| #1 | Themify Builder | 9 | 5,195 | 2,096 | 5k+ | | Text Domain Mismatch |
| #2 | wpForo Forum | 17 | 4,033 | 2,922 | 20k+ | | Unsafe printing function |
| #3 | WPtouch – Make your WordPress Website Mobile-Friendly | 17 | 1,466 | 325 | 50k+ | | Text Domain Mismatch |
| #4 | Podlove Podcast Publisher | 18 | 2,326 | 1,429 | 3k+ | | Output is not escaped |
| #5 | Property Hive | 18 | 1,957 | 6,027 | 3k+ | | Missing nonce verification |
| #6 | Element Pack – Widgets, Templates & Addons for Elementor | 19 | 9,448 | 517 | 100k+ | | Text Domain Mismatch |
| #7 | Download Monitor | 19 | 425 | 1,364 | 80k+ | | Non-prefixed hook name |
| #8 | Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization | 19 | 1,295 | 2,679 | 9k+ | | Output is not escaped |
| #9 | Razorpay Payment Button Plugin | 19 | 486 | 98 | 2k+ | | Exception output is not escaped |
| #10 | Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) | 19 | 541 | 385 | 3m+ | | Missing Translators Comment |
| #11 | DMCA Protection Badge | 20 | 4,425 | 217 | 1k+ | | Output is not escaped |
| #12 | Filter Everything — WordPress & WooCommerce Filters | 20 | 568 | 730 | 50k+ | | Output is not escaped |
| #13 | MBE eShip | 20 | 527 | 740 | 1k+ | | Non-prefixed global variable |
| #14 | Microthemer Lite – Visual Editor to Customize CSS | 20 | 1,004 | 1,699 | 10k+ | | Non-prefixed global variable |
| #15 | Nimble Page Builder | 20 | 1,591 | 1,684 | 30k+ | | Missing Arg Domain |
| #16 | Razorpay for WooCommerce | 20 | 974 | 855 | 100k+ | | Non-prefixed function |
| #17 | Store Locator WordPress | 21 | 2,372 | 1,572 | 10k+ | | Text Domain Mismatch |
| #18 | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce | 21 | 461 | 614 | 200k+ | | Text Domain Mismatch |
| #19 | ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support | 21 | 829 | 5,966 | 5k+ | | Direct Query |
| #20 | Feeds for YouTube (YouTube video, channel, and gallery plugin) | 21 | 558 | 978 | 100k+ | | Output is not escaped |
| #21 | Mapster WP Maps | 21 | 3,440 | 2,903 | 3k+ | | Text Domain Mismatch |
| #22 | Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | 21 | 1,918 | 5,065 | 10k+ | | Non-prefixed hook name |
| #23 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | 21 | 696 | 1,483 | 50k+ | | Nonce verification recommended |
| #24 | Rocket Maintenance Mode & Coming Soon Page | 21 | 1,176 | 1,406 | 4k+ | | Non-prefixed global variable |
| #25 | Royal Addons for Elementor – Addons and Templates Kit for Elementor | 21 | 13,011 | 2,530 | 600k+ | | Text Domain Mismatch |
| #26 | Shortcodes and extra features for Phlox theme | 22 | 413 | 426 | 90k+ | | Output is not escaped |
| #27 | Borderless – Addons and Templates for Elementor | 22 | 438 | 1,388 | 5k+ | | Non-prefixed global variable |
| #28 | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | 22 | 3,654 | 5,061 | 8k+ | | Non-prefixed global variable |
| #29 | EleSpare – News, Magazine and Blog Addons for Elementor | 22 | 733 | 1,423 | 10k+ | | Non-prefixed global variable |
| #30 | Events Manager – Calendar, Bookings, Tickets, and more! | 22 | 4,722 | 5,621 | 70k+ | | Output is not escaped |
| #31 | Falang multilanguage for WordPress | 22 | 716 | 769 | 1k+ | | Output is not escaped |
| #32 | Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms | 22 | 1,037 | 722 | 20k+ | | Unsafe printing function |
| #33 | Csomagpontok és Címkék WooCommerce-hez | 22 | 2,001 | 769 | 7k+ | | Text Domain Mismatch |
| #34 | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | 22 | 2,361 | 3,384 | 70k+ | | Non-prefixed global variable |
| #35 | Leyka | 22 | 253 | 3,445 | 2k+ | | Request data is not unslashed |
| #36 | MailOptin – Popup, Optin Forms & Email Newsletters for Mailchimp, HubSpot, AWeber Etc. | 22 | 2,619 | 2,453 | 10k+ | | Output is not escaped |
| #37 | Prime Mover – Migrate WordPress Website & Backups | 22 | 1,326 | 1,600 | 10k+ | | Non-prefixed global variable |
| #38 | ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF | 22 | 1,044 | 799 | 300k+ | | Non-prefixed global variable |
| #39 | Simple Job Board | 22 | 634 | 1,355 | 10k+ | | Non-prefixed global variable |
| #40 | Slick Popup: Contact Form 7 Popup Plugin | 22 | 2,322 | 316 | 2k+ | | Text Domain Mismatch |
| #41 | Slim Jetpack | 22 | 2,586 | 1,947 | 2k+ | | Text Domain Mismatch |
| #42 | NextScripts: Social Networks Auto-Poster | 22 | 2,408 | 1,133 | 30k+ | | Output is not escaped |
| #43 | Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent | 22 | 225 | 519 | 8k+ | | error log error log |
| #44 | 10Web Booster – Website speed optimization, Cache & Page Speed optimizer | 22 | 513 | 601 | 80k+ | | Non-prefixed global variable |
| #45 | ThemeHunk Customizer | 22 | 3,969 | 582 | 7k+ | | Text Domain Mismatch |
| #46 | Welcart e-Commerce | 22 | 10,377 | 10,896 | 10k+ | | Text Domain Mismatch |
| #47 | Advanced AJAX Product Filters | 22 | 2,683 | 1,205 | 50k+ | | Text Domain Mismatch |
| #48 | CoDesigner – All in One Elementor WooCommerce Builder | 22 | 4,131 | 774 | 5k+ | | Text Domain Mismatch |
| #49 | WP Express Checkout (Fast Payments via PayPal & Stripe) | 22 | 591 | 627 | 1k+ | | Output is not escaped |
| #50 | WPSSO Core – Complete Schema Markup and Meta Tags | 22 | 1,407 | 412 | 5k+ | | Missing Translators Comment |