| #1 | BulletProof Security | 0 | 5,048 | 4,949 | 20k+ | | Output Not Escaped |
| #2 | WPtouch – Make your WordPress Website Mobile-Friendly | 17 | 1,466 | 325 | 50k+ | | Text Domain Mismatch |
| #3 | Robin Image Optimizer – Unlimited Image Optimization, WebP & AVIF | 20 | 557 | 541 | 100k+ | | Output Not Escaped |
| #4 | Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More | 21 | 2,572 | 1,277 | 1m+ | | Output Not Escaped |
| #5 | Wordfence Security – Firewall, Malware Scan, and Login Security | 21 | 1,592 | 2,973 | 5m+ | | Output Not Escaped |
| #6 | Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer | 22 | 2,858 | 1,270 | 50k+ | | Text Domain Mismatch |
| #7 | NextScripts: Social Networks Auto-Poster | 22 | 2,408 | 1,133 | 30k+ | | Output Not Escaped |
| #8 | SSL Zen — SSL Certificate Installer & HTTPS Redirects | 22 | 779 | 1,575 | 10k+ | | Non Prefixed Variable Found |
| #9 | ManageWP Worker | 22 | 507 | 565 | 1m+ | | Non Prefixed Class Found |
| #10 | GAinWP Google Analytics Integration for WordPress | 23 | 525 | 176 | 8k+ | | Output Not Escaped |
| #11 | Next Active Directory Integration | 23 | 683 | 284 | 2k+ | | Exception Not Escaped |
| #12 | Local Google Analytics for WordPress – caches external requests | 23 | 551 | 199 | 3k+ | | Output Not Escaped |
| #13 | WP Migrate Lite – Migration Made Easy | 23 | 368 | 254 | 200k+ | | Exception Not Escaped |
| #14 | AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress | 24 | 5,230 | 1,464 | 7k+ | | Output Not Escaped |
| #15 | Assets manager, dequeue scripts, dequeue styles for WordPress | 24 | 592 | 255 | 2k+ | | Output Not Escaped |
| #16 | Social Slider Feed – Social Media Feed & Gallery Widgets | 24 | 929 | 707 | 20k+ | | Non Prefixed Variable Found |
| #17 | Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates | 24 | 522 | 135 | 10k+ | | Output Not Escaped |
| #18 | Disable Comments & Delete All Comments | 25 | 503 | 185 | 9k+ | | Output Not Escaped |
| #19 | Disable Admin Notices – Hide Dashboard Notifications | 25 | 465 | 195 | 100k+ | | Output Not Escaped |
| #20 | WP-DownloadManager | 25 | 607 | 508 | 3k+ | | Unsafe Printing Function |
| #21 | WP-Polls | 25 | 618 | 639 | 40k+ | | Unsafe Printing Function |
| #22 | WP Popups – WordPress Popup builder | 25 | 440 | 342 | 30k+ | | Output Not Escaped |
| #23 | Visitors Online by BestWebSoft | 26 | 512 | 269 | 1k+ | | Text Domain Mismatch |
| #24 | BackUpWordPress | 27 | 245 | 271 | 90k+ | | Non Prefixed Variable Found |
| #25 | Cyrlitera – Transliteration of Links and File Names | 27 | 453 | 204 | 40k+ | | Output Not Escaped |
| #26 | WP-DBManager | 27 | 386 | 304 | 60k+ | | Non Prefixed Variable Found |
| #27 | Better Google Analytics | 29 | 376 | 869 | 2k+ | | Non Prefixed Variable Found |
| #28 | Countdown, Coming Soon, Maintenance – Countdown & Clock | 29 | 1,735 | 143 | 10k+ | | Non Singular String Literal Domain |
| #29 | WP-PostRatings | 29 | 425 | 384 | 30k+ | | Output Not Escaped |
| #30 | Analytics Insights – Google Analytics Dashboard for WordPress | 30 | 241 | 170 | 10k+ | | Unsafe Printing Function |
| #31 | Popup Builder – Create highly converting, mobile friendly marketing popups. | 30 | 26 | 722 | 200k+ | | Non Prefixed Variable Found |
| #32 | Affiliate Coupons – Coupon Display Manager – Excellent Tool for Affiliate Marketers | 32 | 183 | 61 | 1k+ | | Output Not Escaped |
| #33 | Quick Featured Images | 32 | 436 | 323 | 50k+ | | Non Prefixed Variable Found |
| #34 | WP-Stats | 32 | 237 | 126 | 2k+ | | Output Not Escaped |
| #35 | Companion Sitemap Generator – Simple, Smart, and SEO-Ready | 33 | 118 | 57 | 7k+ | | Missing Translators Comment |
| #36 | WP-UserOnline | 33 | 111 | 161 | 10k+ | | Output Not Escaped |
| #37 | Multi Step Form | 34 | 277 | 136 | 9k+ | | Output Not Escaped |
| #38 | One User Avatar | User Profile Picture | 34 | 68 | 190 | 100k+ | | Non Prefixed Variable Found |
| #39 | Search Engine Insights for Google Search Console | 34 | 174 | 113 | 2k+ | | Output Not Escaped |
| #40 | Ultimate Post List | 35 | 186 | 84 | 2k+ | | Missing Arg Domain |
| #41 | WP-PageNavi | 35 | 84 | 95 | 500k+ | | Non Singular String Literal Domain |
| #42 | WP-PostViews | 35 | 132 | 64 | 100k+ | | Unsafe Printing Function |
| #43 | WP-Print | 35 | 110 | 52 | 8k+ | | Unsafe Printing Function |
| #44 | WP-EMail | 36 | 340 | 95 | 1k+ | | Unsafe Printing Function |
| #45 | Recent Posts Widget With Thumbnails | 37 | 222 | 46 | 100k+ | | Output Not Escaped |
| #46 | ReCaptcha Integration for WordPress | 37 | 60 | 66 | 10k+ | | Output Not Escaped |
| #47 | Announce from the Dashboard | 38 | 138 | 24 | 7k+ | | Non Singular String Literal Domain |
| #48 | WP REST API – OAuth 1.0a Server | 38 | 100 | 85 | 8k+ | | Text Domain Mismatch |
| #49 | WP-Ban | 38 | 99 | 108 | 8k+ | | Unsafe Printing Function |
| #50 | WP-DraftsForFriends | 38 | 141 | 71 | 1k+ | | Output Not Escaped |