GamiPress – BuddyPress Group Leaderboard Security & Risk Analysis

wordpress.org/plugins/gamipress-buddypress-group-leaderboard

Add a completely configurable tab on BuddyPress groups with a GamiPress leaderboard of group members

300 active installs v1.1.4 PHP + WP 4.4+ Updated Dec 1, 2025
achievementgamificationgamifygamipresspoint
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GamiPress – BuddyPress Group Leaderboard Safe to Use in 2026?

Generally Safe

Score 100/100

GamiPress – BuddyPress Group Leaderboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The gamipress-buddypress-group-leaderboard plugin v1.1.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. The absence of known vulnerabilities and bundled libraries is also a strong indicator of responsible development. However, a significant concern arises from the presence of an unprotected AJAX handler. This single unprotected entry point, while seemingly isolated, presents a potential avenue for attackers to exploit without proper authentication or authorization checks, which could lead to unintended actions or data manipulation.

The code analysis reveals one AJAX handler that lacks authentication checks, forming a critical weakness in its security design. While no critical or high severity taint flows were detected, this unprotected entry point is a direct pathway for potential misuse. The plugin's history of zero vulnerabilities suggests a generally secure codebase, but this does not negate the immediate risk posed by the identified unprotected AJAX handler. A balanced conclusion highlights the plugin's strengths in secure SQL handling and its clean vulnerability history, but it is critically undermined by the presence of an unprotected AJAX endpoint which requires immediate attention.

Key Concerns

  • Unprotected AJAX handler
  • Missing nonce checks on AJAX
  • Insufficient output escaping (37% unescaped)
Vulnerabilities
None known

GamiPress – BuddyPress Group Leaderboard Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GamiPress – BuddyPress Group Leaderboard Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
3
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

63% escaped8 total outputs
Attack Surface
1 unprotected

GamiPress – BuddyPress Group Leaderboard Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_gamipress_buddypress_group_leaderboard_regenerate_leaderboardsincludes\ajax-functions.php:24
WordPress Hooks 18
actionadmin_noticesgamipress-buddypress-group-leaderboard.php:120
actionplugins_loadedgamipress-buddypress-group-leaderboard.php:271
filtergamipress_settings_addons_meta_boxesincludes\admin.php:149
actionadd_meta_boxesincludes\admin.php:167
filtergamipress_automatic_updates_pluginsincludes\admin.php:208
actionbp_initincludes\bp-groups.php:25
actionbp_template_contentincludes\bp-groups.php:34
actiongroups_delete_groupincludes\bp-groups.php:92
filtergamipress_leaderboards_leaderboard_pre_query_varsincludes\content-filters.php:56
filtergamipress_leaderboards_leaderboard_usersincludes\content-filters.php:98
filtergamipress_leaderboards_leaderboard_users_per_pageincludes\content-filters.php:99
filtergamipress_leaderboards_leaderboard_columnsincludes\content-filters.php:100
filtergamipress_leaderboards_leaderboard_metricsincludes\content-filters.php:101
filtergamipress_leaderboards_leaderboard_periodincludes\content-filters.php:102
filtergamipress_leaderboards_leaderboard_period_start_dateincludes\content-filters.php:103
filtergamipress_leaderboards_leaderboard_period_end_dateincludes\content-filters.php:104
actionadmin_initincludes\scripts.php:28
actionadmin_enqueue_scriptsincludes\scripts.php:50
Maintenance & Trust

GamiPress – BuddyPress Group Leaderboard Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version
Downloads16K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

GamiPress – BuddyPress Group Leaderboard Developer Profile

Ruben Garcia

30 plugins · 25K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
139 days
View full developer profile
Detection Fingerprints

How We Detect GamiPress – BuddyPress Group Leaderboard

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gamipress-buddypress-group-leaderboard/assets/css/gamipress-bp-group-leaderboard.css/wp-content/plugins/gamipress-buddypress-group-leaderboard/assets/js/gamipress-bp-group-leaderboard.js
Script Paths
/wp-content/plugins/gamipress-buddypress-group-leaderboard/assets/js/gamipress-bp-group-leaderboard.js
Version Parameters
gamipress-buddypress-group-leaderboard/assets/css/gamipress-bp-group-leaderboard.css?ver=gamipress-buddypress-group-leaderboard/assets/js/gamipress-bp-group-leaderboard.js?ver=

HTML / DOM Fingerprints

CSS Classes
gamipress-bp-group-leaderboardgamipress-bp-group-leaderboard-tab
HTML Comments
<!-- GamiPress - BuddyPress Group Leaderboard --><!-- GamiPress - BuddyPress Group Leaderboard Tab -->
Data Attributes
data-gamipress-bp-group-leaderboard-group-iddata-gamipress-bp-group-leaderboard-user-id
JS Globals
gamipress_bp_group_leaderboard_vars
Shortcode Output
[gamipress_bp_group_leaderboard]
FAQ

Frequently Asked Questions about GamiPress – BuddyPress Group Leaderboard