Most Improved Security WordPress Plugins

137 indexed plugins

Plugins

137

Active Installs

27m+

Average Score

48

Audited

137

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#1Admin Menu Editor32159233300k+Non-prefixed global variable
#2Advanced Access Manager – Access Governance for WordPress3284962100k+Output is not escaped
#3Advanced Country Blocker4023772k+Exception output is not escaped
#4Advanced IP Blocker4094442k+Exception output is not escaped
#5All-In-One Security (AIOS) – Security and Firewall245521,2281m+Non-prefixed global variable
#6Titan Anti-spam & Security – Brute Force Protection, 2FA & Spam Filter315719650k+Nonce verification recommended
#7App for Cloudflare®981011k+wp function not compatible with requires wp
#8Activity Log – Monitor & Record User Changes3881149200k+Nonce verification recommended
#9Login by Auth0373078210k+Text Domain Mismatch
#10Banhammer – Monitor Site Traffic, Block Bad Users and Bots371041741k+Output is not escaped
#11Kadence Security – Password, Two Factor Authentication, and Brute Force Protection231,053967700k+Missing Translators Comment
#12Blackhole for Bad Bots391236930k+Output is not escaped
#13BBQ Firewall – Fast & Powerful Firewall Security441717100k+Output is not escaped
#14BotBlocker Security – Firewall & Bot Protection9953k+Non-prefixed constant
#15Brozzme DB Prefix & Tools Addons3524429k+Request data is not unslashed
#16BulletProof Security05,0484,94920k+Output is not escaped
#17Captcha by BestWebSoft – Advanced Spam Protection, Math & OCR-Friendly Captcha for Site Forms2249329510k+Text Domain Mismatch
#18AntiSpam for Contact Form 78614810k+Text Domain Mismatch
#19CloudSecure WP Security2974350100k+Request data is not unslashed
#20Companion Auto Update3315929850k+Direct Query
#21CrowdSec351301192k+Output is not escaped
#22Content Security Policy Manager681922k+Output is not escaped
#23OpenID Connect Generic Client7395910k+Non-prefixed hook name
#24Dam Spam10011k+unexpected markdown file
#25DefendWP Firewall39162033k+Non-prefixed global variable
#26Defender Security – Malware Scanner, Login Security & Firewall2430651880k+Non-prefixed namespace
#27Disable WP Registration Page Spam775121k+Nonce verification recommended
#28Expire User Passwords353153k+Nonce verification recommended
#29Exploit Scanner37251308k+Non-prefixed global variable
#30Forget Spam Comment6751010k+Input is not sanitized
#31Lock Down Admin4230203k+Unsafe printing function
#32GD Security Headers254075211k+Output is not escaped
#33The GDPR Framework By Data443231,28751710k+Short PHP open tag found
#34Block IPs for Gravity Forms508361k+Request data is not unslashed
#35Google Authenticator41396520k+Output is not escaped
#36Anti-Malware Security and Brute-Force Firewall22544965100k+Output is not escaped
#37WP Ghost (Hide My WP Ghost) – Security & Firewall856373100k+Non-prefixed global variable
#38Hostinger Tools8114223m+wp function not compatible with requires wp
#39HSTS Ready853113k+Input is not validated
#40Inactive Logout64307110k+Non-prefixed global variable
#41IP Geo Block233995899k+Output is not escaped
#42Kadence Central – Site Management, Backups, Security, and Reporting2646221330k+Text Domain Mismatch
#43InfiniteWP Client222,2861,812200k+Exception output is not escaped
#44Jetpack – WP Security, Backup, Speed, & Growth232,8211,3033m+Text Domain Mismatch
#45Jetpack Protect30657217100k+Text Domain Mismatch
#46My Private Site3142519020k+Text Domain Mismatch
#47Keyring352332031k+Output is not escaped
#48Limit Attempts by BestWebSoft – WordPress Anti-Bot and Security Plugin for Login and Forms245635484k+Text Domain Mismatch
#49Limit Login Attempts408138300k+Output is not escaped
#50Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention256216021m+Unsafe printing function