WordPress.Security.PluginMenuSlug.Using__FILE__

Using FILE

Plugin Check reported a security-sensitive coding pattern that needs review.

critical weight

Why It Shows Up

The finding came from a security-focused WordPress coding standard or Plugin Check rule.

Why It Matters

Security findings often involve trust boundaries: request input, browser output, redirects, database access, capabilities, or filesystem behavior.

How to Fix

  • Identify the untrusted value or privileged action involved.
  • Add validation, sanitization, escaping, nonce checks, capability checks, or prepared SQL as appropriate.
  • Rerun Plugin Check after the code path is fixed.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#1Smart Forms – when you need more than just a contact form217765745k+Output Not Escaped
#2HeadSpace2 SEO229403603k+Text Domain Mismatch
#3BlossomThemes Email Newsletter2333723920k+Output Not Escaped
#4SEO Redirection Plugin – 301 Redirect Manager2327272710k+Non Prefixed Variable Found
#5eCommerce Product Catalog Plugin for WordPress246213,1777k+Non Prefixed Function Found
#6WP Meta and Date Remover246651,31490k+Non Prefixed Variable Found
#7WP Travel Engine – Tour Booking Plugin – Tour Operator Software242,0105,68820k+Non Prefixed Variable Found
#8All 404 Redirect to Homepage25140301200k+date date
#9Booking Package251,7003,97710k+Missing
#10Sitemap by click5252861326k+Unsafe Printing Function
#11iQ Block Country2716424520k+Missing Unslash
#12VOD Infomaniak2779738520k+Output Not Escaped
#13DB Cache Reloaded Fix29133422k+Output Not Escaped
#14Custom Field Template3052161830k+Recommended
#15Widgetize Pages Light301451043k+Output Not Escaped
#16WP125311781843k+Unsafe Printing Function
#17AGCA – Custom Dashboard & Login Page343504420k+Unsafe Printing Function
#18Audit Trail349010710k+Unsafe Printing Function
#19Forms: 3rd-Party Integration342341125k+Output Not Escaped
#20HTML Import 234273265k+Unsafe Printing Function
#21Search Meter341919420k+Output Not Escaped
#22ReOrder Posts within Categories35392077k+Non Prefixed Variable Found
#23Simple Header Footer HTML353053k+Output Not Escaped
#24User Photo35112683k+Output Not Escaped
#25Easy Accept Payments via PayPal353221287k+Text Domain Mismatch
#26WP-Paginate35375520k+Input Not Validated
#27authLdap3647305k+Exception Not Escaped
#28Peter’s Post Notes362241023k+Output Not Escaped
#29Photoswipe Masonry Gallery3657476k+Non Singular String Literal Text
#30Plugins Garbage Collector (Database Cleanup)36325110k+Missing
#31WP Super Edit36351852k+Recommended
#32Images to WebP3739509k+curl curl setopt
#33OSM – OpenStreetMap371306410k+Output Not Escaped
#34PNG to JPG371301739k+Interpolated Not Prepared
#35Publish to Schedule37195434k+Text Domain Mismatch
#36WP PageNavi Style37109118k+Unsafe Printing Function
#37Any Mobile Theme Switcher38695920k+Output Not Escaped
#38Attachments38238668k+Unsafe Printing Function
#39Multiple Domain Mapping on Single Site38135516k+Text Domain Mismatch
#40Simple Google Sitemap XML383882k+Output Not Escaped
#41mb.miniAudioPlayer – an HTML5 audio player for your mp3 files3820464k+Unsafe Printing Function
#42Faster Image Insert3994262k+Output Not Escaped
#43hpb seo plugin for WordPress3915872k+Non Prefixed Variable Found
#44Mail Subscribe List3917943k+Input Not Validated
#45TinyMCE Custom Styles39297767k+Non Singular String Literal Domain
#46Uptolike Social Share Buttons3938334k+Output Not Escaped
#47UserHeat Plugin39121206k+Non Singular String Literal Domain
#48WP Realtime Sitemap39464110k+Output Not Escaped
#49SEO Auto Linker3997623k+Unsafe Printing Function
#50Crisp – Live Chat and Chatbot40242020k+Unsafe Printing Function