Most Improved Security WordPress Plugins
190 indexed plugins
Plugins
190
Active Installs
27m+
Average Score
53
Audited
190
Most Improved
| Rank | Plugin | Score | Errors | Warnings | Installs | Added | Updated | Top Issue |
|---|---|---|---|---|---|---|---|---|
| #1 | Proxy & VPN Blocker | 44 | 74 | 1k+ | Nonce verification recommended | |||
| #2 | WEDOS | Protection & Cache Performance | 100 | 1 | 800 | trademarked term | |||
| #3 | Hostinger Tools | 82 | 13 | 22 | 3m+ | wp function not compatible with requires wp | ||
| #4 | Injection Guard | 37 | 86 | 45 | 1k+ | Unsafe printing function | ||
| #5 | WP Helper Premium | 24 | 3,908 | 1,515 | 1k+ | Text Domain Mismatch | ||
| #6 | Admin Menu Editor | 32 | 159 | 233 | 300k+ | Non-prefixed global variable | ||
| #7 | Advanced Access Manager – Access Governance for WordPress | 32 | 849 | 62 | 100k+ | Output is not escaped | ||
| #8 | Advanced Country Blocker | 40 | 23 | 77 | 2k+ | Exception output is not escaped | ||
| #9 | Advanced IP Blocker | 40 | 94 | 43 | 2k+ | Exception output is not escaped | ||
| #10 | All-In-One Security (AIOS) – Security and Firewall | 24 | 552 | 1,228 | 1m+ | Non-prefixed global variable | ||
| #11 | Titan Anti-spam & Security – Brute Force Protection, 2FA & Spam Filter | 31 | 57 | 196 | 50k+ | Nonce verification recommended | ||
| #12 | App for Cloudflare® | 98 | 10 | 1 | 1k+ | wp function not compatible with requires wp | ||
| #13 | Activity Log – Monitor & Record User Changes | 38 | 81 | 149 | 200k+ | Nonce verification recommended | ||
| #14 | Atomic Edge Security – Firewall, Malware Scan and Login Security | 40 | 12 | 184 | 700 | Non-prefixed global variable | ||
| #15 | Login by Auth0 | 37 | 307 | 82 | 10k+ | Text Domain Mismatch | ||
| #16 | Auto SRI | 92 | 4 | 1 | 500 | wp function not compatible with requires wp | ||
| #17 | Banhammer – Monitor Site Traffic, Block Bad Users and Bots | 37 | 104 | 174 | 1k+ | Output is not escaped | ||
| #18 | Kadence Security – Password, Two Factor Authentication, and Brute Force Protection | 23 | 1,053 | 967 | 700k+ | Missing Translators Comment | ||
| #19 | Blackhole for Bad Bots | 39 | 123 | 69 | 30k+ | Output is not escaped | ||
| #20 | BBQ Firewall – Fast & Powerful Firewall Security | 44 | 17 | 17 | 100k+ | Output is not escaped | ||
| #21 | Block wp-login | 98 | 16 | 3 | 600 | wp function not compatible with requires wp | ||
| #22 | Booter – Bots & Crawlers Manager | 68 | 81 | 7k+ | Non-prefixed global variable | |||
| #23 | BotBlocker Security – Firewall & Bot Protection | 99 | 5 | 3k+ | Non-prefixed constant | |||
| #24 | Brozzme DB Prefix & Tools Addons | 35 | 24 | 42 | 10k+ | Request data is not unslashed | ||
| #25 | BulletProof Security | 0 | 5,048 | 4,949 | 20k+ | Output is not escaped | ||
| #26 | Captcha by BestWebSoft – Advanced Spam Protection, Math & OCR-Friendly Captcha for Site Forms | 22 | 493 | 295 | 10k+ | Text Domain Mismatch | ||
| #27 | AntiSpam for Contact Form 7 | 86 | 14 | 8 | 10k+ | Text Domain Mismatch | ||
| #28 | CloudGuard | 41 | 41 | 13 | 1k+ | Output is not escaped | ||
| #29 | CloudSecure WP Security | 29 | 74 | 350 | 100k+ | Request data is not unslashed | ||
| #30 | Comment Form CSRF Protection | 70 | 7 | 10 | 500 | Request data is not unslashed | ||
| #31 | Companion Auto Update | 33 | 159 | 298 | 50k+ | Direct Query | ||
| #32 | Control XML-RPC publishing | 92 | 7 | 0 | 400 | Text Domain Mismatch | ||
| #33 | CrowdSec | 35 | 130 | 119 | 2k+ | Output is not escaped | ||
| #34 | Content Security Policy Manager | 68 | 19 | 2 | 2k+ | Output is not escaped | ||
| #35 | WebDefender Security – Protection & AntiSpam | 70 | 176 | 61 | 1k+ | wp function not compatible with requires wp | ||
| #36 | OpenID Connect Generic Client | 73 | 9 | 59 | 10k+ | Non-prefixed hook name | ||
| #37 | Dam Spam | 100 | 1 | 1k+ | unexpected markdown file | |||
| #38 | DefendWP Firewall | 39 | 16 | 203 | 3k+ | Non-prefixed global variable | ||
| #39 | Defender Security – Malware Scanner, Login Security & Firewall | 24 | 306 | 518 | 80k+ | Non-prefixed namespace | ||
| #40 | Disable File Editor | 97 | 3 | 2 | 500 | outdated tested upto header | ||
| #41 | Disable Registration Page | 88 | 4 | 6 | 400 | Text Domain Mismatch | ||
| #42 | Disable WP Registration Page Spam | 77 | 5 | 12 | 1k+ | Nonce verification recommended | ||
| #43 | Easy Basic Authentication – Add basic auth to site or admin area | 46 | 14 | 28 | 600 | Input is not sanitized | ||
| #44 | Edit Lock | 41 | 47 | 22 | 500 | Non Singular String Literal Domain | ||
| #45 | Expire User Passwords | 35 | 3 | 15 | 3k+ | Nonce verification recommended | ||
| #46 | Exploit Scanner | 37 | 25 | 130 | 8k+ | Non-prefixed global variable | ||
| #47 | Forget Spam Comment | 67 | 5 | 10 | 10k+ | Input is not sanitized | ||
| #48 | Lock Down Admin | 42 | 30 | 20 | 3k+ | Unsafe printing function | ||
| #49 | GD Security Headers | 25 | 407 | 521 | 1k+ | Output is not escaped | ||
| #50 | The GDPR Framework By Data443 | 23 | 1,287 | 517 | 10k+ | Short PHP open tag found |