Activation Add-on for GamiPress Security & Risk Analysis

wordpress.org/plugins/activation-add-on-for-gamipress

This GamiPress add-on adds a global switch in the Backend where the awarding of badges can be enabled and disabled.

0 active installs v1.0.0 PHP 5.5.9+ WP 4.4+ Updated Nov 2, 2020
badgebadgescredlyobiopenbadges
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Activation Add-on for GamiPress Safe to Use in 2026?

Generally Safe

Score 85/100

Activation Add-on for GamiPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of 'activation-add-on-for-gamipress' v1.0.0 reveals a plugin with a remarkably small attack surface, reporting zero entry points. This is a strong indicator of good development practices in terms of limiting exposure. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are positive signs. However, a significant concern arises from the complete lack of output escaping for the two identified outputs. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities if the data being output is not sufficiently sanitized before insertion. The lack of nonce and capability checks on any potential entry points (though none were identified) is also a weakness, as it implies that if new entry points were added or discovered, they might lack essential authentication and authorization measures. The plugin's vulnerability history is clean, with no recorded CVEs, which is reassuring. This, combined with the limited attack surface, suggests a generally well-maintained codebase. The primary risk lies in the unescaped output, which should be addressed to prevent potential XSS attacks.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Activation Add-on for GamiPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Activation Add-on for GamiPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Activation Add-on for GamiPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_noticesgamipress-activation-addon.php:46
actionplugins_loadedgamipress-activation-addon.php:47
actionwp_print_scriptsgamipress-activation-addon.php:48
actionadmin_noticesincludes\actions-filters.php:57
filtergamipress_user_deserves_triggerincludes\actions-filters.php:74
filteruser_has_access_to_achievementincludes\actions-filters.php:75
filtergamipress_update_user_trigger_countincludes\actions-filters.php:76
filtergamipress_settings_addons_meta_boxesincludes\actions-filters.php:79
Maintenance & Trust

Activation Add-on for GamiPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedNov 2, 2020
PHP min version5.5.9
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Activation Add-on for GamiPress Developer Profile

konnektiv

10 plugins · 70 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Activation Add-on for GamiPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gamipress-activation-addon/css/admin.css/wp-content/plugins/gamipress-activation-addon/js/admin.js
Script Paths
/wp-content/plugins/gamipress-activation-addon/js/admin.js
Version Parameters
gamipress-activation-addon/css/admin.css?ver=gamipress-activation-addon/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
gamipress-activation-addon-settings
Data Attributes
data-gamipress-activation-addon-settings
JS Globals
gamipress_activation_addon_params
FAQ

Frequently Asked Questions about Activation Add-on for GamiPress