Recently Scanned Security WordPress Plugins
137 indexed plugins
Plugins
137
Active Installs
27m+
Average Score
48
Audited
137
Recently Scanned
| Rank | Plugin | Score | Errors | Warnings | Installs | Updated | Top Issue |
|---|---|---|---|---|---|---|---|
| #1 | GD Security Headers | 25 | 407 | 521 | 1k+ | Output Not Escaped | |
| #2 | Block IPs for Gravity Forms | 50 | 8 | 36 | 1k+ | Missing Unslash | |
| #3 | Keyring | 35 | 233 | 203 | 1k+ | Output Not Escaped | |
| #4 | Disable WP Registration Page Spam | 77 | 5 | 12 | 1k+ | Recommended | |
| #5 | Banhammer – Monitor Site Traffic, Block Bad Users and Bots | 37 | 104 | 174 | 1k+ | Output Not Escaped | |
| #6 | Passwords Evolved | 45 | 26 | 17 | 1k+ | Output Not Escaped | |
| #7 | Proxy & VPN Blocker | 42 | 10 | 72 | 1k+ | Recommended | |
| #8 | WebAuthn Provider for Two Factor | 91 | 6 | 14 | 1k+ | Missing Arg Domain | |
| #9 | App for Cloudflare® | 98 | 10 | 1 | 1k+ | wp function not compatible with requires wp | |
| #10 | Restrict Usernames Emails Characters | 32 | 327 | 367 | 1k+ | Output Not Escaped | |
| #11 | Dam Spam | 100 | 1 | 1k+ | unexpected markdown file | ||
| #12 | Remove XML-RPC Methods | 100 | 0 | 1k+ | No open findings | ||
| #13 | Universal Honey Pot | 40 | 23 | 94 | 1k+ | Missing | |
| #14 | Advanced IP Blocker | 40 | 94 | 44 | 1k+ | Exception Not Escaped | |
| #15 | Logbook | 40 | 33 | 59 | 2k+ | Recommended | |
| #16 | Virusdie | One-click website security | 39 | 149 | 66 | 2k+ | Output Not Escaped | |
| #17 | No-Bot Registration | 40 | 112 | 42 | 2k+ | Unsafe Printing Function | |
| #18 | Simple Automatic Updates | 85 | 18 | 1 | 2k+ | Missing Translators Comment | |
| #19 | WP Admin Basic Auth | 87 | 5 | 6 | 2k+ | Input Not Sanitized | |
| #20 | Content Security Policy Manager | 68 | 19 | 2 | 2k+ | Output Not Escaped | |
| #21 | Smart Passworded Pages | 80 | 11 | 8 | 2k+ | wp function not compatible with requires wp | |
| #22 | Advanced Country Blocker | 40 | 23 | 77 | 2k+ | Exception Not Escaped | |
| #23 | CrowdSec | 35 | 130 | 119 | 2k+ | Output Not Escaped | |
| #24 | WPOrLogin – Custom Login, Social Login, Limit Attempts, Hide Login & reCAPTCHA | 30 | 484 | 222 | 2k+ | Unsafe Printing Function | |
| #25 | WP-WebAuthn | 22 | 957 | 396 | 2k+ | Exception Not Escaped | |
| #26 | WP Author Slug | 96 | 16 | 6 | 2k+ | Text Domain Mismatch | |
| #27 | Staatic – Static Site Generator for WordPress | 31 | 420 | 195 | 2k+ | Not Prepared | |
| #28 | Lock Down Admin | 42 | 30 | 20 | 3k+ | Unsafe Printing Function | |
| #29 | DefendWP Firewall | 39 | 16 | 203 | 3k+ | Non Prefixed Variable Found | |
| #30 | BotBlocker Security – Firewall & Bot Protection | 99 | 5 | 3k+ | Non Prefixed Constant Found | ||
| #31 | Protection Against DDoS | 68 | 22 | 5 | 3k+ | Output Not Escaped | |
| #32 | Expire User Passwords | 35 | 3 | 15 | 3k+ | Recommended | |
| #33 | HSTS Ready | 85 | 3 | 11 | 3k+ | Input Not Validated | |
| #34 | WP fail2ban Blocklist | 36 | 61 | 63 | 3k+ | Not Prepared | |
| #35 | RSFirewall! | 24 | 563 | 521 | 4k+ | Output Not Escaped | |
| #36 | Simple Login Lockdown | 69 | 13 | 6 | 4k+ | Output Not Escaped | |
| #37 | WP Anti-Clickjack | 66 | 4 | 42 | 4k+ | Recommended | |
| #38 | Limit Attempts by BestWebSoft – WordPress Anti-Bot and Security Plugin for Login and Forms | 24 | 563 | 548 | 4k+ | Text Domain Mismatch | |
| #39 | No CAPTCHA reCAPTCHA | 40 | 112 | 26 | 4k+ | Text Domain Mismatch | |
| #40 | WPMasterToolKit (WPMTK) – All in one plugin | 99 | 1 | 4 | 4k+ | trademarked term | |
| #41 | Melapress File Monitor | 80 | 16 | 90 | 6k+ | Non Prefixed Variable Found | |
| #42 | Manage XML-RPC | 98 | 3 | 1 | 6k+ | file system operations is writable | |
| #43 | OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) | 27 | 272 | 531 | 6k+ | Missing Unslash | |
| #44 | Stop XML-RPC Attacks | 100 | 1 | 6k+ | Non Prefixed Class Found | ||
| #45 | Salt Shaker | 85 | 15 | 13 | 6k+ | Interpolated Not Prepared | |
| #46 | SMNTCS Disable REST API User Endpoints | 35 | 8 | 0 | 6k+ | hidden files | |
| #47 | Prevent XSS Vulnerability | 98 | 10 | 1 | 6k+ | Missing Arg Domain | |
| #48 | SP Move Login | 26 | 881 | 215 | 6k+ | Text Domain Mismatch | |
| #49 | WP EXtra – One Click Optimize | 33 | 414 | 101 | 7k+ | Missing Arg Domain | |
| #50 | Security Ninja – WordPress Security & Firewall | 29 | 149 | 347 | 7k+ | Direct Query |