
IDPay For MyCred Security & Risk Analysis
wordpress.org/plugins/idpay-mycredAfter installing and enabling this plugin, your customers can pay through IDPay gateway.
Is IDPay For MyCred Safe to Use in 2026?
Generally Safe
Score 85/100IDPay For MyCred has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The idpay-mycred plugin, version 1.2.2, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for all SQL queries and appears to have no known past vulnerabilities. The absence of a significant attack surface, including no detected AJAX handlers, REST API routes, shortcodes, or cron events, is also a strength. However, significant concerns arise from the static analysis. A notable 49% of output escaping is not properly handled, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is ever rendered without sanitization. Furthermore, all seven analyzed taint flows originate from unsanitized paths, although they are not flagged as critical or high severity, this suggests a general lack of input validation and sanitization within the plugin's logic. The presence of external HTTP requests without clear authentication or authorization checks could also pose a risk if the plugin communicates with sensitive endpoints. In conclusion, while the plugin avoids common pitfalls like raw SQL and known CVEs, the substantial number of unsanitized taint flows and the significant percentage of unescaped output are notable weaknesses that require attention to improve its overall security.
Key Concerns
- Unescaped output detected
- Taint flows with unsanitized paths
- External HTTP request without auth checks
IDPay For MyCred Security Vulnerabilities
IDPay For MyCred Code Analysis
Output Escaping
Data Flow Analysis
IDPay For MyCred Attack Surface
WordPress Hooks 8
Maintenance & Trust
IDPay For MyCred Maintenance & Trust
Maintenance Signals
Community Trust
IDPay For MyCred Alternatives
GamiPress – myCRED Importer
gamipress-mycred-importer
Tool to migrate all stored data from myCRED to GamiPress
PayU GPO Payment for WooCommerce
woo-payu-payment-gateway
PayU fast online payments for WooCommerce. Banks, BLIK, credit or debit cards, Installments, Apple Pay, Google Pay.
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions
wp-full-stripe-free
🚀 Create Stripe payment forms for WordPress. Accept credit cards, Apple Pay, donations, subscriptions & more. Easy setup, no coding needed!
Stripe Payment Forms by WP Simple Pay – Accept Credit Card Payments + Subscriptions with Stripe
stripe
🤩 Accept Stripe payments and recurring subscriptions on your WordPress using WP Simple Pay, the best Stripe payments plugin! 🚀
Asaas Gateway for WooCommerce
woo-asaas
Take transparent credit card and bank ticket payment checkouts on your store using Asaas.
IDPay For MyCred Developer Profile
7 plugins · 1K total installs
How We Detect IDPay For MyCred
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/idpay-mycred/assets/logo.svgHTML / DOM Fingerprints
mycred_idpay_messagemycred_idpay_message errormycred_idpay_message successname="mycred-gateway-idpay-currency"