall Security441717100k+Output Not Escaped
#41User Role Editor43117145700k+Output Not Escaped
#42Lock Down Admin4230203k+Unsafe Printing Function
#43Login No Captcha reCAPTCHA42452460k+Unsafe Printing Function
#44Two Factor421870100k+Recommended
#45WP Fingerprint4234479k+Direct Query
#46Google Authenticator41396520k+Output Not Escaped
#47Lockdown WP Admin41205010k+Missing Unslash
#48Log cleaner for Solid Security4165478k+Text Domain Mismatch
#49Advanced Country Blocker4023772k+Exception Not Escaped
#50Limit Login Attempts408138300k+Output Not Escaped