BadgeOS Timelimit Add-on Security & Risk Analysis

wordpress.org/plugins/timelimit-add-on-for-badgeos

Allows to limit awarding BadgeOS achievements per a configurable time interval, e.g. a certain achievement will only be awarded once per day.

10 active installs v1.0.3 PHP + WP + Updated Jun 8, 2016
badgebadgesopenbadgestimetimelimit
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BadgeOS Timelimit Add-on Safe to Use in 2026?

Generally Safe

Score 85/100

BadgeOS Timelimit Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The plugin "timelimit-add-on-for-badgeos" v1.0.3 exhibits a remarkably clean static analysis report. The absence of any identified AJAX handlers, REST API routes, shortcodes, cron events, or file operations significantly limits the potential attack surface. Furthermore, the code demonstrates good practices by not utilizing dangerous functions and by exclusively employing prepared statements for all SQL queries. The reported external HTTP requests and file operations are also zero, which further reduces exposure. However, there are areas that warrant attention. The lack of nonce checks and capability checks, coupled with a relatively high percentage of unescaped outputs (25%), suggests potential weaknesses that could be exploited if an attacker can find a way to interact with the plugin's code. The vulnerability history being entirely clear is a strong positive, indicating a history of secure development and maintenance. Despite the low attack surface, the unescaped outputs and the absence of critical security checks like nonces and capabilities mean the plugin is not entirely risk-free. The overall security posture is strong due to the limited attack surface and good SQL practices, but the identified code signal concerns prevent a perfect score.

Key Concerns

  • 25% of outputs are unescaped
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

BadgeOS Timelimit Add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

BadgeOS Timelimit Add-on Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped4 total outputs
Attack Surface

BadgeOS Timelimit Add-on Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_noticesbadgeos-timelimit.php:45
actionplugins_loadedbadgeos-timelimit.php:46
actionwp_print_scriptsbadgeos-timelimit.php:47
filterbadgeos_achievement_data_meta_box_fieldsincludes\actions-filters.php:3
filteruser_deserves_achievementincludes\actions-filters.php:16
Maintenance & Trust

BadgeOS Timelimit Add-on Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJun 8, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BadgeOS Timelimit Add-on Developer Profile

konnektiv

10 plugins · 70 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BadgeOS Timelimit Add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/timelimit-add-on-for-badgeos/includes/actions-filters.php

HTML / DOM Fingerprints

Data Attributes
name="_badgeos_time_limit"id="_badgeos_time_limit"
FAQ

Frequently Asked Questions about BadgeOS Timelimit Add-on