
Custom Post Type Add-On for GamiPress Security & Risk Analysis
wordpress.org/plugins/custom-post-type-add-on-for-gamipressThis GamiPress add-on adds triggers for publishing and commenting on custom post types.
Is Custom Post Type Add-On for GamiPress Safe to Use in 2026?
Generally Safe
Score 85/100Custom Post Type Add-On for GamiPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "custom-post-type-add-on-for-gamipress" v1.0.0 reveals a generally strong security posture due to the absence of identified dangerous functions, file operations, external HTTP requests, and a lack of critical taint analysis findings. The complete absence of any recorded vulnerabilities, including CVEs, further suggests a mature and well-maintained codebase.
However, significant concerns arise from the complete lack of output escaping and the absence of nonce and capability checks across all identified entry points. While the current analysis shows zero entry points, this could be misleading if the plugin is intended to have interactive elements or if the analysis missed potential injection vectors. The 0% output escaping is a critical weakness, as it leaves the application vulnerable to cross-site scripting (XSS) attacks if any user-controlled data is ever rendered directly in the browser.
In conclusion, while the plugin benefits from a clean vulnerability history and absence of certain risky code patterns, the fundamental security flaws in output handling and lack of authorization checks represent a significant risk. The absence of these fundamental security measures, even with a currently small apparent attack surface, means that any future expansion or interaction with user input could easily lead to exploitable vulnerabilities, particularly XSS.
Key Concerns
- Output escaping is not properly implemented
- Nonce checks are missing
- Capability checks are missing
Custom Post Type Add-On for GamiPress Security Vulnerabilities
Custom Post Type Add-On for GamiPress Code Analysis
Output Escaping
Custom Post Type Add-On for GamiPress Attack Surface
WordPress Hooks 5
Maintenance & Trust
Custom Post Type Add-On for GamiPress Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post Type Add-On for GamiPress Alternatives
myCred Badgr Integration
mycred-badgr-achievement-badge
📢🚨 Important Notice: myCred Badgr is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be provided.
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
gamipress
Boost your gamification marketing & reward your users with points, achievements, badges & ranks to increase your site activity & loyalty!
GamiPress – Reset User
gamipress-reset-user
Reset all user earnings and logs from a single button.
BadgeOS Community Add-on
badgeos-community-add-on
Adds BadgeOS features to BuddyPress and bbPress. Earn badges/points/ranks based on community activity, and display them on user profiles and activity …
BadgeOS LearnDash Add-on
badgeos-learndash-add-on
BadgeOS achievements and badges earned from a wide array of LearnDash learning management system activity.
Custom Post Type Add-On for GamiPress Developer Profile
10 plugins · 70 total installs
How We Detect Custom Post Type Add-On for GamiPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-post-type-add-on-for-gamipress/languages/