GamiPress – myCRED Importer Security & Risk Analysis

wordpress.org/plugins/gamipress-mycred-importer

Tool to migrate all stored data from myCRED to GamiPress

10 active installs v1.1.1 PHP + WP 4.4+ Updated Dec 1, 2025
creditsgamificationgamipressmycredpoints
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GamiPress – myCRED Importer Safe to Use in 2026?

Generally Safe

Score 100/100

GamiPress – myCRED Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The gamipress-mycred-importer v1.1.1 plugin exhibits a strong security posture based on the provided static analysis. It demonstrates excellent practices by utilizing prepared statements for all SQL queries and properly escaping all output. The absence of file operations and external HTTP requests further mitigates common attack vectors. Furthermore, the plugin has no recorded vulnerability history, suggesting a well-maintained and secure codebase over time. The entire attack surface, comprising 5 AJAX handlers, is protected by capability checks, indicating a deliberate effort to secure entry points. The taint analysis showing zero flows with unsanitized paths is also a positive sign. However, the complete lack of nonce checks across its AJAX handlers is a notable concern. While capability checks are in place, nonces are a critical defense against Cross-Site Request Forgery (CSRF) attacks, which could allow attackers to trick authenticated users into performing unintended actions. This is the primary weakness identified in an otherwise robust security profile.

Key Concerns

  • Missing nonce checks on AJAX handlers
Vulnerabilities
None known

GamiPress – myCRED Importer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GamiPress – myCRED Importer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
24 prepared
Unescaped Output
0
26 escaped
Nonce Checks
0
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared24 total queries

Output Escaping

100% escaped26 total outputs
Attack Surface

GamiPress – myCRED Importer Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_gamipress_mycred_importer_import_pointsincludes\tool.php:323
authwp_ajax_gamipress_mycred_importer_import_achievementsincludes\tool.php:523
authwp_ajax_gamipress_mycred_importer_import_ranksincludes\tool.php:637
authwp_ajax_gamipress_mycred_importer_import_earningsincludes\tool.php:862
authwp_ajax_gamipress_mycred_importer_import_logsincludes\tool.php:1046
WordPress Hooks 5
actionadmin_noticesgamipress-mycred-importer.php:94
actionplugins_loadedgamipress-mycred-importer.php:204
actionadmin_initincludes\scripts.php:26
actionadmin_enqueue_scriptsincludes\scripts.php:46
filtergamipress_tools_import_export_meta_boxesincludes\tool.php:151
Maintenance & Trust

GamiPress – myCRED Importer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

GamiPress – myCRED Importer Developer Profile

Ruben Garcia

30 plugins · 25K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
139 days
View full developer profile
Detection Fingerprints

How We Detect GamiPress – myCRED Importer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gamipress-mycred-importer/assets/js/gamipress-mycred-importer-admin.min.js/wp-content/plugins/gamipress-mycred-importer/assets/js/gamipress-mycred-importer-admin.js
Script Paths
/wp-content/plugins/gamipress-mycred-importer/assets/js/gamipress-mycred-importer-admin.min.js/wp-content/plugins/gamipress-mycred-importer/assets/js/gamipress-mycred-importer-admin.js
Version Parameters
/wp-content/plugins/gamipress-mycred-importer/assets/js/gamipress-mycred-importer-admin.min.js?ver=/wp-content/plugins/gamipress-mycred-importer/assets/js/gamipress-mycred-importer-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about GamiPress – myCRED Importer