
GamiPress – Link Security & Risk Analysis
wordpress.org/plugins/gamipress-linkAdd activity events based on link clicks generated by [gamipress_link]
Is GamiPress – Link Safe to Use in 2026?
Generally Safe
Score 99/100GamiPress – Link has a strong security track record. Known vulnerabilities have been patched promptly.
The gamipress-link plugin v1.1.5 demonstrates a generally good security posture based on the static analysis. The absence of unauthenticated AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code strictly uses prepared statements for all SQL queries and includes nonce checks, which are strong indicators of secure coding practices. The lack of file operations and external HTTP requests further reduces common attack vectors.
However, there are some areas for improvement. While the majority of output is properly escaped, a notable percentage (30%) is not. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if malicious input is not handled carefully. The vulnerability history shows a recent medium-severity XSS vulnerability, which aligns with the concern about unescaped output. Although this vulnerability is currently patched, it highlights a recurring pattern that requires ongoing attention.
In conclusion, gamipress-link v1.1.5 is relatively secure due to its limited attack surface and robust handling of database operations and nonces. The primary concern stems from the unescaped output, which has historically led to XSS vulnerabilities. Continued vigilance in ensuring all output is properly escaped will be crucial for maintaining a strong security profile.
Key Concerns
- Unescaped output percentage is high
- Recent medium vulnerability (XSS)
GamiPress – Link Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
GamiPress – Link <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
GamiPress – Link Code Analysis
Output Escaping
GamiPress – Link Attack Surface
AJAX Handlers 2
WordPress Hooks 20
Maintenance & Trust
GamiPress – Link Maintenance & Trust
Maintenance Signals
Community Trust
GamiPress – Link Alternatives
GamiPress – Button
gamipress-button
Add activity events based on button clicks generated by [gamipress_button]
GamiPress – Leaderboards Include/Exclude Users
gamipress-leaderboards-include-exclude-users
Include or exclude specific users or roles on any leaderboard.
GamiPress – Block Users
gamipress-block-users
Block users and roles from getting awarded through the GamiPress awards engine
GamiPress – BuddyPress Group Leaderboard
gamipress-buddypress-group-leaderboard
Add a completely configurable tab on BuddyPress groups with a GamiPress leaderboard of group members
GamiPress – Emails By Type
gamipress-emails-by-type
Set different emails settings by type
GamiPress – Link Developer Profile
30 plugins · 25K total installs
How We Detect GamiPress – Link
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gamipress-link/assets/js/gamipress-link-admin.js/wp-content/plugins/gamipress-link/assets/js/gamipress-link.js/wp-content/plugins/gamipress-link/assets/js/gamipress-link.js/wp-content/plugins/gamipress-link/assets/js/gamipress-link-admin.js/wp-content/plugins/gamipress-link/assets/js/gamipress-link.js?ver=/wp-content/plugins/gamipress-link/assets/js/gamipress-link-admin.js?ver=HTML / DOM Fingerprints
gamipress_link