Recently Scanned Security WordPress Plugins

137 indexed plugins

Plugins

137

Active Installs

27m+

Average Score

48

Audited

137

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#1GD Security Headers254075211k+Output Not Escaped
#2Block IPs for Gravity Forms508361k+Missing Unslash
#3Keyring352332031k+Output Not Escaped
#4Disable WP Registration Page Spam775121k+Recommended
#5Banhammer – Monitor Site Traffic, Block Bad Users and Bots371041741k+Output Not Escaped
#6Passwords Evolved4526171k+Output Not Escaped
#7Proxy & VPN Blocker4210721k+Recommended
#8WebAuthn Provider for Two Factor916141k+Missing Arg Domain
#9App for Cloudflare®981011k+wp function not compatible with requires wp
#10Restrict Usernames Emails Characters323273671k+Output Not Escaped
#11Dam Spam10011k+unexpected markdown file
#12Remove XML-RPC Methods10001k+No open findings
#13Universal Honey Pot4023941k+Missing
#14Advanced IP Blocker4094441k+Exception Not Escaped
#15Logbook4033592k+Recommended
#16Virusdie | One-click website security39149662k+Output Not Escaped
#17No-Bot Registration40112422k+Unsafe Printing Function
#18Simple Automatic Updates851812k+Missing Translators Comment
#19WP Admin Basic Auth87562k+Input Not Sanitized
#20Content Security Policy Manager681922k+Output Not Escaped
#21Smart Passworded Pages801182k+wp function not compatible with requires wp
#22Advanced Country Blocker4023772k+Exception Not Escaped
#23CrowdSec351301192k+Output Not Escaped
#24WPOrLogin – Custom Login, Social Login, Limit Attempts, Hide Login & reCAPTCHA304842222k+Unsafe Printing Function
#25WP-WebAuthn229573962k+Exception Not Escaped
#26WP Author Slug961662k+Text Domain Mismatch
#27Staatic – Static Site Generator for WordPress314201952k+Not Prepared
#28Lock Down Admin4230203k+Unsafe Printing Function
#29DefendWP Firewall39162033k+Non Prefixed Variable Found
#30BotBlocker Security – Firewall & Bot Protection9953k+Non Prefixed Constant Found
#31Protection Against DDoS682253k+Output Not Escaped
#32Expire User Passwords353153k+Recommended
#33HSTS Ready853113k+Input Not Validated
#34WP fail2ban Blocklist3661633k+Not Prepared
#35RSFirewall!245635214k+Output Not Escaped
#36Simple Login Lockdown691364k+Output Not Escaped
#37WP Anti-Clickjack664424k+Recommended
#38Limit Attempts by BestWebSoft – WordPress Anti-Bot and Security Plugin for Login and Forms245635484k+Text Domain Mismatch
#39No CAPTCHA reCAPTCHA40112264k+Text Domain Mismatch
#40WPMasterToolKit (WPMTK) – All in one plugin99144k+trademarked term
#41Melapress File Monitor8016906k+Non Prefixed Variable Found
#42Manage XML-RPC98316k+file system operations is writable
#43OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA)272725316k+Missing Unslash
#44Stop XML-RPC Attacks10016k+Non Prefixed Class Found
#45Salt Shaker8515136k+Interpolated Not Prepared
#46SMNTCS Disable REST API User Endpoints35806k+hidden files
#47Prevent XSS Vulnerability981016k+Missing Arg Domain
#48SP Move Login268812156k+Text Domain Mismatch
#49WP EXtra – One Click Optimize334141017k+Missing Arg Domain
#50Security Ninja – WordPress Security & Firewall291493477k+Direct Query