Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Security & Risk Analysis

wordpress.org/plugins/kredeum-nfts

Sell your NFTs directly on your WordPress site in an easy and fast way.

40 active installs v1.6.10 PHP 7.3+ WP 5.0+ Updated Dec 31, 2024
blockchainethereumipfsnftpolygon
91
A · Safe
CVEs total1
Unpatched0
Last CVEDec 13, 2024
Safety Verdict

Is Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Safe to Use in 2026?

Generally Safe

Score 91/100

Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 13, 2024Updated 1yr ago
Risk Assessment

The kredeum-nfts plugin v1.6.10 presents a mixed security posture. While it demonstrates good practices in output escaping, SQL query preparation, and the absence of critical taint analysis findings, significant concerns arise from its attack surface and lack of authorization checks. The presence of 3 AJAX handlers without authentication checks represents a notable risk, as these could potentially be exploited by unauthenticated users. Although there are no currently unpatched CVEs, the plugin has a history of a medium severity Cross-site Scripting vulnerability, which indicates past issues with input sanitization or output encoding, even though current static analysis shows 100% output escaping. The total lack of capability checks further amplifies the risk associated with unprotected entry points. The bundling of the dompdf library, while not explicitly flagged as an issue here, warrants attention for potential vulnerabilities in older versions. Overall, the plugin has strengths in preventing common code-level vulnerabilities but suffers from a critical weakness in access control for its AJAX endpoints, requiring immediate attention to mitigate potential exploitation. The past XSS vulnerability, even if patched, serves as a reminder of the need for robust input validation and authorization mechanisms.

Key Concerns

  • AJAX handlers without authentication checks
  • No capability checks
  • Bundled dompdf library
  • History of medium severity XSS vulnerability
Vulnerabilities
1 published

Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11876medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site <= 1.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 13, 2024 Patched in 1.6.10 (24d)
Version History

Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Release Timeline

v1.6.10Current
v1.6.91 CVE
v1.6.61 CVE
v1.6.51 CVE
v1.6.41 CVE
v1.6.31 CVE
v1.6.21 CVE
v1.2.01 CVE
v1.1.41 CVE
v1.1.31 CVE
v1.1.01 CVE
v1.0.41 CVE
v1.0.31 CVE
v0.18.31 CVE
v0.17.21 CVE
v0.16.91 CVE
v0.13.11 CVE
v0.12.11 CVE
v0.11.11 CVE
v0.10.41 CVE
Code Analysis
Analyzed Mar 16, 2026

Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
6 prepared
Unescaped Output
0
74 escaped
Nonce Checks
3
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
1

Bundled Libraries

dompdf

SQL Query Safety

86% prepared7 total queries

Output Escaping

100% escaped74 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<ajax> (admin\ajax\ajax.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Attack Surface

Entry Points5
Unprotected3

AJAX Handlers 3

authwp_ajax_tokenadmin\ajax\ajax.php:26
authwp_ajax_importadmin\ajax\ajax.php:46
authwp_ajax_collectionadmin\ajax\ajax.php:64

Shortcodes 2

[kredeum_opensky] common\shortcode\shortcode.php:50
[kredeum_automarket] common\shortcode\shortcode.php:66
WordPress Hooks 23
actionadmin_enqueue_scriptsadmin\ajax\ajax.php:15
actionadd_meta_boxes_attachmentadmin\media\post.php:14
filterattachment_fields_to_editadmin\media\post.php:34
actionedit_attachmentadmin\media\post.php:57
actionadd_attachmentadmin\media\upload.php:15
filterbulk_actions-uploadadmin\media-list\actions.php:13
filterhandle_bulk_actions-uploadadmin\media-list\actions.php:24
actionadmin_noticesadmin\media-list\actions.php:57
filtermanage_media_columnsadmin\media-list\column.php:13
actionmanage_media_custom_columnadmin\media-list\column.php:25
actionadmin_menuadmin\nfts\index.php:10
filterbulk_actions-edit-postadmin\post-list\actions.php:16
filterhandle_bulk_actions-edit-postadmin\post-list\actions.php:27
actionadmin_noticesadmin\post-list\actions.php:101
filtermanage_posts_columnsadmin\post-list\column.php:13
actionmanage_posts_custom_columnadmin\post-list\column.php:25
actionadmin_menuadmin\settings\class-settings.php:31
actionadmin_initadmin\settings\class-settings.php:34
actionadmin_initadmin\settings\class-settings.php:35
actionadmin_enqueue_scriptskredeum-nfts.php:58
actionplugins_loadedkredeum-nfts.php:97
actionwp_enqueue_scriptspublic\front\automarket.php:14
filterthe_contentpublic\post\bottom.php:10
Maintenance & Trust

Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 31, 2024
PHP min version7.3
Downloads17K

Community Trust

Rating100/100
Number of ratings4
Active installs40
Developer Profile

Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Developer Profile

yoannr35

1 plugin · 40 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
24 days
View full developer profile
Detection Fingerprints

How We Detect Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kredeum-nfts/assets/js/kredeum-nfts.js/wp-content/plugins/kredeum-nfts/assets/js/kredeum-nfts.css/wp-content/plugins/kredeum-nfts/assets/css/front.css/wp-content/plugins/kredeum-nfts/admin/settings/storage-choice.js/wp-content/plugins/kredeum-nfts/admin/ajax/ajax.js
Script Paths
/wp-content/plugins/kredeum-nfts/assets/js/kredeum-nfts.js/wp-content/plugins/kredeum-nfts/admin/settings/storage-choice.js/wp-content/plugins/kredeum-nfts/admin/ajax/ajax.js
Version Parameters
kredeum-nfts/assets/js/kredeum-nfts.js?ver=kredeum-nfts/assets/js/kredeum-nfts.css?ver=kredeum-nfts/assets/css/front.css?ver=kredeum-nfts/admin/settings/storage-choice.js?ver=kredeum-nfts/admin/ajax/ajax.js?ver=

HTML / DOM Fingerprints

Data Attributes
chainidaddresstokenid
Shortcode Output
<div id="kredeum-sell"<div id="kredeum-opensky"<div id="kredeum-automarket"
FAQ

Frequently Asked Questions about Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site