GamiPress – Leaderboards Include/Exclude Users Security & Risk Analysis

wordpress.org/plugins/gamipress-leaderboards-include-exclude-users

Include or exclude specific users or roles on any leaderboard.

500 active installs v1.0.9 PHP + WP 4.4+ Updated Dec 1, 2025
achievementgamificationgamifygamipresspoint
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GamiPress – Leaderboards Include/Exclude Users Safe to Use in 2026?

Generally Safe

Score 100/100

GamiPress – Leaderboards Include/Exclude Users has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The plugin "gamipress-leaderboards-include-exclude-users" v1.0.9 exhibits a strong security posture based on the provided static analysis. The code demonstrates excellent adherence to secure coding practices, with no detected dangerous functions, all SQL queries utilizing prepared statements, and all output properly escaped. Furthermore, the absence of file operations and external HTTP requests mitigates common attack vectors. The zero-count for critical and high-severity taint flows further reinforces this positive assessment.

However, a significant concern arises from the complete lack of any security checks, including nonces and capability checks, across all identified entry points. While the analysis reports zero entry points, this finding is contradictory and raises a red flag. If there were indeed no entry points, it would imply the plugin is inert and poses no security risk. If entry points exist but have no checks, this is a critical oversight. The vulnerability history shows no prior issues, which is positive, but it does not compensate for the potential for future vulnerabilities due to the absence of fundamental security mechanisms.

In conclusion, while the plugin's code itself appears clean and well-written with respect to SQL and output handling, the lack of any authentication or authorization checks on its (potential) entry points is a serious weakness. This absence of basic security hygiene leaves it vulnerable to attacks if any functionality is indeed exposed. The plugin's strengths lie in its clean code, but its weakness is a fundamental lack of security enforcement mechanisms.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
  • Contradictory entry point analysis (0 total, 0 unprotected)
Vulnerabilities
None known

GamiPress – Leaderboards Include/Exclude Users Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GamiPress – Leaderboards Include/Exclude Users Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

GamiPress – Leaderboards Include/Exclude Users Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_noticesgamipress-leaderboards-include-exclude-users.php:105
actionplugins_loadedgamipress-leaderboards-include-exclude-users.php:236
filtergamipress_automatic_updates_pluginsincludes\admin.php:26
actiongamipress_init_gp_leaderboard_meta_boxesincludes\admin.php:88
filtergamipress_leaderboards_leaderboard_pre_query_varsincludes\content-filters.php:116
actionadmin_initincludes\scripts.php:26
actionadmin_enqueue_scriptsincludes\scripts.php:45
Maintenance & Trust

GamiPress – Leaderboards Include/Exclude Users Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 1, 2025
PHP min version
Downloads15K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

GamiPress – Leaderboards Include/Exclude Users Developer Profile

Ruben Garcia

30 plugins · 25K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
139 days
View full developer profile
Detection Fingerprints

How We Detect GamiPress – Leaderboards Include/Exclude Users

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gamipress-leaderboards-include-exclude-users/assets/css/admin.css/wp-content/plugins/gamipress-leaderboards-include-exclude-users/assets/js/admin.js
Script Paths
/wp-content/plugins/gamipress-leaderboards-include-exclude-users/assets/js/admin.js
Version Parameters
/wp-content/plugins/gamipress-leaderboards-include-exclude-users/assets/css/admin.css?ver=/wp-content/plugins/gamipress-leaderboards-include-exclude-users/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
gamipress-leaderboards-include-exclude-users-fieldgamipress-leaderboards-include-exclude-users-select2gamipress-leaderboards-include-exclude-users-exclude-users-containergamipress-leaderboards-include-exclude-users-include-users-container
Data Attributes
data-gamipress-leaderboards-include-exclude-users
JS Globals
GamiPressLeaderboardsIncludeExcludeUsersgamipress_leaderboards_include_exclude_users_admin_params
FAQ

Frequently Asked Questions about GamiPress – Leaderboards Include/Exclude Users