Security WordPress Plugins with Most Issues

137 indexed plugins

Plugins

137

Active Installs

27m+

Average Score

47

Audited

124

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#1BulletProof Security05,0484,94920k+Output Not Escaped
#2Wordfence Security – Firewall, Malware Scan, and Login Security211,5922,9735m+Output Not Escaped
#3Jetpack – WP Security, Backup, Speed, & Growth232,8211,3033m+Text Domain Mismatch
#4InfiniteWP Client222,2861,812200k+Exception Not Escaped
#5NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall221,2652,065100k+Non Prefixed Variable Found
#6SecuPress with Simple SSL – Simple and Performant Security231,6961,59040k+Non Prefixed Variable Found
#7Kadence Security – Password, Two Factor Authentication, and Brute Force Protection231,053967700k+Missing Translators Comment
#8Security Plugin, Firewall & Malware Scanner with Auto Removal241,19178830k+Output Not Escaped
#9The GDPR Framework By Data443231,28751710k+Echo Found
#10All-In-One Security (AIOS) – Security and Firewall245521,2281m+Non Prefixed Variable Found
#11Anti-Malware Security and Brute-Force Firewall22544965100k+Output Not Escaped
#12WP-WebAuthn229573962k+Exception Not Escaped
#13Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning231,11820240k+Missing Translators Comment
#14Loginizer258145041m+Output Not Escaped
#15Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention256216021m+Unsafe Printing Function
#16NinjaScanner – Virus & Malware scan2259655130k+Non Prefixed Variable Found
#17Login With Ajax – Fast Logins, 2FA, Redirects2362352010k+Output Not Escaped
#18Limit Attempts by BestWebSoft – WordPress Anti-Bot and Security Plugin for Login and Forms245635484k+Text Domain Mismatch
#19SP Move Login268812156k+Text Domain Mismatch
#20RSFirewall!245635214k+Output Not Escaped
#21ManageWP Worker225075651m+Non Prefixed Class Found
#22IP Geo Block233995899k+Output Not Escaped
#23Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)195413853m+Missing Translators Comment
#24WPS Cleaner3043049120k+Output Not Escaped
#25Advanced Access Manager – Access Governance for WordPress3284962100k+Output Not Escaped
#26WPFront User Role Editor3533357830k+Output Not Escaped
#27Nexter Extension – Security, Performance, Code Snippets & Site Toolkit2519871010k+Recommended
#28Jetpack Protect30657217100k+Text Domain Mismatch
#29Defender Security – Malware Scanner, Login Security & Firewall2430651880k+Non Prefixed Namespace Found
#30OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA)272725316k+Missing Unslash
#31WPScan – WordPress Security Scanner215272658k+Text Domain Mismatch
#32Captcha by BestWebSoft – Advanced Spam Protection, Math & OCR-Friendly Captcha for Site Forms2249329510k+Text Domain Mismatch
#33WPOrLogin – Custom Login, Social Login, Limit Attempts, Hide Login & reCAPTCHA304842222k+Unsafe Printing Function
#34Kadence Central – Site Management, Backups, Security, and Reporting2646221330k+Text Domain Mismatch
#35Wordfence Login Security2524841870k+Output Not Escaped
#36SiteGuard WP Plugin24329333500k+Output Not Escaped
#37My Private Site3142519020k+Text Domain Mismatch
#38Staatic – Static Site Generator for WordPress314201952k+Not Prepared
#39Simply Static – The Static Site Generator2516344630k+Non Prefixed Hookname Found
#40Patchstack – WordPress & Plugins Security2310748940k+Missing
#41WP EXtra – One Click Optimize334141017k+Missing Arg Domain
#42WP Hide & Security Enhancer2712437550k+Input Not Sanitized
#43Security Ninja – WordPress Security & Firewall291493477k+Direct Query
#44Zero Spam for WordPress347939320k+Non Prefixed Variable Found
#45Companion Auto Update3315929850k+Direct Query
#46Jetpack VaultPress287136210k+Missing
#47CloudSecure WP Security2974350100k+Missing Unslash
#48MainWP Dashboard: Self-hosted WordPress Management for Agencies319531720k+Interpolated Not Prepared
#49Admin Menu Editor32159233300k+Non Prefixed Variable Found
#50Login by Auth0373078210k+Text Domain Mismatch