
Badges Security & Risk Analysis
wordpress.org/plugins/badgesDisplay a set of badges based on files in a directory off the root of the blog.
Is Badges Safe to Use in 2026?
Generally Safe
Score 92/100Badges has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "badges" v2.5 plugin exhibits a seemingly strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events suggests a minimal attack surface. Furthermore, the code analysis indicates a lack of dangerous functions and SQL queries are exclusively handled via prepared statements, which are excellent security practices. The vulnerability history is also clean, with no known CVEs or past issues, suggesting a well-maintained plugin. However, a significant concern arises from the very low percentage of properly escaped output (5%). This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly in the browser without adequate sanitization. While the current analysis did not uncover specific taint flows, the lack of proper output escaping creates a fertile ground for such vulnerabilities to be exploited.
Key Concerns
- Low percentage of properly escaped output
- No capability checks found
- No nonce checks found
Badges Security Vulnerabilities
Badges Release Timeline
Badges Code Analysis
Output Escaping
Badges Attack Surface
WordPress Hooks 1
Maintenance & Trust
Badges Maintenance & Trust
Maintenance Signals
Community Trust
Badges Alternatives
Currently Reading
currently-reading
Displays a cover image of a book with a link to Google Books based on a supplied ISBN-10 or ISBN-13.
eBook WooSell
ebook-woohook
EBooks distribution plugin for woocommerce. Enable you to sell epub3 ebooks directly to EpubSystems cloud and E-reading Apps.
BNC BiblioShare
bnc-biblioshare
Displays a book's cover image, title, author, and other book data from BiblioShare
Bestseller Lists from the New York Times
bestseller-lists-from-new-york-times
Integrate bestseller lists from the New York Times into your own site with a user-friendly interface.
DeadTrees
dead-trees
Share the books you've read with your readers, family, & friends. Never again receive a book you've already read as a gift!
Badges Developer Profile
3 plugins · 150 total installs
How We Detect Badges
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/badges/HTML / DOM Fingerprints
badgegroupbadge<!-- #badge-id='badge-style='<div class='badgegroup'<div class='badge'