Most Installed Security WordPress Plugins

188 indexed plugins

Plugins

188

Active Installs

27m+

Average Score

53

Audited

188

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#151.htaccess Site Access Control375467800Input is not sanitized
#152JetHost Total Care – Security & Enhancements451085800Direct Query
#153Media Vault34115150800Output is not escaped
#154Plugin Security Scanner8499800Output is not escaped
#155SameSite Cookies9832800Missing direct file access protection
#156WEDOS | Protection & Cache Performance9823800ABSPATHDetected
#157WP fail2ban Add-on for Contact Form 7851018800Non-prefixed constant
#158htaccess protect392833800Input is not validated
#159Update Notifier8681700Output is not escaped
#160User Session Control433121700Output is not escaped
#161Atomic Edge Security – Firewall, Malware Scan and Login Security4012184600Non-prefixed global variable
#162Block wp-login98163600wp function not compatible with requires wp
#163Easy Basic Authentication – Add basic auth to site or admin area461428600Input is not sanitized
#164LH HSTS78312600Input is not sanitized
#165Protect Login952619600Missing direct file access protection
#166Whitelist IP For Limit Login Attempts481812600Output is not escaped
#167WP fail2ban Add-on for Gravity Forms851018600Non-prefixed constant
#168Auto SRI9241500wp function not compatible with requires wp
#169Comment Form CSRF Protection70710500Request data is not unslashed
#170Disable File Editor9732500outdated tested upto header
#171Edit Lock414722500Non Singular String Literal Domain
#172Give – Cloudflare Turnstile3532500Hidden files included
#173Logout Clear Cookies9831500Missing direct file access protection
#174Maestro Connector9774500Missing direct file access protection
#175Rublon Multi-Factor Authentication (MFA)30216160500Output is not escaped
#176Security Header Generator871020500Non Singular String Literal Text
#177Security Ninja For MainWP4724671500Text Domain Mismatch
#178Security.txt Manager3510500Hidden files included
#179WP Author Security424013500Output is not escaped
#180Control XML-RPC publishing9270400Text Domain Mismatch
#181Disable Registration Page8846400Text Domain Mismatch
#182Hide WordPress Version9654400trademarked term
#183Host Header Injection Fix7098400Output is not escaped
#184yubikey-plugin406433400Text Domain Mismatch
#185Access Areas for WordPress351795400Direct Query
#186WP Login Door641911400Output is not escaped
#187WP Logout Redirect67205400Unsafe printing function
#188WP PGP Encrypted Emails356339400Output is not escaped