Most Downloaded Security WordPress Plugins

188 indexed plugins

Plugins

188

Active Installs

27m+

Average Score

53

Audited

188

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#101Simple Login Captcha70201910k+date date
#102Staatic – Static Site Generator for WordPress314201952k+SQL query is not prepared
#103Plugin Security Scanner8499800Output is not escaped
#104Smart Passworded Pages801182k+wp function not compatible with requires wp
#105Manage XML-RPC98316k+file system operations is writable
#106WPMasterToolKit (WPMTK) – All in one plugin99144k+trademarked term
#107Simple Login Lockdown691364k+Output is not escaped
#108CrowdSec351301192k+Output is not escaped
#109Expire User Passwords353153k+Nonce verification recommended
#110Advanced IP Blocker4094442k+Exception output is not escaped
#111WPOrLogin – Custom Login, Social Login, Limit Attempts, Hide Login & reCAPTCHA304842222k+Unsafe printing function
#112Banhammer – Monitor Site Traffic, Block Bad Users and Bots371041741k+Output is not escaped
#113Logbook4033592k+Nonce verification recommended
#114Protection Against DDoS682253k+Output is not escaped
#115WP Anti-Clickjack664424k+Nonce verification recommended
#116Restrict Usernames Emails Characters323273671k+Output is not escaped
#117WebAuthn Provider for Two Factor916141k+Missing Arg Domain
#118WP Author Slug961662k+Text Domain Mismatch
#119No-Bot Registration40112422k+Unsafe printing function
#120Virusdie | One-click website security39149662k+Output is not escaped
#121WP Fingerprint4234479k+Direct Query
#122App for Cloudflare®981011k+wp function not compatible with requires wp
#123Content Security Policy Manager681922k+Output is not escaped
#124HSTS Ready853113k+Input is not validated
#125Injection Guard3687451k+Unsafe printing function
#126GD Security Headers254075211k+Output is not escaped
#127Access Areas for WordPress351795400Direct Query
#128RSFirewall!245635214k+Output is not escaped
#129SMNTCS Disable REST API User Endpoints35806k+Hidden files included
#130CloudGuard4141131k+Output is not escaped
#131Stop XML-RPC Attacks10016k+Non-prefixed class
#132WP fail2ban Blocklist3661633k+SQL query is not prepared
#133Passwords Evolved4526171k+Output is not escaped
#134Password Strength for WooCommerce98301k+Missing direct file access protection
#135WP-WebAuthn229573962k+Exception output is not escaped
#136Security Header Generator871020500Non Singular String Literal Text
#137Lock Down Admin4230203k+Unsafe printing function
#138WP PGP Encrypted Emails356339400Output is not escaped
#139Host Header Injection Fix7098400Output is not escaped
#140SameSite Cookies9832800Missing direct file access protection
#141MilesWeb Tools9544910k+Non-prefixed global variable
#142Simple Automatic Updates851812k+Missing Translators Comment
#143Whitelist IP For Limit Login Attempts481812600Output is not escaped
#144Control XML-RPC publishing9270400Text Domain Mismatch
#145Block wp-login98163600wp function not compatible with requires wp
#146Protect Login952619600Missing direct file access protection
#147SX User Name Security46429900Output is not escaped
#148Security Ninja For MainWP4724671500Text Domain Mismatch
#149Subresource Integrity (SRI) Manager352694900Request data is not unslashed
#150Update Notifier8681700Output is not escaped