Top Security WordPress Plugins

172 indexed plugins

Plugins

172

Active Installs

27m+

Average Score

51

Audited

172

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#101.htaccess Site Access Control375467800Input is not sanitized
#102ReCaptcha Integration for WordPress3760669k+Output is not escaped
#103Injection Guard3687451k+Unsafe printing function
#104underConstruction36986040k+Unsafe printing function
#105WP fail2ban Blocklist3661633k+SQL query is not prepared
#106Brozzme DB Prefix & Tools Addons3524429k+Request data is not unslashed
#107CrowdSec351301192k+Output is not escaped
#108Expire User Passwords353153k+Nonce verification recommended
#109Give – Cloudflare Turnstile3532500Hidden files included
#110Keyring352332031k+Output is not escaped
#111Security.txt Manager3510500Hidden files included
#112Security Optimizer – The All-In-One Protection Plugin3540821m+Request data is not unslashed
#113SMNTCS Disable REST API User Endpoints35806k+Hidden files included
#114Subresource Integrity (SRI) Manager352694900Request data is not unslashed
#115WPFront User Role Editor3533357830k+Output is not escaped
#116Media Vault34115150800Output is not escaped
#117Zero Spam for WordPress347939320k+Non-prefixed global variable
#118Companion Auto Update3315929850k+Direct Query
#119WP EXtra – One Click Optimize334141017k+Missing Arg Domain
#120Admin Menu Editor32159233300k+Non-prefixed global variable
#121Advanced Access Manager – Access Governance for WordPress3284962100k+Output is not escaped
#122Restrict Usernames Emails Characters323273671k+Output is not escaped
#123WP fail2ban – Advanced Security327515360k+Dynamic hook name
#124Titan Anti-spam & Security – Brute Force Protection, 2FA & Spam Filter315719650k+Nonce verification recommended
#125My Private Site3142519020k+Text Domain Mismatch
#126LWS Tools3110413410k+Request data is not unslashed
#127MainWP Dashboard: Self-hosted WordPress Management for Agencies319531720k+Interpolated SQL is not prepared
#128Staatic – Static Site Generator for WordPress314201952k+SQL query is not prepared
#129Jetpack Protect30657217100k+Text Domain Mismatch
#130WPOrLogin – Custom Login, Social Login, Limit Attempts, Hide Login & reCAPTCHA304842222k+Unsafe printing function
#131WPS Cleaner3043049120k+Output is not escaped
#132CloudSecure WP Security2974350100k+Request data is not unslashed
#133Security Ninja – WordPress Security & Firewall291493477k+Direct Query
#134Jetpack VaultPress287136210k+Missing nonce verification
#135OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA)272715686k+Request data is not unslashed
#136WP Hide & Security Enhancer2712437550k+Input is not sanitized
#137Kadence Central – Site Management, Backups, Security, and Reporting2646221330k+Text Domain Mismatch
#138SP Move Login268812156k+Text Domain Mismatch
#139GD Security Headers254075211k+Output is not escaped
#140Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention256186051m+Unsafe printing function
#141Loginizer258145041m+Output is not escaped
#142Nexter Extension – Security, Performance, Code Snippets & Site Toolkit2519871010k+Nonce verification recommended
#143Simply Static – The Static Site Generator2516344830k+Non-prefixed hook name
#144Wordfence Login Security2524841870k+Output is not escaped
#145All-In-One Security (AIOS) – Security and Firewall245521,2281m+Non-prefixed global variable
#146Defender Security – Malware Scanner, Login Security & Firewall2430651880k+Non-prefixed namespace
#147Limit Attempts by BestWebSoft – WordPress Anti-Bot and Security Plugin for Login and Forms245635484k+Text Domain Mismatch
#148RSFirewall!245635214k+Output is not escaped
#149Security Plugin, Firewall & Malware Scanner with Auto Removal241,19176930k+Output is not escaped
#150SiteGuard WP Plugin24362345500k+Output is not escaped