Upload WordPress Plugins with Most Issues

35 indexed plugins

Plugins

35

Active Installs

375k+

Average Score

71

Audited

35

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#1Iptanus File Upload245091,32510k+Non-prefixed function
#2Post Lists View Custom334621502k+Missing Arg Domain
#3Shared Files – File Upload & Download Manager3951844k+Nonce verification recommended
#4WP GIF Uploader33117441k+Text Domain Mismatch
#5Media Deduper3660999k+Missing Arg Domain
#6Pro Mime Types – Manage file media types8055982k+Non-prefixed global variable
#7Drag and Drop Multiple File Upload for WooCommerce49114295k+Text Domain Mismatch
#8Drag and Drop Multiple File Upload for Contact Form 736823660k+wp function not compatible with requires wp
#9Auto Upload Images40621320k+Unsafe printing function
#10WP Upload Restriction8659162k+Text Domain Mismatch
#11Custom Upload Dir556375k+Missing Arg Domain
#12Microsoft Azure Storage for WordPress8625262k+Missing Translators Comment
#13Easy Theme and Plugin Upgrades94292070k+Discouraged PHP function
#14Bulk Change Media Author4225202k+Unsafe printing function
#15Thumbnail Crop Position644312k+Output is not escaped
#16WP Original Media Path693536k+Non Singular String Literal Domain
#17WP Extra File Types43112640k+Request data is not unslashed
#18Plus WebP or AVIF98245k+Non-prefixed global variable
#19Canvas Image Resize751911k+Output is not escaped
#20WEN Featured Image761183k+Input is not validated
#21GD bbPress Attachments352106k+wp redirect wp redirect
#22File Upload Types by WPForms982930k+Non-prefixed function
#23Max upload filesize83389k+Input is not validated
#24Upload SVG84381k+Non-prefixed global variable
#25Upload Url and Path Enabler831012k+Missing Arg Domain
#26Clean Image Filenames826130k+Output is not escaped
#27Clean Filenames94243k+Missing nonce verification
#28Allow ePUB and MOBI formats upload98222k+Missing direct file access protection
#29Disable "BIG Image" Threshold983110k+Missing direct file access protection
#30Enable vCard Upload97312k+outdated tested upto header
#31Enable virtual card upload – vcf,vcard98227k+mismatched plugin name
#32Make Filename Lowercase98311k+Missing direct file access protection
#33Add From Server Reloaded99212k+Missing direct file access protection
#34Disable Real MIME Check983010k+Missing direct file access protection
#35Filenames to latin98219k+Missing direct file access protection