
Meritocracy – Near-Powered Gamification Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/meritocracyMeritocracy is a Near protocol-powered gamification plugin for WordPress.
Is Meritocracy – Near-Powered Gamification Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Meritocracy – Near-Powered Gamification Plugin for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "meritocracy" plugin v1.3.1 exhibits a generally positive security posture with several strong points. Notably, there are no recorded vulnerabilities in its history, which is a significant indicator of good development practices and diligent maintenance. The code analysis reveals no dangerous functions, all SQL queries use prepared statements, and the vast majority of output is properly escaped, minimizing risks of injection and XSS. The absence of file operations and external HTTP requests further reduces the attack surface.
However, there are notable areas of concern. The plugin exposes a substantial attack surface with 8 AJAX handlers, a significant portion of which (6) lack authentication checks. This is a critical oversight that could allow unauthenticated users to trigger plugin functionality with potentially harmful consequences. While the taint analysis shows no critical or high-severity issues, the lack of capability checks on any entry points is a missed opportunity to further strengthen security, especially given the unprotected AJAX handlers.
In conclusion, while the "meritocracy" plugin demonstrates a commitment to secure coding practices in many areas, the unprotected AJAX handlers represent a significant security weakness that needs immediate attention. The lack of historical vulnerabilities is encouraging, but the current code presents a clear risk that could be mitigated by implementing proper authentication and capability checks on all entry points.
Key Concerns
- Unprotected AJAX handlers
- No capability checks on entry points
Meritocracy – Near-Powered Gamification Plugin for WordPress Security Vulnerabilities
Meritocracy – Near-Powered Gamification Plugin for WordPress Code Analysis
Output Escaping
Data Flow Analysis
Meritocracy – Near-Powered Gamification Plugin for WordPress Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Meritocracy – Near-Powered Gamification Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Meritocracy – Near-Powered Gamification Plugin for WordPress Alternatives
Web3Press – Migrating to 3ook.com Decentralized Bookstore
likecoin
FINAL LEGACY VERSION: Read-only maintenance version before 3ook.com transition. No new publishing features.
Chainwire Integration
chainwire-integration
This plugin allows to integrate your website with MediaFuse platforms.
Web3 Access
web3-access
Accept cryptocurrency payments via MetaMask or web3 browser wallets. Restrict content to NFT owners or crypto wallets that make a payment.
CardanoPress – Cardano Blockchain Integration for WordPress
cardanopress
Integrate the Cardano blockchain with your WordPress website. Merging Web2 and Web3.
Chainium – Blockchain Integrations & Web3 Crypto Wallet Authenticator
chainium
Blockchain Integrations, Web3, Crypto, Wallet, Authenticator, Login, NFT Marketplace, Explorer, MetaMask, Trust Wallet, Ethereum, Solana, Tron
Meritocracy – Near-Powered Gamification Plugin for WordPress Developer Profile
1 plugin · 10 total installs
How We Detect Meritocracy – Near-Powered Gamification Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/meritocracy/gateways/mycred-buycred-meritocracy.php/wp-content/plugins/meritocracy/gateways/mycred-cashcred-meritocracy.phpmeritocracy/style.css?ver=meritocracy/script.js?ver=