
Achievement Shortcode Add-On for GamiPress Security & Risk Analysis
wordpress.org/plugins/achievement-shortcode-add-on-for-gamipressThis GamiPress Add-on adds a shortcode to show or hide content depending on the user having earned a specific achievement.
Is Achievement Shortcode Add-On for GamiPress Safe to Use in 2026?
Generally Safe
Score 85/100Achievement Shortcode Add-On for GamiPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "achievement-shortcode-add-on-for-gamipress" plugin v1.0.0 reveals a very strong security posture. The absence of any identified dangerous functions, raw SQL queries, file operations, external HTTP requests, or vulnerabilities in the plugin's history is highly commendable. Furthermore, the plugin has zero identified entry points that are unprotected, indicating a robust approach to access control for AJAX handlers, REST API routes, shortcodes, and cron events.
While the plugin demonstrates excellent security practices, the static analysis does highlight a couple of minor areas for potential improvement. With 75% of output properly escaped, there is still a small percentage that is not, which could theoretically lead to cross-site scripting vulnerabilities if the unescaped output contains user-controlled data. Additionally, the complete lack of nonce and capability checks across all identified entry points (which, in this case, is zero) is a theoretical concern. While there are no active entry points to exploit, future development or changes to the plugin could introduce them, and establishing a baseline of security checks would be prudent.
Overall, the plugin is exceptionally secure based on the provided data. Its clean code, absence of known vulnerabilities, and lack of exploitable attack surface are significant strengths. The minor concerns regarding output escaping and the absence of any checks are extremely low risk given the current state, but worth noting for future development to maintain this high level of security.
Key Concerns
- Unescaped output present
- No nonce checks
- No capability checks
Achievement Shortcode Add-On for GamiPress Security Vulnerabilities
Achievement Shortcode Add-On for GamiPress Code Analysis
Output Escaping
Achievement Shortcode Add-On for GamiPress Attack Surface
WordPress Hooks 4
Maintenance & Trust
Achievement Shortcode Add-On for GamiPress Maintenance & Trust
Maintenance Signals
Community Trust
Achievement Shortcode Add-On for GamiPress Alternatives
Achievement Shortcode Add-On for BadgeOS
achievement-shortcode-for-badgeos
This BadgeOS Add-on adds a shortcode to show or hide content depending on the user having earned a specific achievement.
Award On Click Add-On for GamiPress
award-on-click-for-gamipress
This GamiPress Add-on adds a shortcode to show a link. The user is awarded a specified achievement when the link is clicked.
Award On Click Add-On for BadgeOS
award-on-click-add-on-for-badgeos
This BadgeOS Add-on adds a shortcode to show a link. The user is awarded a specified achievement when the link is clicked.
Code School Badges
code-school-badges
Provides both widgets and shortcodes to help display Code School profile badges on your website.
Advanced Access Manager – Access Governance for WordPress
advanced-access-manager
Access Governance for WordPress. Control roles, users, content, admin areas, and APIs to prevent broken access controls and excessive privileges.
Achievement Shortcode Add-On for GamiPress Developer Profile
10 plugins · 70 total installs
How We Detect Achievement Shortcode Add-On for GamiPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/achievement-shortcode-add-on-for-gamipress/js/rangyinputs-jquery-src.js/wp-content/plugins/achievement-shortcode-add-on-for-gamipress/js/achievement-shortcode-embed.js/wp-content/plugins/achievement-shortcode-add-on-for-gamipress/js/rangyinputs-jquery-src.js/wp-content/plugins/achievement-shortcode-add-on-for-gamipress/js/achievement-shortcode-embed.js/wp-content/plugins/achievement-shortcode-add-on-for-gamipress/js/rangyinputs-jquery-src.js?ver=/wp-content/plugins/achievement-shortcode-add-on-for-gamipress/js/achievement-shortcode-embed.js?ver=HTML / DOM Fingerprints
gamipress-post-selectorgamipress-switchdata-post-typedata-placeholder<div class="error">You have to specify a valid achievement id in the "id" parameter!</div>