Security Scorecard for WordPress Plugins






Check Plugin Not in WordPress Plugin Directory

Subscribers of our service can submit ZIP files of plugins that are not in the WordPress Plugin Directory to have them checked. (Not all issues can be checked for with uploaded plugins, as they require data not available with just the plugin's files.) You can sign up for the service for free here. For existing subscribers, once you are logged in to your account, return to this page to access that functionality.

The results of these gradings will not be stored.

About the Scorecard

Looking to get a better handle on the security of WordPress plugins? This scorecard tool grades plugins' handling of security based on data coming from the Plugin Vulnerabilities service, checking over the contents of the plugin, the WordPress.org API, and data generated specifically for the tool. It provides a useful, but incomplete, understanding of the security posture of the plugin and its developer.

Grades are calculated based on issues with any of the following:

  • Plugins known to be vulnerable
  • Plugin developers with track records of improperly handling security problems
  • Security issues in the plugin that can be detected in an automated fashion
  • Issues with the developer's development processes that suggest that there could be problems with security
  • Plugins making unsupported, misleading, and false claims about their handling of security and the handling of security with WordPress

We are working to expand and refine the tools' ability to provide a good measure of plugins' security status. If you are aware of an additional security concern with a plugin that isn't represented in our grading, please contact us. Other feedback on the tool is also welcome.

If you want a comprehensive understanding of the security of the plugin, a well-done security review is really needed to provide that.

Plugin Security Scorecard API

Looking to incorporate the grades that WordPress plugins have received from the Plugin Security Scorecard in to your own solution? We have you covered with a JSON based API.

Latest WordPress Plugin Security Scorecard Grades

You can follow the recent results of the Plugin Security Scorecard through the tool's Bluesky account.

Latest Security Scorecard Grades for WordPress Security Plugins

Latest WordPress Plugin Security Scorecard A Grades

Latest WordPress Plugin Security Scorecard F Grades


WordPress Plugin Security Scorecard Grades by Category