GamiPress – H5P Points Per Score Security & Risk Analysis

wordpress.org/plugins/gamipress-h5p-points-per-score

Award points based on the user score in H5P.

300 active installs v1.0.3 PHP + WP 4.4+ Updated Dec 15, 2025
badgescreditsh5ppointsscore
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GamiPress – H5P Points Per Score Safe to Use in 2026?

Generally Safe

Score 100/100

GamiPress – H5P Points Per Score has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

Based on the static analysis and vulnerability history provided, the gamipress-h5p-points-per-score plugin version 1.0.3 exhibits a strong security posture. The absence of identified dangerous functions, the exclusive use of prepared statements for SQL queries, and proper output escaping all indicate good development practices. Furthermore, the plugin's attack surface appears to be well-secured, with no exposed entry points like unprotected AJAX handlers, REST API routes, or shortcodes. The zero recorded CVEs and the lack of any identified taint flows further contribute to this positive assessment. However, the complete absence of nonce checks and capability checks across all identified entry points (even though there are zero identified) represents a potential gap. While the current version may not have exploitable vulnerabilities due to these omissions, future development or changes could introduce risks if these fundamental security controls are not implemented.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

GamiPress – H5P Points Per Score Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

GamiPress – H5P Points Per Score Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

GamiPress – H5P Points Per Score Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped2 total outputs
Attack Surface

GamiPress – H5P Points Per Score Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_noticesgamipress-h5p-points-per-score.php:102
actionplugins_loadedgamipress-h5p-points-per-score.php:224
actioncmb2_admin_initincludes\admin.php:56
filtergamipress_automatic_updates_pluginsincludes\admin.php:73
actionh5p_alter_user_resultincludes\filters.php:111
actionadmin_initincludes\scripts.php:26
actionadmin_enqueue_scriptsincludes\scripts.php:45
Maintenance & Trust

GamiPress – H5P Points Per Score Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 15, 2025
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

GamiPress – H5P Points Per Score Developer Profile

Ruben Garcia

32 plugins · 25K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
128 days
View full developer profile
Detection Fingerprints

How We Detect GamiPress – H5P Points Per Score

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gamipress-h5p-points-per-score/assets/js/gamipress-h5p-points-per-score-admin.js/wp-content/plugins/gamipress-h5p-points-per-score/assets/js/gamipress-h5p-points-per-score-admin.min.js
Script Paths
assets/js/gamipress-h5p-points-per-score-admin.jsassets/js/gamipress-h5p-points-per-score-admin.min.js
Version Parameters
gamipress-h5p-points-per-score/assets/js/gamipress-h5p-points-per-score-admin.js?ver=gamipress-h5p-points-per-score/assets/js/gamipress-h5p-points-per-score-admin.min.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about GamiPress – H5P Points Per Score