Top Security WordPress Plugins

188 indexed plugins

Plugins

188

Active Installs

27m+

Average Score

52

Audited

179

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#51LH HSTS78312600Input is not sanitized
#52Disable WP Registration Page Spam775121k+Nonce verification recommended
#53OpenID Connect Generic Client7395910k+Non-prefixed hook name
#54Comment Form CSRF Protection70710500Request data is not unslashed
#55WebDefender Security – Protection & AntiSpam70176611k+wp function not compatible with requires wp
#56Simple Login Captcha70201910k+date date
#57Simple Login Lockdown691364k+Output is not escaped
#58Content Security Policy Manager681922k+Output is not escaped
#59Protection Against DDoS682253k+Output is not escaped
#60Forget Spam Comment6751010k+Input is not sanitized
#61WP Anti-Clickjack664424k+Nonce verification recommended
#62Inactive Logout64307110k+Non-prefixed global variable
#63REST XML-RPC Data Checker5414451k+Input is not sanitized
#64Meta Generator and Version Info Remover52202810k+Non-prefixed function
#65Block IPs for Gravity Forms508361k+Request data is not unslashed
#66TrustedSite50291420k+Output is not escaped
#67Whitelist IP For Limit Login Attempts481812600Output is not escaped
#68Security Ninja For MainWP4724671500Text Domain Mismatch
#69iControlWP4745591k+Missing direct file access protection
#70Easy Basic Authentication – Add basic auth to site or admin area461428600Input is not sanitized
#71SX User Name Security46429900Output is not escaped
#72JetHost Total Care – Security & Enhancements451085800Direct Query
#73LWS Hide Login4555820k+Request data is not unslashed
#74Passwords Evolved4526171k+Output is not escaped
#75BBQ Firewall – Fast & Powerful Firewall Security441717100k+Output is not escaped
#76User Role Editor43117145700k+Output is not escaped
#77User Session Control433121700Output is not escaped
#78Lock Down Admin4230203k+Unsafe printing function
#79Login No Captcha reCAPTCHA42452460k+Unsafe printing function
#80Proxy & VPN Blocker4210721k+Nonce verification recommended
#81Two Factor421870100k+Nonce verification recommended
#82WP Author Security424013500Output is not escaped
#83WP Fingerprint4234479k+Direct Query
#84CloudGuard4141131k+Output is not escaped
#85Edit Lock414722500Non Singular String Literal Domain
#86Google Authenticator41396520k+Output is not escaped
#87Lockdown WP Admin41205010k+Request data is not unslashed
#88Log cleaner for Solid Security4165478k+Text Domain Mismatch
#89Advanced Country Blocker4023772k+Exception output is not escaped
#90Advanced IP Blocker4094442k+Exception output is not escaped
#91Atomic Edge Security – Firewall, Malware Scan and Login Security4012184600Non-prefixed global variable
#92Limit Login Attempts408138300k+Output is not escaped
#93Logbook4033592k+Nonce verification recommended
#94No-Bot Registration40112422k+Unsafe printing function
#95No CAPTCHA reCAPTCHA40112264k+Text Domain Mismatch
#96Universal Honey Pot4023941k+Missing nonce verification
#97Blackhole for Bad Bots391236930k+Output is not escaped
#98DefendWP Firewall39162033k+Non-prefixed global variable
#99Virusdie | One-click website security39149662k+Output is not escaped
#100WPS Limit Login3915276100k+Output is not escaped