Most Downloaded Security WordPress Plugins

144 indexed plugins

Plugins

144

Active Installs

27m+

Average Score

48

Audited

137

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#1Jetpack – WP Security, Backup, Speed, & Growth232,8211,3033m+Text Domain Mismatch
#2Wordfence Security – Firewall, Malware Scan, and Login Security211,5922,9735m+Output is not escaped
#3Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)195413853m+Missing Translators Comment
#4Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention256186051m+Unsafe printing function
#5MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites383136700k+Non-prefixed hook name
#6Kadence Security – Password, Two Factor Authentication, and Brute Force Protection231,053967700k+Missing Translators Comment
#7All-In-One Security (AIOS) – Security and Firewall245521,2281m+Non-prefixed global variable
#8Sucuri Security – Auditing, Malware Scanner and Security Hardening94525600k+Missing direct file access protection
#9Security Optimizer – The All-In-One Protection Plugin3540821m+Request data is not unslashed
#10Loginizer258145041m+Output is not escaped
#11ManageWP Worker225075651m+Non-prefixed class
#12User Role Editor43117145700k+Output is not escaped
#13Hostinger Tools8114223m+wp function not compatible with requires wp
#14Safe SVG98741m+Missing Arg Domain
#15Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning231,11820240k+Missing Translators Comment
#16InfiniteWP Client222,2861,812200k+Exception output is not escaped
#17Admin Menu Editor32159233300k+Non-prefixed global variable
#18Anti-Malware Security and Brute-Force Firewall22544965100k+Output is not escaped
#19Advanced Access Manager – Access Governance for WordPress3284962100k+Output is not escaped
#20SiteGuard WP Plugin24362345500k+Output is not escaped
#21BulletProof Security05,0484,94920k+Output is not escaped
#22Companion Auto Update3315929850k+Direct Query
#23Defender Security – Malware Scanner, Login Security & Firewall2430651880k+Non-prefixed namespace
#24Activity Log – Monitor & Record User Changes3881149200k+Nonce verification recommended
#25Titan Anti-spam & Security – Brute Force Protection, 2FA & Spam Filter315719650k+Nonce verification recommended
#26WP Hide & Security Enhancer2712437550k+Input is not sanitized
#27BBQ Firewall – Fast & Powerful Firewall Security441717100k+Output is not escaped
#28NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall221,2652,065100k+Non-prefixed global variable
#29Security Plugin, Firewall & Malware Scanner with Auto Removal241,19176930k+Output is not escaped
#30Stop Spammers Classic94185130k+wp function not compatible with requires wp
#31WP Ghost (Hide My WP Ghost) – Security & Firewall856373100k+Non-prefixed global variable
#32Jetpack Protect30657217100k+Text Domain Mismatch
#33Limit Login Attempts408138300k+Output is not escaped
#34Jetpack VaultPress287136210k+Missing nonce verification
#35WP fail2ban – Advanced Security327515360k+Dynamic hook name
#36Simply Static – The Static Site Generator2516344830k+Non-prefixed hook name
#37MainWP Dashboard: Self-hosted WordPress Management for Agencies319531720k+Interpolated SQL is not prepared
#38underConstruction36986040k+Unsafe printing function
#39Two Factor421870100k+Nonce verification recommended
#40Protect Uploads992140k+Missing direct file access protection
#41Zero Spam for WordPress347939320k+Non-prefixed global variable
#42Kadence Central – Site Management, Backups, Security, and Reporting2646221330k+Text Domain Mismatch
#43Login No Captcha reCAPTCHA42452460k+Unsafe printing function
#44Stop User Enumeration991150k+Dynamic hook name
#45Wordfence Login Security2524841870k+Output is not escaped
#46SecuPress with Simple SSL – Simple and Performant Security231,6961,59040k+Non-prefixed global variable
#47Restricted Site Access91141110k+Missing Arg Domain
#48Modular DS: Monitor, update, and backup multiple websites211618140k+Exception output is not escaped
#49Login With Ajax – Fast Logins, 2FA, Redirects2362352010k+Output is not escaped
#50Exploit Scanner37251308k+Non-prefixed global variable