
GamiPress – Reset User Security & Risk Analysis
wordpress.org/plugins/gamipress-reset-userReset all user earnings and logs from a single button.
Is GamiPress – Reset User Safe to Use in 2026?
Generally Safe
Score 99/100GamiPress – Reset User has a strong security track record. Known vulnerabilities have been patched promptly.
The gamipress-reset-user plugin v1.0.1 presents a mixed security picture. On the positive side, the static analysis shows a very limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. The taint analysis also indicates no identified critical or high-severity unsanitized flows, which is a strong positive. However, a significant concern is the handling of SQL queries, as 100% of the 5 detected queries do not use prepared statements. This makes the plugin vulnerable to SQL injection if any of the inputs feeding these queries are not strictly sanitized, which is not explicitly detailed in the static analysis but is a high risk given the context.
The plugin's vulnerability history, while having only one medium-severity CVE, is noteworthy. The fact that it was a Cross-Site Request Forgery (CSRF) vulnerability and the last one was very recent (2024-09-04) suggests a pattern of potentially insecure coding practices. While the current version has no unpatched CVEs, this history warrants caution. The presence of a nonce check and capability checks are good practices, but the complete lack of SQL prepared statements is a major weakness that overshadows the otherwise clean attack surface and taint analysis.
Key Concerns
- 100% of SQL queries use raw SQL, not prepared statements
- Medium severity CSRF vulnerability in vulnerability history
GamiPress – Reset User Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
GamiPress - Reset User <= 1.0.0 - Cross-Site Request Forgery to GamiPress User Data Removal
GamiPress – Reset User Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
GamiPress – Reset User Attack Surface
WordPress Hooks 5
Maintenance & Trust
GamiPress – Reset User Maintenance & Trust
Maintenance Signals
Community Trust
GamiPress – Reset User Alternatives
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
gamipress
Boost your gamification marketing & reward your users with points, achievements, badges & ranks to increase your site activity & loyalty!
GamiPress – BadgeOS Importer
gamipress-badgeos-importer
Tool to migrate all stored data from BadgeOS to GamiPress
Connect GamiPress to Discord
connect-gamipress-and-discord
Create a community of your Members by connecting your GamiPress Website to your Discord server.
GamiPress – WPAchievements Importer
gamipress-wpachievements-importer
Tool to migrate all stored data from WPAchievements to GamiPress
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
mycred
A WordPress gamification plugin is also a points management system. Award ranks, loyalty points and rewards or WooCommerce rewards to your users.
GamiPress – Reset User Developer Profile
30 plugins · 25K total installs
How We Detect GamiPress – Reset User
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gamipress-reset-user/includes/admin.phpgamipress-reset-user/includes/admin.php?ver=gamipress-reset-user.php?ver=HTML / DOM Fingerprints
gamipress-reset-user-informationgamipress_reset_user