Security WordPress Plugins with Most Issues

137 indexed plugins

Plugins

137

Active Installs

27m+

Average Score

48

Audited

137

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#51MainWP Dashboard: Self-hosted WordPress Management for Agencies319531720k+Interpolated Not Prepared
#52Admin Menu Editor32159233300k+Non Prefixed Variable Found
#53Login by Auth0373078210k+Text Domain Mismatch
#54WP Ghost (Hide My WP Ghost) – Security & Firewall856373100k+Non Prefixed Variable Found
#55Banhammer – Monitor Site Traffic, Block Bad Users and Bots371041741k+Output Not Escaped
#56User Role Editor43117145700k+Output Not Escaped
#57Plugin Check (PCP)012813210k+Exception Not Escaped
#58Titan Anti-spam & Security – Brute Force Protection, 2FA & Spam Filter315719650k+Recommended
#59CrowdSec351301192k+Output Not Escaped
#60Modular DS: Monitor, update, and backup multiple websites211618140k+Exception Not Escaped
#61LWS Tools3110413410k+Missing Unslash
#62Activity Log – Monitor & Record User Changes3881149200k+Recommended
#63WP fail2ban – Advanced Security327515360k+Dynamic Hookname Found
#64WPS Limit Login3915276100k+Output Not Escaped
#65DefendWP Firewall39162033k+Non Prefixed Variable Found
#66Virusdie | One-click website security39149662k+Output Not Escaped
#67Blackhole for Bad Bots391236930k+Output Not Escaped
#68Stop Spammers Classic94185130k+wp function not compatible with requires wp
#69underConstruction36986040k+Unsafe Printing Function
#70Exploit Scanner37251308k+Non Prefixed Variable Found
#71No-Bot Registration40112422k+Unsafe Printing Function
#72MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites383136700k+Non Prefixed Hookname Found
#73Advanced IP Blocker4094442k+Exception Not Escaped
#74No CAPTCHA reCAPTCHA40112264k+Text Domain Mismatch
#75ReCaptcha Integration for WordPress37606610k+Output Not Escaped
#76WP fail2ban Blocklist3661633k+Not Prepared
#77Security Optimizer – The All-In-One Protection Plugin3540821m+Missing Unslash
#78Limit Login Attempts408138300k+Output Not Escaped
#79Universal Honey Pot4023941k+Missing
#80Log cleaner for Solid Security4165478k+Text Domain Mismatch
#81Melapress File Monitor8016906k+Non Prefixed Variable Found
#82Google Authenticator41396520k+Output Not Escaped
#83Inactive Logout64307110k+Non Prefixed Variable Found
#84Advanced Country Blocker4023772k+Exception Not Escaped
#85Logbook4033592k+Recommended
#86Two Factor421870100k+Recommended
#87Proxy & VPN Blocker4210721k+Recommended
#88WP Fingerprint4234479k+Direct Query
#89Malcure Malware Shield — Removal, Repair, Monitor9575610k+wp function not compatible with requires wp
#90Lockdown WP Admin41205010k+Missing Unslash
#91Login No Captcha reCAPTCHA42452460k+Unsafe Printing Function
#92OpenID Connect Generic Client7395910k+Non Prefixed Hookname Found
#93Brozzme DB Prefix & Tools Addons3524429k+Missing Unslash
#94LWS Hide Login4555820k+Missing Unslash
#95Sucuri Security – Auditing, Malware Scanner and Security Hardening94525600k+missing direct file access protection
#96MilesWeb Tools9544910k+Non Prefixed Variable Found
#97Lock Down Admin4230203k+Unsafe Printing Function
#98Meta Generator and Version Info Remover52202810k+Non Prefixed Function Found
#99WP Anti-Clickjack664424k+Recommended
#100Block IPs for Gravity Forms508361k+Missing Unslash