
BadgeOS Community Add-on Security & Risk Analysis
wordpress.org/plugins/badgeos-community-add-onAdds BadgeOS features to BuddyPress and bbPress. Earn badges/points/ranks based on community activity, and display them on user profiles and activity …
Is BadgeOS Community Add-on Safe to Use in 2026?
Generally Safe
Score 85/100BadgeOS Community Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "badgeos-community-add-on" v1.3.1 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history are positive indicators of a well-maintained and secure plugin. The code analysis reveals good practices such as 100% of SQL queries using prepared statements and the absence of dangerous functions or file operations. However, a significant concern lies in the output escaping, where only 50% of outputs are properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed to users. The plugin's attack surface appears minimal with no entry points found without authentication checks, which is commendable.
Key Concerns
- Half of output escaping is not proper
BadgeOS Community Add-on Security Vulnerabilities
BadgeOS Community Add-on Code Analysis
SQL Query Safety
Output Escaping
BadgeOS Community Add-on Attack Surface
WordPress Hooks 73
Maintenance & Trust
BadgeOS Community Add-on Maintenance & Trust
Maintenance Signals
Community Trust
BadgeOS Community Add-on Alternatives
BadgeOS Invite Codes Add-on
badgeos-invite-codes-add-on
Enhances sites running BuddyPress and BadgeOS by joining users to one or more specified groups when they use a special Invite Code to join your site.
Open Badges Issuer Add-on
badgeos-open-badges-issuer-add-on
Issue Mozilla Open Badges directly from your site with this add-on for BadgeOS
BadgeOS Suggested Achievements Add-on
badgeos-suggested-achievements-add-on
Enhances sites running BuddyPress and BadgeOS by suggesting next possible incomplete achievements that a user can earn.
Credly Custom Badge Assertion Shortcode
credly-pro-custom-assertion
Easily create an official Credly Badge Assertion page on your site.
Activation Add-on for GamiPress
activation-add-on-for-gamipress
This GamiPress add-on adds a global switch in the Backend where the awarding of badges can be enabled and disabled.
BadgeOS Community Add-on Developer Profile
12 plugins · 720 total installs
How We Detect BadgeOS Community Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/badgeos-community-add-on/css/bos-community.css