| #1 | AnyComment | 17 | 445 | 449 | 5k+ | | Output Not Escaped |
| #2 | WP Directory Kit | 18 | 2,119 | 2,617 | 2k+ | | Non Prefixed Variable Found |
| #3 | Block Slider – Responsive Image Slider, Video Slider & Post Slider | 19 | 555 | 1,291 | 3k+ | | Non Prefixed Variable Found |
| #4 | Robin Image Optimizer – Unlimited Image Optimization, WebP & AVIF | 20 | 557 | 541 | 100k+ | | Output Not Escaped |
| #5 | Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages | 21 | 1,173 | 2,983 | 9k+ | | Non Prefixed Variable Found |
| #6 | FunnelKit Payment Gateway for Stripe WooCommerce | 22 | 244 | 321 | 20k+ | | Input Not Sanitized |
| #7 | UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds | 22 | 444 | 243 | 200k+ | | Text Domain Mismatch |
| #8 | Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery | 23 | 2,119 | 986 | 400k+ | | Text Domain Mismatch |
| #9 | SecuPress with Simple SSL – Simple and Performant Security | 23 | 1,696 | 1,590 | 40k+ | | Non Prefixed Variable Found |
| #10 | Smart Slider 3 | 23 | 261 | 268 | 800k+ | | Non Prefixed Variable Found |
| #11 | Social Slider Feed – Social Media Feed & Gallery Widgets | 24 | 929 | 707 | 20k+ | | Non Prefixed Variable Found |
| #12 | Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant | 30 | 264 | 221 | 4k+ | | Missing Unslash |
| #13 | WooPayments: Integrated WooCommerce Payments | 30 | 177 | 298 | 900k+ | | Exception Not Escaped |
| #14 | WP 2FA – Two-factor authentication for WordPress | 30 | 269 | 380 | 100k+ | | Exception Not Escaped |
| #15 | WPOrLogin – Custom Login, Social Login, Limit Attempts, Hide Login & reCAPTCHA | 30 | 484 | 222 | 2k+ | | Unsafe Printing Function |
| #16 | Form Vibes – Database Manager for Forms | 31 | 176 | 284 | 10k+ | | Text Domain Mismatch |
| #17 | Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages | 32 | 53 | 773 | 9k+ | | Recommended |
| #18 | Thrive Automator | 32 | 84 | 84 | 10k+ | | Not Prepared |
| #19 | CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress | 35 | 20 | 10 | 100k+ | | Missing Arg Domain |
| #20 | CartPops – High Converting Add To Cart Popup For WooCommerce | 35 | 56 | 187 | 4k+ | | Non Prefixed Variable Found |
| #21 | Custom Order Status for WooCommerce | 35 | 20 | 60 | 10k+ | | Non Prefixed Hookname Found |
| #22 | Form Input Masks For Elementor Forms | 35 | 3 | 2 | 10k+ | | Non Prefixed Class Found |
| #23 | Iframely – WP media embeds, cards and blocks | 35 | 136 | 43 | 2k+ | | Unsafe Printing Function |
| #24 | Order Delivery Date for WooCommerce | 35 | 2,060 | 73 | 10k+ | | wp function not compatible with requires wp |
| #25 | SMNTCS Custom Logo Link | 35 | 48 | 1 | 3k+ | | badly named files |
| #26 | Abandoned Cart Lite for WooCommerce | 35 | 84 | 161 | 20k+ | | Non Prefixed Variable Found |
| #27 | WP Custom Cursors | WordPress Cursor Plugin | 36 | 691 | 390 | 9k+ | | Text Domain Mismatch |
| #28 | SendWP | 37 | 47 | 42 | 10k+ | | Output Not Escaped |
| #29 | CatFolders Document Gallery & PDF Library | 39 | 66 | 32 | 3k+ | | Output Not Escaped |
| #30 | Graphina – Charts and Graphs For Elementor | 39 | 1,895 | 113 | 10k+ | | Text Domain Mismatch |
| #31 | WP Server Health Stats | 39 | 66 | 31 | 10k+ | | Output Not Escaped |
| #32 | Hostinger Reach – AI-Powered Email Marketing for WordPress | 40 | 9 | 46 | 1m+ | | Direct Query |
| #33 | MailerSend – Official SMTP Integration | 40 | 39 | 25 | 2k+ | | Unsafe Printing Function |
| #34 | WP Meteor Website Speed Optimization Addon | 40 | 34 | 19 | 20k+ | | Output Not Escaped |
| #35 | 多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 | 42 | 17 | 38 | 2k+ | | Input Not Sanitized |
| #36 | Hide Cart Functions | 42 | 12 | 50 | 3k+ | | Recommended |
| #37 | ACF Quick Edit Fields | 49 | 20 | 72 | 30k+ | | Recommended |
| #38 | YayMail – WooCommerce Email Customizer | 51 | 162 | 762 | 50k+ | | Non Prefixed Variable Found |
| #39 | Wenprise Pinyin Slug | 52 | 30 | 34 | 4k+ | | Text Domain Mismatch |
| #40 | Holded integration | 55 | 72 | 23 | 2k+ | | Non Singular String Literal Domain |
| #41 | Disable Cart Fragments by Optimocha | 57 | 8 | 13 | 10k+ | | Recommended |
| #42 | Slider Factory | 61 | 3 | 414 | 2k+ | | Non Prefixed Variable Found |
| #43 | SMK Sidebar Generator | 64 | 19 | 5 | 10k+ | | Output Not Escaped |
| #44 | AI Product Gallery Slider for WooCommerce, Slider, Zoom, Video & Variation Images – WPBean | 65 | 264 | 16 | 2k+ | | Text Domain Mismatch |
| #45 | WP User Avatars | 68 | 5 | 20 | 20k+ | | Input Not Sanitized |
| #46 | SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) | 69 | 17 | 952 | 6k+ | | Non Prefixed Variable Found |
| #47 | SmartSMTP | 72 | 7 | 37 | 2k+ | | Recommended |
| #48 | Testimonial – Testimonial Slider and Showcase Plugin | 75 | 563 | 231 | 30k+ | | Text Domain Mismatch |
| #49 | Change Mail Sender | 76 | 97 | 19 | 20k+ | | Text Domain Mismatch |
| #50 | SureRank SEO – Smart Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema | 77 | 58 | 94 | 300k+ | | Non Prefixed Hookname Found |