
Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Security & Risk Analysis
wordpress.org/plugins/kredeum-nftsSell your NFTs directly on your WordPress site in an easy and fast way.
Is Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Safe to Use in 2026?
Generally Safe
Score 91/100Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The kredeum-nfts plugin v1.6.10 presents a mixed security posture. While it demonstrates good practices in output escaping, SQL query preparation, and the absence of critical taint analysis findings, significant concerns arise from its attack surface and lack of authorization checks. The presence of 3 AJAX handlers without authentication checks represents a notable risk, as these could potentially be exploited by unauthenticated users. Although there are no currently unpatched CVEs, the plugin has a history of a medium severity Cross-site Scripting vulnerability, which indicates past issues with input sanitization or output encoding, even though current static analysis shows 100% output escaping. The total lack of capability checks further amplifies the risk associated with unprotected entry points. The bundling of the dompdf library, while not explicitly flagged as an issue here, warrants attention for potential vulnerabilities in older versions. Overall, the plugin has strengths in preventing common code-level vulnerabilities but suffers from a critical weakness in access control for its AJAX endpoints, requiring immediate attention to mitigate potential exploitation. The past XSS vulnerability, even if patched, serves as a reminder of the need for robust input validation and authorization mechanisms.
Key Concerns
- AJAX handlers without authentication checks
- No capability checks
- Bundled dompdf library
- History of medium severity XSS vulnerability
Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site <= 1.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Release Timeline
Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Attack Surface
AJAX Handlers 3
Shortcodes 2
WordPress Hooks 23
Maintenance & Trust
Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Maintenance & Trust
Maintenance Signals
Community Trust
Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Alternatives
KoalaMint Plugin
koalamint
The No-Code Solution to Launch a Generative NFT Collection On your Website.
MintNFT Plugin
mintnft
The “MintNFT Plugin” is a useful tool for those who want to mint their own NFTs without having to build an entire minting platform from scratch.
WordThree – Easily Login & Register Using Your MetaMask Wallet
wordthree
Allow users to login and register using their MetaMask wallet.
Web3 – Crypto wallet Login & NFT token gating
web3-authentication
Users can sign up for your WordPress using their crypto wallets. Gate content based on NFTs owned. Web3 authentication plugin supports crypto wallets …
Token / NFT / Blockchain Page Gating
litprotocol-wp-lit-gated
Gate your content based on blockchain conditions like NFT ownership.
Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Developer Profile
1 plugin · 40 total installs
How We Detect Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kredeum-nfts/assets/js/kredeum-nfts.js/wp-content/plugins/kredeum-nfts/assets/js/kredeum-nfts.css/wp-content/plugins/kredeum-nfts/assets/css/front.css/wp-content/plugins/kredeum-nfts/admin/settings/storage-choice.js/wp-content/plugins/kredeum-nfts/admin/ajax/ajax.js/wp-content/plugins/kredeum-nfts/assets/js/kredeum-nfts.js/wp-content/plugins/kredeum-nfts/admin/settings/storage-choice.js/wp-content/plugins/kredeum-nfts/admin/ajax/ajax.jskredeum-nfts/assets/js/kredeum-nfts.js?ver=kredeum-nfts/assets/js/kredeum-nfts.css?ver=kredeum-nfts/assets/css/front.css?ver=kredeum-nfts/admin/settings/storage-choice.js?ver=kredeum-nfts/admin/ajax/ajax.js?ver=HTML / DOM Fingerprints
chainidaddresstokenid<div id="kredeum-sell"<div id="kredeum-opensky"<div id="kredeum-automarket"