Custom Post Type Add-On for GamiPress Security & Risk Analysis

wordpress.org/plugins/custom-post-type-add-on-for-gamipress

This GamiPress add-on adds triggers for publishing and commenting on custom post types.

10 active installs v1.0.0 PHP 5.5.9+ WP 4.4+ Updated Nov 6, 2020
achievementbadgebadgesopen-badgesopenbadges
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Post Type Add-On for GamiPress Safe to Use in 2026?

Generally Safe

Score 85/100

Custom Post Type Add-On for GamiPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of "custom-post-type-add-on-for-gamipress" v1.0.0 reveals a generally strong security posture due to the absence of identified dangerous functions, file operations, external HTTP requests, and a lack of critical taint analysis findings. The complete absence of any recorded vulnerabilities, including CVEs, further suggests a mature and well-maintained codebase.

However, significant concerns arise from the complete lack of output escaping and the absence of nonce and capability checks across all identified entry points. While the current analysis shows zero entry points, this could be misleading if the plugin is intended to have interactive elements or if the analysis missed potential injection vectors. The 0% output escaping is a critical weakness, as it leaves the application vulnerable to cross-site scripting (XSS) attacks if any user-controlled data is ever rendered directly in the browser.

In conclusion, while the plugin benefits from a clean vulnerability history and absence of certain risky code patterns, the fundamental security flaws in output handling and lack of authorization checks represent a significant risk. The absence of these fundamental security measures, even with a currently small apparent attack surface, means that any future expansion or interaction with user input could easily lead to exploitable vulnerabilities, particularly XSS.

Key Concerns

  • Output escaping is not properly implemented
  • Nonce checks are missing
  • Capability checks are missing
Vulnerabilities
None known

Custom Post Type Add-On for GamiPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Post Type Add-On for GamiPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Custom Post Type Add-On for GamiPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_noticesgamipress-cpt.php:44
actionplugins_loadedgamipress-cpt.php:45
actioncomment_postincludes\rules-engine.php:53
actiontransition_comment_statusincludes\rules-engine.php:54
filtergamipress_activity_triggersincludes\rules-engine.php:68
Maintenance & Trust

Custom Post Type Add-On for GamiPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedNov 6, 2020
PHP min version5.5.9
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Custom Post Type Add-On for GamiPress Developer Profile

konnektiv

10 plugins · 70 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Post Type Add-On for GamiPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-post-type-add-on-for-gamipress/languages/

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Custom Post Type Add-On for GamiPress