Skip to main content
WP HealthKit
Live CVE Data

Plugin Vulnerability Timeline

High-risk WordPress plugins with known vulnerabilities, tracked in real time.

5

Plugins with CRITICAL issues

11

Plugins with HIGH risk

Flagged Plugins

Ordered by active install count. Click “View Report” to see the full audit breakdown.

PluginRiskGradeFindingsActive InstallsLast AuditedView

Contact Form 7

v6.1.5

CRITICALD42710.0M+24 Mar 2026View Report

Classic Editor

v1.6.7

HIGHC179.0M+24 Mar 2026View Report

Akismet Anti-spam: Spam Protection

v5.7

HIGHD1036.0M+24 Mar 2026View Report

UpdraftPlus: WP Backup & Migration Plugin

v1.26.4

CRITICALD1,1133.0M+8 Apr 2026View Report

Classic Widgets

v0.3

HIGHB172.0M+10 Apr 2026View Report

WordPress Importer

v0.9.5

HIGHD3442.0M+10 Apr 2026View Report

WPS Hide Login

v1.9.18

HIGHB562.0M+11 Apr 2026View Report

WP Super Cache

v3.1.0

HIGHD4911.0M+10 Apr 2026View Report

Loco Translate

v2.8.4

CRITICALD3731.0M+9 Apr 2026View Report

Regenerate Thumbnails

v3.1.6

HIGHB591.0M+11 Apr 2026View Report

SVG Support

v2.5.14

HIGHD1571.0M+9 Apr 2026View Report

Custom Post Type UI

v1.19.2

HIGHD2021.0M+9 Apr 2026View Report

Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode

v6.20.1

HIGHC906700K+10 Apr 2026View Report

Ocean Extra

v2.5.5

CRITICALD1,575500K+11 Apr 2026View Report

WP Shortcodes Plugin — Shortcodes Ultimate

v7.5.0

HIGHD614400K+10 Apr 2026View Report

SiteOrigin Widgets Bundle

v1.72.0

CRITICALD684400K+11 Apr 2026View Report

Risk Level Breakdown

Distribution of risk levels across all audited plugins.

CRITICAL
5 plugins31%
HIGH
11 plugins69%
MEDIUM
0 plugins0%
LOW
0 plugins0%

What to Do If Your Plugin Is Listed

1

Review the full audit report

Click View Report next to your plugin to see every finding, its severity, and a description of the issue. Each finding includes actionable remediation guidance.

2

Prioritise critical findings first

CRITICAL findings typically involve known CVEs, direct SQL injection, remote code execution, or missing authentication. These should be patched before any other work.

3

Use WP HealthKit AutoFix (beta)

For coding standards and static analysis findings, the AutoFix engine can generate patch suggestions. Review all suggestions before applying them.

4

Re-audit after fixes

Once you have pushed a fix, run a new audit from your WP HealthKit dashboard. If the CRITICAL or HIGH findings are resolved, the risk level will update on the next hourly cache cycle.

5

Claim your plugin listing

Verified developers can add a security statement, link to changelogs, and display a WP HealthKit trust badge on their wordpress.org listing.

Audit your plugin for free

Run the full 46-layer WP HealthKit audit and get a detailed security report in minutes. No account required for public plugins.

Audit your plugin