Most Improved Security WordPress Plugins

188 indexed plugins

Plugins

188

Active Installs

27m+

Average Score

53

Audited

182

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#101Protect Uploads992140k+Missing direct file access protection
#102Protection Against DDoS682253k+Output is not escaped
#103Proxy & VPN Blocker4210721k+Nonce verification recommended
#104Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)195413853m+Missing Translators Comment
#105REST XML-RPC Data Checker5414451k+Input is not sanitized
#106Restrict Usernames Emails Characters323273671k+Output is not escaped
#107Restricted Site Access91141110k+Missing Arg Domain
#108RSFirewall!245635214k+Output is not escaped
#109Rublon Multi-Factor Authentication (MFA)30216160500Output is not escaped
#110Safe SVG98741m+Missing Arg Domain
#111Salt Shaker8515136k+Interpolated SQL is not prepared
#112SameSite Cookies9832800Missing direct file access protection
#113SecuPress with Simple SSL – Simple and Performant Security231,6961,59040k+Non-prefixed global variable
#114Security Header Generator871020500Non Singular String Literal Text
#115Security Plugin, Firewall & Malware Scanner with Auto Removal241,19176930k+Output is not escaped
#116Security Ninja – WordPress Security & Firewall291493477k+Direct Query
#117Security Ninja For MainWP4724671500Text Domain Mismatch
#118Security.txt Manager3510500Hidden files included
#119SP Move Login268812156k+Text Domain Mismatch
#120Security Optimizer – The All-In-One Protection Plugin3540821m+Request data is not unslashed
#121Simple Automatic Updates851812k+Missing Translators Comment
#122Simple Login Captcha70201910k+date date
#123Simple Login Lockdown691364k+Output is not escaped
#124Simply Static – The Static Site Generator2516344830k+Non-prefixed hook name
#125SiteGuard WP Plugin24362345500k+Output is not escaped
#126Smart Passworded Pages801182k+wp function not compatible with requires wp
#127SMNTCS Disable REST API User Endpoints35806k+Hidden files included
#128Staatic – Static Site Generator for WordPress314201952k+SQL query is not prepared
#129Stop Spammers Classic94185130k+wp function not compatible with requires wp
#130Stop User Enumeration991150k+Dynamic hook name
#131Stop XML-RPC Attacks10016k+Non-prefixed class
#132Sucuri Security – Auditing, Malware Scanner and Security Hardening94525600k+Missing direct file access protection
#133TrustedSite50291420k+Output is not escaped
#134Two Factor421870100k+Nonce verification recommended
#135WebAuthn Provider for Two Factor916141k+Missing Arg Domain
#136underConstruction36986040k+Unsafe printing function
#137Universal Honey Pot4023941k+Missing nonce verification
#138Update Notifier8681700Output is not escaped
#139SX User Name Security46429900Output is not escaped
#140User Role Editor43117145700k+Output is not escaped
#141User Session Control433121700Output is not escaped
#142Jetpack VaultPress287136210k+Missing nonce verification
#143Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…10011k+mismatched plugin name
#144Virusdie | One-click website security39149662k+Output is not escaped
#145Password Strength Settings for WooCommerce8917610k+Missing Arg Domain
#146Melapress File Monitor8016906k+Non-prefixed global variable
#147Remove XML-RPC Methods10001k+No open findings
#148WEDOS | Protection & Cache Performance9823800ABSPATHDetected
#149Whitelist IP For Limit Login Attempts481812600Output is not escaped
#150Wordfence Security – Firewall, Malware Scan, and Login Security211,5922,9735m+Output is not escaped