Best Security WordPress Plugins

137 indexed plugins

Plugins

137

Active Installs

27m+

Average Score

48

Audited

133

RankPluginScoreErrorsWarningsInstallsUpdatedTop Issue
#1Dam Spam10011k+unexpected markdown file
#2Login Security Captcha100010k+No open findings
#3Stop XML-RPC Attacks10016k+Non Prefixed Class Found
#4Remove XML-RPC Methods10001k+No open findings
#5BotBlocker Security – Firewall & Bot Protection9953k+Non Prefixed Constant Found
#6Protect Uploads992140k+missing direct file access protection
#7Stop User Enumeration991150k+Dynamic Hookname Found
#8WPMasterToolKit (WPMTK) – All in one plugin99144k+trademarked term
#9App for Cloudflare®981011k+wp function not compatible with requires wp
#10Manage XML-RPC98316k+file system operations is writable
#11Prevent XSS Vulnerability981016k+Missing Arg Domain
#12Safe SVG98741m+Missing Arg Domain
#13WP Author Slug961662k+Text Domain Mismatch
#14WPVulnerability96410k+trademarked term
#15MilesWeb Tools9544910k+Non Prefixed Variable Found
#16Malcure Malware Shield — Removal, Repair, Monitor9575610k+wp function not compatible with requires wp
#17Stop Spammers Classic94185130k+wp function not compatible with requires wp
#18Sucuri Security – Auditing, Malware Scanner and Security Hardening94525600k+missing direct file access protection
#19XO Security945330k+wp function not compatible with requires wp
#20Restricted Site Access91141110k+Missing Arg Domain
#21WebAuthn Provider for Two Factor916141k+Missing Arg Domain
#22Password Strength Settings for WooCommerce8917610k+Missing Arg Domain
#23WP Admin Basic Auth87562k+Input Not Sanitized
#24AntiSpam for Contact Form 78614810k+Text Domain Mismatch
#25WP Ghost (Hide My WP Ghost) – Security & Firewall856373100k+Non Prefixed Variable Found
#26HSTS Ready853113k+Input Not Validated
#27Salt Shaker8515136k+Interpolated Not Prepared
#28Simple Automatic Updates851812k+Missing Translators Comment
#29WP Fail2Ban Redux821107k+trademarked term
#30Hostinger Tools8114223m+wp function not compatible with requires wp
#31Smart Passworded Pages801182k+wp function not compatible with requires wp
#32Melapress File Monitor8016906k+Non Prefixed Variable Found
#33OpenID Connect Generic Client7395910k+Non Prefixed Hookname Found
#34Simple Login Captcha70201910k+date date
#35Simple Login Lockdown691364k+Output Not Escaped
#36Content Security Policy Manager681922k+Output Not Escaped
#37Protection Against DDoS682253k+Output Not Escaped
#38Forget Spam Comment675109k+Input Not Sanitized
#39WP Anti-Clickjack664424k+Recommended
#40Inactive Logout64307110k+Non Prefixed Variable Found
#41Meta Generator and Version Info Remover52202810k+Non Prefixed Function Found
#42TrustedSite50291420k+Output Not Escaped
#43LWS Hide Login4555820k+Missing Unslash
#44Passwords Evolved4526171k+Output Not Escaped
#45BBQ Firewall – Fast & Powerful Firewall Security441717100k+Output Not Escaped
#46User Role Editor43117145700k+Output Not Escaped
#47Lock Down Admin4230203k+Unsafe Printing Function
#48Login No Captcha reCAPTCHA42452460k+Unsafe Printing Function
#49Proxy & VPN Blocker4210721k+Recommended
#50Two Factor421870100k+Recommended