
GamiPress – BadgeOS Importer Security & Risk Analysis
wordpress.org/plugins/gamipress-badgeos-importerTool to migrate all stored data from BadgeOS to GamiPress
Is GamiPress – BadgeOS Importer Safe to Use in 2026?
Generally Safe
Score 100/100GamiPress – BadgeOS Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the "gamipress-badgeos-importer" v1.1.9 plugin exhibits a generally strong security posture. The absence of dangerous functions, external HTTP requests, and file operations is commendable. Crucially, all SQL queries utilize prepared statements, and all output is properly escaped, mitigating common risks like SQL injection and XSS. The plugin also demonstrates good practice by implementing capability checks for all its AJAX handlers, ensuring that unauthorized users cannot trigger sensitive actions.
However, a notable area of concern is the complete lack of nonce checks on its 17 AJAX handlers. While capability checks are in place, nonce verification is a critical defense against Cross-Site Request Forgery (CSRF) attacks. Without it, an attacker could trick a logged-in user into performing unintended actions if they can craft a malicious request. The vulnerability history being clean is a positive indicator, suggesting that the developers have historically maintained good security, but the current static analysis reveals this potential gap.
In conclusion, the plugin has several robust security features, particularly in handling data and access control. The absence of known vulnerabilities is a significant strength. The primary weakness identified is the lack of nonce checks on AJAX actions, which represents a tangible risk that should be addressed to further harden the plugin's security.
Key Concerns
- Missing nonce checks on AJAX handlers
GamiPress – BadgeOS Importer Security Vulnerabilities
GamiPress – BadgeOS Importer Code Analysis
SQL Query Safety
Output Escaping
GamiPress – BadgeOS Importer Attack Surface
AJAX Handlers 17
WordPress Hooks 6
Maintenance & Trust
GamiPress – BadgeOS Importer Maintenance & Trust
Maintenance Signals
Community Trust
GamiPress – BadgeOS Importer Alternatives
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
gamipress
Boost your gamification marketing & reward your users with points, achievements, badges & ranks to increase your site activity & loyalty!
GamiPress – Reset User
gamipress-reset-user
Reset all user earnings and logs from a single button.
Connect GamiPress to Discord
connect-gamipress-and-discord
Create a community of your Members by connecting your GamiPress Website to your Discord server.
GamiPress – myCRED Importer
gamipress-mycred-importer
Tool to migrate all stored data from myCRED to GamiPress
GamiPress – WPAchievements Importer
gamipress-wpachievements-importer
Tool to migrate all stored data from WPAchievements to GamiPress
GamiPress – BadgeOS Importer Developer Profile
30 plugins · 25K total installs
How We Detect GamiPress – BadgeOS Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gamipress-badgeos-importer/assets/js/gamipress-badgeos-importer-admin.js/wp-content/plugins/gamipress-badgeos-importer/assets/js/gamipress-badgeos-importer-admin.min.js/wp-content/plugins/gamipress-badgeos-importer/assets/js/gamipress-badgeos-importer-admin.js/wp-content/plugins/gamipress-badgeos-importer/assets/js/gamipress-badgeos-importer-admin.min.jsgamipress-badgeos-importer/assets/js/gamipress-badgeos-importer-admin.js?ver=gamipress-badgeos-importer/assets/js/gamipress-badgeos-importer-admin.min.js?ver=HTML / DOM Fingerprints
gamipress_badgeos_importer