Most Improved Security WordPress Plugins

188 indexed plugins

Plugins

188

Active Installs

27m+

Average Score

53

Audited

185

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#151Wordfence Security – Firewall, Malware Scan, and Login Security211,5922,9735m+Output is not escaped
#152Wordfence Login Security2524841870k+Output is not escaped
#153ManageWP Worker225075651m+Non-prefixed class
#154iControlWP4745591k+Missing direct file access protection
#155Access Areas for WordPress351795400Direct Query
#156WP Admin Basic Auth87562k+Input is not sanitized
#157WP Anti-Clickjack664424k+Nonce verification recommended
#158WP Author Security424013500Output is not escaped
#159WP Author Slug961662k+Text Domain Mismatch
#160WP Disable Site Health93441k+trademarked term
#161WP EXtra – One Click Optimize334141017k+Missing Arg Domain
#162WP fail2ban – Advanced Security327515360k+Dynamic hook name
#163WP fail2ban Add-on for Contact Form 7851018800Non-prefixed constant
#164WP fail2ban Add-on for Gravity Forms851018600Non-prefixed constant
#165WP Fail2Ban Redux821107k+trademarked term
#166WP Fingerprint4234479k+Direct Query
#167WP Hide & Security Enhancer2712437550k+Input is not sanitized
#168WP Login Door641911400Output is not escaped
#169Malcure Malware Shield — Removal, Repair, Monitor9575610k+wp function not compatible with requires wp
#170ReCaptcha Integration for WordPress3760669k+Output is not escaped
#171Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning231,11820240k+Missing Translators Comment
#172Subresource Integrity (SRI) Manager352694900Request data is not unslashed
#173WP-WebAuthn229573962k+Exception output is not escaped
#174WP fail2ban Blocklist3661633k+SQL query is not prepared
#175WPFront User Role Editor3533357830k+Output is not escaped
#176WPMasterToolKit (WPMTK) – All in one plugin99144k+trademarked term
#177WPOrLogin – Custom Login, Social Login, Limit Attempts, Hide Login & reCAPTCHA304842222k+Unsafe printing function
#178WPS Cleaner3043049120k+Output is not escaped
#179WPS Limit Login3915276100k+Output is not escaped
#180WPScan – WordPress Security Scanner215272658k+Text Domain Mismatch
#181WPVulnerability96410k+trademarked term
#182WebTotem Security211,110213900Text Domain Mismatch
#183XO Security945330k+wp function not compatible with requires wp
#184Zero Spam for WordPress347939320k+Non-prefixed global variable
#185htaccess protect392833800Input is not validated