https://developer.wordpress.org/apis/security/ Our three most common reasons for not approving a plugin are: - The plugin contains unescaped output: [Learn about escaping data](https://developer.wordpress.org/apis/security/escaping/) - The plugin accepts unsanitised data: [Learn about sanitising data](https://developer.wordpress.org/apis/security/sanitizing/) - The plugin processes form data without a nonce: [Learn about nonces](https://developer.wordpress.org/apis/security/nonces/)