Best Security WordPress Plugins

137 indexed plugins

Plugins

137

Active Installs

27m+

Average Score

48

Audited

137

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#1Dam Spam10011k+unexpected markdown file
#2Login Security Captcha100010k+No open findings
#3Stop XML-RPC Attacks10016k+Non-prefixed class
#4Remove XML-RPC Methods10001k+No open findings
#5BotBlocker Security – Firewall & Bot Protection9953k+Non-prefixed constant
#6Protect Uploads992140k+Missing direct file access protection
#7Stop User Enumeration991150k+Dynamic hook name
#8WPMasterToolKit (WPMTK) – All in one plugin99144k+trademarked term
#9App for Cloudflare®981011k+wp function not compatible with requires wp
#10Manage XML-RPC98316k+file system operations is writable
#11Prevent XSS Vulnerability981016k+Missing Arg Domain
#12Safe SVG98741m+Missing Arg Domain
#13WP Author Slug961662k+Text Domain Mismatch
#14WPVulnerability96410k+trademarked term
#15MilesWeb Tools9544910k+Non-prefixed global variable
#16Malcure Malware Shield — Removal, Repair, Monitor9575610k+wp function not compatible with requires wp
#17Stop Spammers Classic94185130k+wp function not compatible with requires wp
#18Sucuri Security – Auditing, Malware Scanner and Security Hardening94525600k+Missing direct file access protection
#19XO Security945330k+wp function not compatible with requires wp
#20Restricted Site Access91141110k+Missing Arg Domain
#21WebAuthn Provider for Two Factor916141k+Missing Arg Domain
#22Password Strength Settings for WooCommerce8917610k+Missing Arg Domain
#23WP Admin Basic Auth87562k+Input is not sanitized
#24AntiSpam for Contact Form 78614810k+Text Domain Mismatch
#25WP Ghost (Hide My WP Ghost) – Security & Firewall856373100k+Non-prefixed global variable
#26HSTS Ready853113k+Input is not validated
#27Salt Shaker8515136k+Interpolated SQL is not prepared
#28Simple Automatic Updates851812k+Missing Translators Comment
#29WP Fail2Ban Redux821107k+trademarked term
#30Hostinger Tools8114223m+wp function not compatible with requires wp
#31Smart Passworded Pages801182k+wp function not compatible with requires wp
#32Melapress File Monitor8016906k+Non-prefixed global variable
#33Disable WP Registration Page Spam775121k+Nonce verification recommended
#34OpenID Connect Generic Client7395910k+Non-prefixed hook name
#35Simple Login Captcha70201910k+date date
#36Simple Login Lockdown691364k+Output is not escaped
#37Content Security Policy Manager681922k+Output is not escaped
#38Protection Against DDoS682253k+Output is not escaped
#39Forget Spam Comment675109k+Input is not sanitized
#40WP Anti-Clickjack664424k+Nonce verification recommended
#41Inactive Logout64307110k+Non-prefixed global variable
#42Meta Generator and Version Info Remover52202810k+Non-prefixed function
#43Block IPs for Gravity Forms508361k+Request data is not unslashed
#44TrustedSite50291420k+Output is not escaped
#45LWS Hide Login4555820k+Request data is not unslashed
#46Passwords Evolved4526171k+Output is not escaped
#47BBQ Firewall – Fast & Powerful Firewall Security441717100k+Output is not escaped
#48User Role Editor43117145700k+Output is not escaped
#49Lock Down Admin4230203k+Unsafe printing function
#50Login No Captcha reCAPTCHA42452460k+Unsafe printing function