
Open Badges Issuer Add-on Security & Risk Analysis
wordpress.org/plugins/badgeos-open-badges-issuer-add-onIssue Mozilla Open Badges directly from your site with this add-on for BadgeOS
Is Open Badges Issuer Add-on Safe to Use in 2026?
Generally Safe
Score 100/100Open Badges Issuer Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "badgeos-open-badges-issuer-add-on" plugin v1.1.2 exhibits a mixed security posture. While the absence of known CVEs and the use of prepared statements for SQL queries are positive indicators, several areas raise concerns. The plugin exposes an unprotected AJAX handler, creating a significant attack vector. Furthermore, the low percentage of properly escaped output suggests a risk of cross-site scripting (XSS) vulnerabilities when user-supplied data is rendered without adequate sanitization.
The static analysis reveals a relatively small attack surface with only one unprotected entry point, an AJAX handler. The lack of taint analysis flows and dangerous functions might suggest a limited potential for complex exploits, but this is overshadowed by the identified risks. The vulnerability history is clean, which is a strong positive, implying a generally well-maintained codebase or limited historical exposure. However, this alone does not negate the immediate risks identified in the static analysis. Overall, while the plugin has a clean vulnerability record and avoids dangerous coding patterns, the unprotected AJAX handler and inadequate output escaping represent concrete security weaknesses that require attention.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
Open Badges Issuer Add-on Security Vulnerabilities
Open Badges Issuer Add-on Code Analysis
Output Escaping
Open Badges Issuer Add-on Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 12
Maintenance & Trust
Open Badges Issuer Add-on Maintenance & Trust
Maintenance Signals
Community Trust
Open Badges Issuer Add-on Alternatives
BadgeOS Community Add-on
badgeos-community-add-on
Adds BadgeOS features to BuddyPress and bbPress. Earn badges/points/ranks based on community activity, and display them on user profiles and activity …
BadgeOS Invite Codes Add-on
badgeos-invite-codes-add-on
Enhances sites running BuddyPress and BadgeOS by joining users to one or more specified groups when they use a special Invite Code to join your site.
BadgeOS Suggested Achievements Add-on
badgeos-suggested-achievements-add-on
Enhances sites running BuddyPress and BadgeOS by suggesting next possible incomplete achievements that a user can earn.
Credly Custom Badge Assertion Shortcode
credly-pro-custom-assertion
Easily create an official Credly Badge Assertion page on your site.
Activation Add-on for GamiPress
activation-add-on-for-gamipress
This GamiPress add-on adds a global switch in the Backend where the awarding of badges can be enabled and disabled.
Open Badges Issuer Add-on Developer Profile
4 plugins · 40 total installs
How We Detect Open Badges Issuer Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/badgeos-open-badges-issuer-add-on/css/badgeos-backpack.css/wp-content/plugins/badgeos-open-badges-issuer-add-on/js/badgeos-backpack.jshttps://backpack.openbadges.org/issuer.jsbadgeos-open-badges-issuer-add-on/js/badgeos-backpack.js?ver=1.1.1badgeos-open-badges-issuer-add-on/css/badgeos-backpack.css?ver=1.1.0HTML / DOM Fingerprints
badgeos_backpack_pushedbadgeos_user_id/wp-json/badge/[badgeos_backpack_push][badgeos_backpack_registered_email]