Meritocracy – Near-Powered Gamification Plugin for WordPress Security & Risk Analysis

wordpress.org/plugins/meritocracy

Meritocracy is a Near protocol-powered gamification plugin for WordPress.

10 active installs v1.3.1 PHP 7.0+ WP 4.8+ Updated Apr 17, 2025
blockchaincryptocurrencymycrednear-protocolweb3
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Meritocracy – Near-Powered Gamification Plugin for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

Meritocracy – Near-Powered Gamification Plugin for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "meritocracy" plugin v1.3.1 exhibits a generally positive security posture with several strong points. Notably, there are no recorded vulnerabilities in its history, which is a significant indicator of good development practices and diligent maintenance. The code analysis reveals no dangerous functions, all SQL queries use prepared statements, and the vast majority of output is properly escaped, minimizing risks of injection and XSS. The absence of file operations and external HTTP requests further reduces the attack surface.

However, there are notable areas of concern. The plugin exposes a substantial attack surface with 8 AJAX handlers, a significant portion of which (6) lack authentication checks. This is a critical oversight that could allow unauthenticated users to trigger plugin functionality with potentially harmful consequences. While the taint analysis shows no critical or high-severity issues, the lack of capability checks on any entry points is a missed opportunity to further strengthen security, especially given the unprotected AJAX handlers.

In conclusion, while the "meritocracy" plugin demonstrates a commitment to secure coding practices in many areas, the unprotected AJAX handlers represent a significant security weakness that needs immediate attention. The lack of historical vulnerabilities is encouraging, but the current code presents a clear risk that could be mitigated by implementing proper authentication and capability checks on all entry points.

Key Concerns

  • Unprotected AJAX handlers
  • No capability checks on entry points
Vulnerabilities
None known

Meritocracy – Near-Powered Gamification Plugin for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Meritocracy – Near-Powered Gamification Plugin for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
57 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped60 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
meritocracy_buy_form_callback (gateways\mycred-buycred-meritocracy.php:219)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

Meritocracy – Near-Powered Gamification Plugin for WordPress Attack Surface

Entry Points9
Unprotected6

AJAX Handlers 8

noprivwp_ajax_meritocracy_purchase_pointsgateways\mycred-buycred-meritocracy.php:196
authwp_ajax_meritocracy_purchase_pointsgateways\mycred-buycred-meritocracy.php:199
noprivwp_ajax_meritocracy_withdrawl_transfer_status_updategateways\mycred-cashcred-meritocracy.php:39
authwp_ajax_meritocracy_withdrawl_transfer_status_updategateways\mycred-cashcred-meritocracy.php:42
noprivwp_ajax_meritocracy_withdrawl_transfer_errorgateways\mycred-cashcred-meritocracy.php:46
authwp_ajax_meritocracy_withdrawl_transfer_errorgateways\mycred-cashcred-meritocracy.php:49
noprivwp_ajax_save_mycred_pref_cashcredsgateways\mycred-cashcred-meritocracy.php:55
authwp_ajax_save_mycred_pref_cashcredsgateways\mycred-cashcred-meritocracy.php:58

Shortcodes 1

[meritocracy_buy_form] gateways\mycred-buycred-meritocracy.php:184
WordPress Hooks 10
actionmycred_front_enqueuegateways\mycred-buycred-meritocracy.php:50
filtermycred_buycred_refsgateways\mycred-buycred-meritocracy.php:51
filtermycred_buycred_log_refsgateways\mycred-buycred-meritocracy.php:52
actionadmin_enqueue_scriptsgateways\mycred-cashcred-meritocracy.php:35
filtermycred_buycred_log_refsgateways\mycred-cashcred-meritocracy.php:36
actioninitmeritocracy.php:149
filtermycred_setup_gatewaysmeritocracy.php:152
filtermycred_cashcred_setup_gatewaysmeritocracy.php:153
actionmycred_buycred_load_gatewaysmeritocracy.php:155
actionmycred_cashcred_load_gatewaysmeritocracy.php:156
Maintenance & Trust

Meritocracy – Near-Powered Gamification Plugin for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 17, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Meritocracy – Near-Powered Gamification Plugin for WordPress Developer Profile

WPExperts.io

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Meritocracy – Near-Powered Gamification Plugin for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/meritocracy/gateways/mycred-buycred-meritocracy.php/wp-content/plugins/meritocracy/gateways/mycred-cashcred-meritocracy.php
Version Parameters
meritocracy/style.css?ver=meritocracy/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Meritocracy – Near-Powered Gamification Plugin for WordPress