
GamiPress – LearnDash Points Importer Security & Risk Analysis
wordpress.org/plugins/gamipress-learndash-points-importerTool to migrate LearnDash user points to GamiPress points.
Is GamiPress – LearnDash Points Importer Safe to Use in 2026?
Generally Safe
Score 100/100GamiPress – LearnDash Points Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The gamipress-learndash-points-importer plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. The complete absence of unprotected entry points, dangerous functions, file operations, external HTTP requests, and a notable 100% of outputs being properly escaped are all positive indicators. Furthermore, the plugin demonstrates good practice with its capability checks and has no recorded vulnerabilities, including no known CVEs. This suggests a well-developed and secure plugin that adheres to fundamental WordPress security principles.
However, a critical area of concern lies in the handling of SQL queries. The analysis reveals two SQL queries present in the codebase, neither of which utilize prepared statements. This is a significant security risk, as it opens the door to SQL injection vulnerabilities, especially if user-supplied data is directly incorporated into these queries without proper sanitization and parameterization. The lack of taint analysis data is also a slight unknown, though the absence of critical and high severity flows is promising. The overall lack of complexity in the plugin's entry points (only one AJAX handler) simplifies the attack surface, but the SQL query issue remains the primary vulnerability.
In conclusion, while the plugin is strong in many security aspects, particularly output escaping and the absence of historical vulnerabilities, the un-prepared SQL queries represent a tangible and potentially exploitable risk. Addressing this specific issue through the implementation of prepared statements should be the immediate priority for improving the plugin's security.
Key Concerns
- SQL queries not using prepared statements
GamiPress – LearnDash Points Importer Security Vulnerabilities
GamiPress – LearnDash Points Importer Code Analysis
SQL Query Safety
Output Escaping
GamiPress – LearnDash Points Importer Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
GamiPress – LearnDash Points Importer Maintenance & Trust
Maintenance Signals
Community Trust
GamiPress – LearnDash Points Importer Alternatives
FG Joomla to WordPress
fg-joomla-to-wordpress
A plugin to migrate categories, posts, tags, images and other medias from Joomla to WordPress
S2W – Import Shopify to WooCommerce
import-shopify-to-woocommerce
Easily migrate all Shopify products and their collections(categories) to WooCommerce after several clicks
FG Drupal to WordPress
fg-drupal-to-wp
A plugin to migrate articles, stories, pages, categories, tags, images from Drupal to WordPress
Export/Import Media
calliope-media-import-export
The ultimate tool to migrate your media library. Export to CSV with Advanced Filters and Import securely with Drag & Drop (images, videos, audio a …
WSW – Shopify WooCommerce / WordPress Integration and Migration
wsw-import-export-ecommerce-integration
It links and imports products,categories,tags from Shopify and converts them into WooCommerce items automatically with the same metadata.
GamiPress – LearnDash Points Importer Developer Profile
30 plugins · 25K total installs
How We Detect GamiPress – LearnDash Points Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gamipress-learndash-points-importer/assets/js/gamipress-learndash-points-importer-admin.js/wp-content/plugins/gamipress-learndash-points-importer/assets/js/gamipress-learndash-points-importer-admin.min.jsassets/js/gamipress-learndash-points-importer-admin.jsassets/js/gamipress-learndash-points-importer-admin.min.jsgamipress-learndash-points-importer/assets/js/gamipress-learndash-points-importer-admin.js?ver=gamipress-learndash-points-importer/assets/js/gamipress-learndash-points-importer-admin.min.js?ver=