Boldwallet myCRED/buyCred Payment Gateway Security & Risk Analysis

wordpress.org/plugins/boldwallet-mycred

Boldwallet payment method for myCRED.

10 active installs v1.2 PHP + WP 4.7+ Updated Jun 2, 2020
boldwalletmastercardpayment-gatewayvervevisa
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Boldwallet myCRED/buyCred Payment Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

Boldwallet myCRED/buyCred Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The boldwallet-mycred plugin v1.2 exhibits a generally positive security posture, adhering to several best practices. The complete absence of known CVEs and an extensive history of no reported vulnerabilities strongly suggests a well-maintained and secure codebase. Static analysis reveals a minimal attack surface with no discovered entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication. Furthermore, the plugin demonstrates robust SQL handling, with all queries utilizing prepared statements, mitigating SQL injection risks. However, the code analysis does flag some areas for improvement. A significant concern is the low percentage of properly escaped output (44%), which could leave the plugin vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not handled with sufficient sanitization before being displayed. The presence of four taint flows with unsanitized paths, even without critical or high severity, indicates potential for data leakage or unintended behavior. The plugin also makes external HTTP requests, which, while not inherently insecure, warrants careful scrutiny for potential supply chain risks or man-in-the-middle vulnerabilities if the target endpoints are not properly secured. The absence of nonce checks and capability checks across all analyzed code signals is a notable omission, especially given the minimal attack surface, as these are fundamental WordPress security mechanisms for preventing CSRF and unauthorized actions.

Key Concerns

  • Low percentage of properly escaped output
  • Taint flows with unsanitized paths
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Boldwallet myCRED/buyCred Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Boldwallet myCRED/buyCred Payment Gateway Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Boldwallet myCRED/buyCred Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

44% escaped39 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
mycred_boldwallet_plugin (boldwallet-mycred.php:50)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Boldwallet myCRED/buyCred Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionplugins_loadedboldwallet-mycred.php:28
filtermycred_setup_gatewaysboldwallet-mycred.php:31
Maintenance & Trust

Boldwallet myCRED/buyCred Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 2, 2020
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Boldwallet myCRED/buyCred Payment Gateway Developer Profile

Mr.software

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Boldwallet myCRED/buyCred Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/boldwallet-mycred/assets/logo.png

HTML / DOM Fingerprints

Data Attributes
id="boldwallet_mycred"name="boldwallet_mycred"id="boldwallet-mycred"name="boldwallet-mycred"id="boldwallet_display_name"name="boldwallet_display_name"+6 more
FAQ

Frequently Asked Questions about Boldwallet myCRED/buyCred Payment Gateway