2 Dec 2024

Plugin Security Scorecard November Results

November was the fourth full month our Plugin Security Scorecard was available. A fair amount of plugins were checked. A total of 78 plugins were checked last month. With 17 of those plugins being security plugins.

As can be seen below, the results for security plugins were not good. With only five of those plugins getting a C or above. That comes from a combination of different issues. Some of those plugins have security issues. Some come from developers that have had repeated issues with vulnerabilities and are not addressing the underlying problems. Most security plugins are failing to implement best practices for security. Then there is the issue of the plugin developers making security claims that are at least not supported with evidence (and often couldn’t be supported with evidence, since they are not true).

The overall results were better than those for just security plugins, but not great. Only one plugin, The SEO Framework, got an A this month. No plugins got an A+ or B+. Those three grades require the developer is taking proactive measures with security, so most plugin developers are not taking measures to provide the best security. 16 of the plugins did get a B, which requires that they are avoiding unnecessary security issues.

November Security Scorecard Grades for  Security Plugins

November Security Scorecard Grades for Other Plugins

Leave a Reply

Your email address will not be published.