Security WordPress Plugins That Need Review

137 indexed plugins

Plugins

137

Active Installs

27m+

Average Score

48

Audited

137

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#1BulletProof Security05,0484,94920k+Output is not escaped
#2Plugin Check (PCP)012813210k+Exception output is not escaped
#3Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)195413853m+Missing Translators Comment
#4Modular DS: Monitor, update, and backup multiple websites211618140k+Exception output is not escaped
#5Wordfence Security – Firewall, Malware Scan, and Login Security211,5922,9735m+Output is not escaped
#6WPScan – WordPress Security Scanner215272658k+Text Domain Mismatch
#7Captcha by BestWebSoft – Advanced Spam Protection, Math & OCR-Friendly Captcha for Site Forms2249329510k+Text Domain Mismatch
#8Anti-Malware Security and Brute-Force Firewall22544965100k+Output is not escaped
#9InfiniteWP Client222,2861,812200k+Exception output is not escaped
#10NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall221,2652,065100k+Non-prefixed global variable
#11NinjaScanner – Virus & Malware scan2259655130k+Non-prefixed global variable
#12ManageWP Worker225075651m+Non-prefixed class
#13WP-WebAuthn229573962k+Exception output is not escaped
#14Kadence Security – Password, Two Factor Authentication, and Brute Force Protection231,053967700k+Missing Translators Comment
#15The GDPR Framework By Data443231,28751710k+Short PHP open tag found
#16IP Geo Block233995899k+Output is not escaped
#17Jetpack – WP Security, Backup, Speed, & Growth232,8211,3033m+Text Domain Mismatch
#18Login With Ajax – Fast Logins, 2FA, Redirects2362352010k+Output is not escaped
#19Patchstack – WordPress & Plugins Security2310748940k+Missing nonce verification
#20SecuPress with Simple SSL – Simple and Performant Security231,6961,59040k+Non-prefixed global variable
#21Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning231,11820240k+Missing Translators Comment
#22All-In-One Security (AIOS) – Security and Firewall245521,2281m+Non-prefixed global variable
#23Defender Security – Malware Scanner, Login Security & Firewall2430651880k+Non-prefixed namespace
#24Limit Attempts by BestWebSoft – WordPress Anti-Bot and Security Plugin for Login and Forms245635484k+Text Domain Mismatch
#25RSFirewall!245635214k+Output is not escaped
#26Security Plugin, Firewall & Malware Scanner with Auto Removal241,19176930k+Output is not escaped
#27SiteGuard WP Plugin24362345500k+Output is not escaped
#28GD Security Headers254075211k+Output is not escaped
#29Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention256216021m+Unsafe printing function
#30Loginizer258145041m+Output is not escaped
#31Nexter Extension – Security, Performance, Code Snippets & Site Toolkit2519871010k+Nonce verification recommended
#32Simply Static – The Static Site Generator2516344630k+Non-prefixed hook name
#33Wordfence Login Security2524841870k+Output is not escaped
#34Kadence Central – Site Management, Backups, Security, and Reporting2646221330k+Text Domain Mismatch
#35SP Move Login268812156k+Text Domain Mismatch
#36OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA)272715686k+Request data is not unslashed
#37WP Hide & Security Enhancer2712437550k+Input is not sanitized
#38Jetpack VaultPress287136210k+Missing nonce verification
#39CloudSecure WP Security2974350100k+Request data is not unslashed
#40Security Ninja – WordPress Security & Firewall291493477k+Direct Query
#41Jetpack Protect30657217100k+Text Domain Mismatch
#42WPOrLogin – Custom Login, Social Login, Limit Attempts, Hide Login & reCAPTCHA304842222k+Unsafe printing function
#43WPS Cleaner3043049120k+Output is not escaped
#44Titan Anti-spam & Security – Brute Force Protection, 2FA & Spam Filter315719650k+Nonce verification recommended
#45My Private Site3142519020k+Text Domain Mismatch
#46LWS Tools3110413410k+Request data is not unslashed
#47MainWP Dashboard: Self-hosted WordPress Management for Agencies319531720k+Interpolated SQL is not prepared
#48Staatic – Static Site Generator for WordPress314201952k+SQL query is not prepared
#49Admin Menu Editor32159233300k+Non-prefixed global variable
#50Advanced Access Manager – Access Governance for WordPress3284962100k+Output is not escaped