Most Improved Security WordPress Plugins

188 indexed plugins

Plugins

188

Active Installs

27m+

Average Score

52

Audited

175

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#51Injection Guard3687451k+Unsafe printing function
#52IP Geo Block233995899k+Output is not escaped
#53Kadence Central – Site Management, Backups, Security, and Reporting2646221330k+Text Domain Mismatch
#54InfiniteWP Client222,2861,812200k+Exception output is not escaped
#55JetHost Total Care – Security & Enhancements451085800Direct Query
#56Jetpack – WP Security, Backup, Speed, & Growth232,8211,3033m+Text Domain Mismatch
#57Jetpack Protect30657217100k+Text Domain Mismatch
#58My Private Site3142519020k+Text Domain Mismatch
#59Keyring352332031k+Output is not escaped
#60LH HSTS78312600Input is not sanitized
#61Limit Attempts by BestWebSoft – WordPress Anti-Bot and Security Plugin for Login and Forms245635484k+Text Domain Mismatch
#62Limit Login Attempts408138300k+Output is not escaped
#63Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention256186051m+Unsafe printing function
#64Lockdown WP Admin41205010k+Request data is not unslashed
#65Log cleaner for Solid Security4165478k+Text Domain Mismatch
#66Logbook4033592k+Nonce verification recommended
#67Login No Captcha reCAPTCHA42452460k+Unsafe printing function
#68Login Security Captcha100010k+No open findings
#69Login With Ajax – Fast Logins, 2FA, Redirects2362352010k+Output is not escaped
#70Loginizer258145041m+Output is not escaped
#71Logout Clear Cookies9831500Missing direct file access protection
#72LWS Hide Login4555820k+Request data is not unslashed
#73LWS Tools3110413410k+Request data is not unslashed
#74MainWP Dashboard: Self-hosted WordPress Management for Agencies319531720k+Interpolated SQL is not prepared
#75MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites383136700k+Non-prefixed hook name
#76Manage XML-RPC98315k+file system operations is writable
#77Media Vault34115150800Output is not escaped
#78Meta Generator and Version Info Remover52202810k+Non-prefixed function
#79MilesWeb Tools9544910k+Non-prefixed global variable
#80Modular DS: Monitor, update, and backup multiple websites211618140k+Exception output is not escaped
#81NETSENSAI Shield8310161k+Nonce verification recommended
#82Nexter Extension – Security, Performance, Code Snippets & Site Toolkit2519871010k+Nonce verification recommended
#83NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall221,2652,065100k+Non-prefixed global variable
#84NinjaScanner – Virus & Malware scan2259655130k+Non-prefixed global variable
#85No-Bot Registration40112422k+Unsafe printing function
#86No CAPTCHA reCAPTCHA40112264k+Text Domain Mismatch
#87OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA)272715686k+Request data is not unslashed
#88Password Strength for WooCommerce98301k+Missing direct file access protection
#89Passwords Evolved4526171k+Output is not escaped
#90Patchstack – WordPress & Plugins Security2310748940k+Missing nonce verification
#91Plugin Check (PCP)012813210k+Exception output is not escaped
#92Plugin Security Scanner8499800Output is not escaped
#93Prevent Concurrent Logins97210900Non-prefixed function
#94Prevent XSS Vulnerability981016k+Missing Arg Domain
#95Protect Login952619600Missing direct file access protection
#96Protect Uploads992140k+Missing direct file access protection
#97Protection Against DDoS682253k+Output is not escaped
#98Proxy & VPN Blocker4210721k+Nonce verification recommended
#99Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)195413853m+Missing Translators Comment
#100REST XML-RPC Data Checker5414451k+Input is not sanitized