| #1 | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution | 19 | 1,218 | 901 | 100k+ | | Exception Not Escaped |
| #2 | WPJAM Basic | 20 | 328 | 356 | 4k+ | | Output Not Escaped |
| #3 | Backup Migration | 21 | 981 | 1,093 | 80k+ | | Non Prefixed Variable Found |
| #4 | Captcha Them All | 21 | 300 | 323 | 6k+ | | Output Not Escaped |
| #5 | EventPrime – Events Calendar, Bookings and Tickets | 21 | 872 | 4,297 | 7k+ | | Non Prefixed Variable Found |
| #6 | FileOrganizer – WordPress File Manager | 21 | 536 | 241 | 200k+ | | unlink unlink |
| #7 | Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred | 21 | 1,469 | 3,333 | 10k+ | | Non Prefixed Variable Found |
| #8 | Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | 21 | 1,918 | 5,065 | 10k+ | | Non Prefixed Hookname Found |
| #9 | Smart Forms – when you need more than just a contact form | 21 | 776 | 574 | 5k+ | | Output Not Escaped |
| #10 | All-in-One Video Gallery | 22 | 911 | 2,892 | 20k+ | | Non Prefixed Variable Found |
| #11 | Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer | 22 | 2,858 | 1,270 | 50k+ | | Text Domain Mismatch |
| #12 | RegistrationMagic – User Registration Forms Plugin | 22 | 3,654 | 5,062 | 8k+ | | Non Prefixed Variable Found |
| #13 | File Manager Pro – Filester | 22 | 565 | 391 | 100k+ | | Missing Unslash |
| #14 | FireBox Popups – Increase Sales and Grow Your Email List | 22 | 153 | 812 | 7k+ | | Non Prefixed Variable Found |
| #15 | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | 22 | 409 | 236 | 700k+ | | Text Domain Mismatch |
| #16 | InfiniteWP Client | 22 | 2,286 | 1,812 | 200k+ | | Exception Not Escaped |
| #17 | Import WP – Export and Import CSV and XML files to WordPress | 22 | 580 | 330 | 4k+ | | Exception Not Escaped |
| #18 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | 22 | 1,581 | 2,326 | 300k+ | | Non Prefixed Variable Found |
| #19 | NextScripts: Social Networks Auto-Poster | 22 | 2,408 | 1,133 | 30k+ | | Output Not Escaped |
| #20 | ManageWP Worker | 22 | 507 | 565 | 1m+ | | Non Prefixed Class Found |
| #21 | File Manager | 22 | 740 | 520 | 1m+ | | Unsafe Printing Function |
| #22 | YaySMTP – WP Mail SMTP with Email Logs, Tracking & Reports | 22 | 654 | 435 | 10k+ | | Exception Not Escaped |
| #23 | FV Flowplayer Video Player | 23 | 1,311 | 1,454 | 20k+ | | Output Not Escaped |
| #24 | Restaurant Menu and Food Ordering | 23 | 385 | 853 | 2k+ | | Non Prefixed Variable Found |
| #25 | MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO | 23 | 488 | 580 | 2k+ | | Missing |
| #26 | MyWorks Sync for WooCommerce & QuickBooks Online | 23 | 2,292 | 9,101 | 5k+ | | Non Prefixed Variable Found |
| #27 | RSVP and Event Management | 23 | 346 | 622 | 3k+ | | Direct Query |
| #28 | Local Google Analytics for WordPress – caches external requests | 23 | 551 | 199 | 3k+ | | Output Not Escaped |
| #29 | Softaculous | 23 | 116 | 49 | 10k+ | | file system operations fread |
| #30 | پارسی دیت – Parsi Date | 23 | 102 | 289 | 100k+ | | Non Prefixed Hookname Found |
| #31 | WP STAGING – WordPress Backup, Restore & Migration | 23 | 1,414 | 1,327 | 100k+ | | Non Prefixed Variable Found |
| #32 | WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel | 23 | 1,119 | 3,516 | 20k+ | | Interpolated Not Prepared |
| #33 | A2 Optimized WP – Turbocharge and secure your WordPress site | 24 | 271 | 231 | 60k+ | | Missing Arg Domain |
| #34 | Backuply – Backup, Restore, Migrate and Clone | 24 | 704 | 551 | 700k+ | | Non Prefixed Variable Found |
| #35 | WOLF – WordPress Posts Bulk Editor and Manager Professional | 24 | 485 | 623 | 4k+ | | Output Not Escaped |
| #36 | FV Simpler SEO | 24 | 766 | 308 | 2k+ | | Text Domain Mismatch |
| #37 | ProfileGrid – User Profiles, Groups and Communities | 24 | 473 | 2,463 | 6k+ | | Non Prefixed Variable Found |
| #38 | Pz-LinkCard | 24 | 951 | 1,581 | 20k+ | | Non Prefixed Variable Found |
| #39 | Security Plugin, Firewall & Malware Scanner with Auto Removal | 24 | 1,191 | 788 | 30k+ | | Output Not Escaped |
| #40 | SiteGuard WP Plugin | 24 | 329 | 333 | 500k+ | | Output Not Escaped |
| #41 | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin | 24 | 938 | 2,935 | 200k+ | | Non Prefixed Variable Found |
| #42 | Video Conferencing with Zoom | 24 | 1,105 | 440 | 10k+ | | Unsafe Printing Function |
| #43 | European VAT Compliance Assistant for WooCommerce | 24 | 515 | 317 | 3k+ | | Output Not Escaped |
| #44 | WP-Members Membership Plugin | 24 | 669 | 382 | 50k+ | | Output Not Escaped |
| #45 | WP Travel – Ultimate Travel Booking System, Tour Management Engine | 24 | 427 | 1,962 | 4k+ | | Non Prefixed Hookname Found |
| #46 | WP Travel Engine – Tour Booking Plugin – Tour Operator Software | 24 | 2,010 | 5,688 | 20k+ | | Non Prefixed Variable Found |
| #47 | Site Kit by Google – Analytics, Search Console, AdSense, Speed | 25 | 1,304 | 242 | 5m+ | | missing direct file access protection |
| #48 | Secure Copy Content Protection and Content Locking | 25 | 958 | 799 | 20k+ | | Output Not Escaped |
| #49 | Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin | 25 | 960 | 738 | 60k+ | | Text Domain Mismatch |
| #50 | VikBooking Hotel Booking Engine & PMS | 25 | 13,232 | 8,312 | 8k+ | | Output Not Escaped |