
BadgeOS Suggested Achievements Add-on Security & Risk Analysis
wordpress.org/plugins/badgeos-suggested-achievements-add-onEnhances sites running BuddyPress and BadgeOS by suggesting next possible incomplete achievements that a user can earn.
Is BadgeOS Suggested Achievements Add-on Safe to Use in 2026?
Generally Safe
Score 85/100BadgeOS Suggested Achievements Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'badgeos-suggested-achievements-add-on' plugin version 1.1.1 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query handling and the absence of dangerous functions or file operations, significant concerns arise from its attack surface. The plugin exposes four AJAX handlers, all of which lack authentication checks. This is a critical weakness that could allow unauthorized users to trigger potentially sensitive actions. Additionally, the lack of any nonce checks further exacerbates this issue, making the AJAX endpoints susceptible to Cross-Site Request Forgery (CSRF) attacks. The taint analysis and vulnerability history are clean, which is positive, but this does not mitigate the immediate risks posed by the unprotected entry points.
Key Concerns
- AJAX handlers without auth checks
- No nonce checks on AJAX handlers
- Insufficient output escaping
BadgeOS Suggested Achievements Add-on Security Vulnerabilities
BadgeOS Suggested Achievements Add-on Code Analysis
SQL Query Safety
Output Escaping
BadgeOS Suggested Achievements Add-on Attack Surface
AJAX Handlers 4
WordPress Hooks 7
Maintenance & Trust
BadgeOS Suggested Achievements Add-on Maintenance & Trust
Maintenance Signals
Community Trust
BadgeOS Suggested Achievements Add-on Alternatives
BadgeOS Community Add-on
badgeos-community-add-on
Adds BadgeOS features to BuddyPress and bbPress. Earn badges/points/ranks based on community activity, and display them on user profiles and activity …
BadgeOS Invite Codes Add-on
badgeos-invite-codes-add-on
Enhances sites running BuddyPress and BadgeOS by joining users to one or more specified groups when they use a special Invite Code to join your site.
Open Badges Issuer Add-on
badgeos-open-badges-issuer-add-on
Issue Mozilla Open Badges directly from your site with this add-on for BadgeOS
Credly Custom Badge Assertion Shortcode
credly-pro-custom-assertion
Easily create an official Credly Badge Assertion page on your site.
Activation Add-on for GamiPress
activation-add-on-for-gamipress
This GamiPress add-on adds a global switch in the Backend where the awarding of badges can be enabled and disabled.
BadgeOS Suggested Achievements Add-on Developer Profile
12 plugins · 720 total installs
How We Detect BadgeOS Suggested Achievements Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/badgeos-suggested-achievements-add-on/css/style.css/wp-content/plugins/badgeos-suggested-achievements-add-on/js/suggested-achievements.js/wp-content/plugins/badgeos-suggested-achievements-add-on/js/suggested-achievements.jsbadgeos-suggested-achievements/css/style.css?ver=badgeos-suggested-achievements-add-on/js/suggested-achievements.js?ver=HTML / DOM Fingerprints
suggested_achievements_classdata-textBosSuggestedAcsVars