
BadgeOS Timelimit Add-on Security & Risk Analysis
wordpress.org/plugins/timelimit-add-on-for-badgeosAllows to limit awarding BadgeOS achievements per a configurable time interval, e.g. a certain achievement will only be awarded once per day.
Is BadgeOS Timelimit Add-on Safe to Use in 2026?
Generally Safe
Score 85/100BadgeOS Timelimit Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "timelimit-add-on-for-badgeos" v1.0.3 exhibits a remarkably clean static analysis report. The absence of any identified AJAX handlers, REST API routes, shortcodes, cron events, or file operations significantly limits the potential attack surface. Furthermore, the code demonstrates good practices by not utilizing dangerous functions and by exclusively employing prepared statements for all SQL queries. The reported external HTTP requests and file operations are also zero, which further reduces exposure. However, there are areas that warrant attention. The lack of nonce checks and capability checks, coupled with a relatively high percentage of unescaped outputs (25%), suggests potential weaknesses that could be exploited if an attacker can find a way to interact with the plugin's code. The vulnerability history being entirely clear is a strong positive, indicating a history of secure development and maintenance. Despite the low attack surface, the unescaped outputs and the absence of critical security checks like nonces and capabilities mean the plugin is not entirely risk-free. The overall security posture is strong due to the limited attack surface and good SQL practices, but the identified code signal concerns prevent a perfect score.
Key Concerns
- 25% of outputs are unescaped
- No nonce checks found
- No capability checks found
BadgeOS Timelimit Add-on Security Vulnerabilities
BadgeOS Timelimit Add-on Code Analysis
Output Escaping
BadgeOS Timelimit Add-on Attack Surface
WordPress Hooks 5
Maintenance & Trust
BadgeOS Timelimit Add-on Maintenance & Trust
Maintenance Signals
Community Trust
BadgeOS Timelimit Add-on Alternatives
BadgeOS LearnDash Add-on
badgeos-learndash-add-on
BadgeOS achievements and badges earned from a wide array of LearnDash learning management system activity.
BadgeOS BadgeStack Add-on
badgeos-badgestack-add-on
This add-on to BadgeOS automatically creates achievement types, pages and sample content to jumpstart your own badging system.
BadgeOS Community Add-on
badgeos-community-add-on
Adds BadgeOS features to BuddyPress and bbPress. Earn badges/points/ranks based on community activity, and display them on user profiles and activity …
myCred Credly
mycred-credly
📢🚨 Important Notice: myCred Credly is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be provided.
BadgeOS Invite Codes Add-on
badgeos-invite-codes-add-on
Enhances sites running BuddyPress and BadgeOS by joining users to one or more specified groups when they use a special Invite Code to join your site.
BadgeOS Timelimit Add-on Developer Profile
10 plugins · 70 total installs
How We Detect BadgeOS Timelimit Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/timelimit-add-on-for-badgeos/includes/actions-filters.phpHTML / DOM Fingerprints
name="_badgeos_time_limit"id="_badgeos_time_limit"