| #1 | wpForo Forum | 17 | 4,033 | 2,922 | 20k+ | | Unsafe Printing Function |
| #2 | Element Pack – Widgets, Templates & Addons for Elementor | 19 | 9,448 | 517 | 100k+ | | Text Domain Mismatch |
| #3 | Brizy – Page Builder | 20 | 589 | 720 | 70k+ | | Output Not Escaped |
| #4 | GiveWP – Donation Plugin and Fundraising Platform | 20 | 3,435 | 3,580 | 100k+ | | Output Not Escaped |
| #5 | Link Library | 20 | 1,941 | 1,397 | 10k+ | | Unsafe Printing Function |
| #6 | Brevo – Email, SMS, Web Push, Chat, and more. | 20 | 460 | 646 | 100k+ | | Missing Unslash |
| #7 | Remove Add to Cart WooCommerce | 20 | 616 | 1,378 | 4k+ | | Non Prefixed Variable Found |
| #8 | Robin Image Optimizer – Unlimited Image Optimization, WebP & AVIF | 20 | 557 | 541 | 100k+ | | Output Not Escaped |
| #9 | Smart Grid-Layout Design for Contact Form 7 | 21 | 1,126 | 734 | 10k+ | | Output Not Escaped |
| #10 | ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support | 21 | 829 | 5,966 | 5k+ | | Direct Query |
| #11 | EventPrime – Events Calendar, Bookings and Tickets | 21 | 872 | 4,297 | 7k+ | | Non Prefixed Variable Found |
| #12 | FileOrganizer – WordPress File Manager | 21 | 536 | 241 | 200k+ | | unlink unlink |
| #13 | MotoPress Hotel Booking | 21 | 3,061 | 1,037 | 10k+ | | Text Domain Mismatch |
| #14 | Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages | 21 | 1,173 | 2,983 | 9k+ | | Non Prefixed Variable Found |
| #15 | Five Star Restaurant Reservations – WordPress Booking Plugin | 21 | 1,099 | 1,147 | 10k+ | | Output Not Escaped |
| #16 | Rocket Maintenance Mode & Coming Soon Page | 21 | 1,176 | 1,406 | 4k+ | | Non Prefixed Variable Found |
| #17 | Royal Addons for Elementor – Addons and Templates Kit for Elementor | 21 | 13,011 | 2,530 | 600k+ | | Text Domain Mismatch |
| #18 | WCFM – Frontend Manager for WooCommerce | 21 | 4,721 | 5,067 | 20k+ | | Non Prefixed Variable Found |
| #19 | Wise Chat | 21 | 470 | 506 | 5k+ | | Output Not Escaped |
| #20 | wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin | 21 | 1,354 | 1,140 | 70k+ | | Output Not Escaped |
| #21 | Better WordPress Minify | 22 | 412 | 484 | 8k+ | | Non Singular String Literal Domain |
| #22 | Captcha by BestWebSoft – Advanced Spam Protection, Math & OCR-Friendly Captcha for Site Forms | 22 | 493 | 295 | 10k+ | | Text Domain Mismatch |
| #23 | Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer | 22 | 2,858 | 1,270 | 50k+ | | Text Domain Mismatch |
| #24 | RegistrationMagic – User Registration Forms Plugin | 22 | 3,654 | 5,062 | 8k+ | | Non Prefixed Variable Found |
| #25 | SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager | 22 | 703 | 841 | 8k+ | | Non Prefixed Variable Found |
| #26 | Dynamic QR Code – generator | 22 | 238 | 208 | 6k+ | | missing direct file access protection |
| #27 | Easy Social Feed – Social Photos Gallery and Post Feed for WordPress | 22 | 1,567 | 1,277 | 30k+ | | Non Prefixed Variable Found |
| #28 | Events Manager – Calendar, Bookings, Tickets, and more! | 22 | 4,722 | 5,621 | 70k+ | | Output Not Escaped |
| #29 | FunnelKit Payment Gateway for Stripe WooCommerce | 22 | 244 | 321 | 20k+ | | Input Not Sanitized |
| #30 | IMPress for IDX Broker | 22 | 1,085 | 636 | 7k+ | | Text Domain Mismatch |
| #31 | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | 22 | 2,361 | 3,384 | 70k+ | | Non Prefixed Variable Found |
| #32 | MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. | 22 | 2,619 | 2,453 | 10k+ | | Output Not Escaped |
| #33 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | 22 | 1,581 | 2,326 | 300k+ | | Non Prefixed Variable Found |
| #34 | Swift Performance Lite | 22 | 2,346 | 1,325 | 7k+ | | Text Domain Mismatch |
| #35 | Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent | 22 | 225 | 519 | 8k+ | | error log error log |
| #36 | Theme Editor | 22 | 798 | 685 | 50k+ | | Output Not Escaped |
| #37 | ThemeHunk Customizer | 22 | 3,969 | 582 | 7k+ | | Text Domain Mismatch |
| #38 | Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links | 22 | 1,044 | 1,797 | 20k+ | | Non Prefixed Variable Found |
| #39 | URL Shortify – Simple and Easy URL Shortener | 22 | 1,520 | 2,689 | 10k+ | | Non Prefixed Variable Found |
| #40 | WCFM Marketplace – Multivendor Marketplace for WooCommerce | 22 | 1,937 | 1,969 | 10k+ | | Non Prefixed Variable Found |
| #41 | WCFM Membership – WooCommerce Memberships for Multivendor Marketplace | 22 | 559 | 675 | 10k+ | | Non Prefixed Variable Found |
| #42 | Fraud Prevention For WooCommerce and EDD | 22 | 572 | 1,394 | 5k+ | | Non Prefixed Variable Found |
| #43 | Advanced AJAX Product Filters | 22 | 2,683 | 1,205 | 50k+ | | Text Domain Mismatch |
| #44 | File Manager | 22 | 740 | 520 | 1m+ | | Unsafe Printing Function |
| #45 | Advanced Product Labels for WooCommerce | 23 | 921 | 559 | 20k+ | | Text Domain Mismatch |
| #46 | Autoptimize | 23 | 288 | 191 | 800k+ | | Output Not Escaped |
| #47 | Brave Popup Builder – Popup, Optins, Lead Generation, Survey & Interactive Content | 23 | 238 | 294 | 20k+ | | error log print r |
| #48 | Burger Companion | 23 | 3,274 | 472 | 10k+ | | Text Domain Mismatch |
| #49 | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | 23 | 264 | 1,018 | 5k+ | | Non Prefixed Variable Found |
| #50 | Ecwid by Lightspeed Ecommerce Shopping Cart | 23 | 339 | 307 | 20k+ | | missing direct file access protection |