
BadgeOS BadgeStack Add-on Security & Risk Analysis
wordpress.org/plugins/badgeos-badgestack-add-onThis add-on to BadgeOS automatically creates achievement types, pages and sample content to jumpstart your own badging system.
Is BadgeOS BadgeStack Add-on Safe to Use in 2026?
Generally Safe
Score 85/100BadgeOS BadgeStack Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of badgeos-badgestack-add-on v1.0.3 reveals a generally strong security posture with no identified vulnerabilities in its code analysis or taint flows. The absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are positive indicators. Furthermore, the plugin demonstrates good practices by having no recorded CVEs, indicating a history of secure development or diligent patching.
However, the analysis does highlight some areas for potential improvement. The complete lack of entry points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual and might suggest limited functionality or that its features are integrated elsewhere. More critically, the absence of any nonce checks and capability checks across its (albeit nonexistent) entry points is a significant concern. While there are no identified attack vectors currently, if any entry points were to be introduced or discovered later, they would be inherently unprotected, leaving the plugin vulnerable to various attacks without proper authorization and integrity checks.
In conclusion, while badgeos-badgestack-add-on v1.0.3 appears to be secure based on the current code analysis and vulnerability history, the lack of essential security measures like nonce and capability checks on its entry points represents a latent risk. This omission could lead to vulnerabilities if the plugin's functionality expands or if new attack surfaces are discovered, even if none are apparent in the current version. Developers should consider implementing these checks as a proactive security measure.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- 1/3 outputs not properly escaped
BadgeOS BadgeStack Add-on Security Vulnerabilities
BadgeOS BadgeStack Add-on Code Analysis
Output Escaping
BadgeOS BadgeStack Add-on Attack Surface
WordPress Hooks 2
Maintenance & Trust
BadgeOS BadgeStack Add-on Maintenance & Trust
Maintenance Signals
Community Trust
BadgeOS BadgeStack Add-on Alternatives
BadgeOS Community Add-on
badgeos-community-add-on
Adds BadgeOS features to BuddyPress and bbPress. Earn badges/points/ranks based on community activity, and display them on user profiles and activity …
BadgeOS LearnDash Add-on
badgeos-learndash-add-on
BadgeOS achievements and badges earned from a wide array of LearnDash learning management system activity.
myCred Credly
mycred-credly
📢🚨 Important Notice: myCred Credly is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be provided.
BadgeOS Invite Codes Add-on
badgeos-invite-codes-add-on
Enhances sites running BuddyPress and BadgeOS by joining users to one or more specified groups when they use a special Invite Code to join your site.
Open Badges Issuer Add-on
badgeos-open-badges-issuer-add-on
Issue Mozilla Open Badges directly from your site with this add-on for BadgeOS
BadgeOS BadgeStack Add-on Developer Profile
12 plugins · 720 total installs
How We Detect BadgeOS BadgeStack Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/badgeos-badgestack-add-on/css/badgeos-badgestack.css/wp-content/plugins/badgeos-badgestack-add-on/js/badgeos-badgestack.js/wp-content/plugins/badgeos-badgestack-add-on/js/badgeos-badgestack.jsbadgeos-badgestack-add-on/css/badgeos-badgestack.css?ver=badgeos-badgestack-add-on/js/badgeos-badgestack.js?ver=HTML / DOM Fingerprints
Copyright © 2012-2013 LearningTimes, LLCThis program is free software: you can redistribute it and/or modify itunder the terms of the GNU Affero General Public License, version 3,as published by the Free Software Foundation.+6 moredata-badgeos-typeBadgeOS_BadgeStack[badgeos_achievements_list