
myCred Amelia – Gamification with Events & Appointments Booking Security & Risk Analysis
wordpress.org/plugins/mycred-ameliamyCred-Amelia is a myCred add-on that connects myCred with Amelia appointment-booking WordPress plugin. Using myCred-Amelia, user can book appointment
Is myCred Amelia – Gamification with Events & Appointments Booking Safe to Use in 2026?
Generally Safe
Score 100/100myCred Amelia – Gamification with Events & Appointments Booking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mycred-amelia" v1.1.9 plugin exhibits a generally strong security posture based on the provided static analysis. There are no identified critical or high-severity vulnerabilities in the code signals or taint analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the plugin does not appear to leverage common attack vectors like AJAX handlers, REST API routes, or shortcodes, significantly limiting its attack surface. The lack of recorded vulnerabilities in its history also suggests a history of secure development.
However, a notable concern arises from the absence of any nonce checks or capability checks across its entry points. While the attack surface is currently zero, this indicates a potential weakness if functionality were to be added in the future without proper authorization checks. Additionally, a significant portion of output (35%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if any user-supplied data is ever rendered directly in the frontend or backend without sanitization. These represent potential risks that, while not actively exploited in the current version, should be addressed for long-term security resilience.
Key Concerns
- No nonce checks implemented
- Capability checks are missing
- Significant unescaped output detected
myCred Amelia – Gamification with Events & Appointments Booking Security Vulnerabilities
myCred Amelia – Gamification with Events & Appointments Booking Code Analysis
Output Escaping
myCred Amelia – Gamification with Events & Appointments Booking Attack Surface
WordPress Hooks 7
Maintenance & Trust
myCred Amelia – Gamification with Events & Appointments Booking Maintenance & Trust
Maintenance Signals
Community Trust
myCred Amelia – Gamification with Events & Appointments Booking Alternatives
SimplyBook.me – Booking and reservations calendar
simplybook
Simply add a booking calendar to your site to schedule bookings, reservations, appointments and to collect payments.
Salon Booking System – Free Version
salon-booking-system
Appointment scheduling plugin for salons, spas, and wellness centers to streamline bookings and improve customer satisfaction.
SuperSaaS – online appointment scheduling
supersaas-appointment-scheduling
SuperSaaS is a flexible appointment scheduling system that works with many different businesses. The basic version is free.
Alex Reservations: Smart Restaurant Booking
alex-reservations
Restaurant reservations solution to help you manage your daily bookings.
Time Slot – Booking and Appointment Scheduling
timeslot
Book appointments, organize your schedule, send notifications, and more. Keep booking simple for everyone with Time Slot.
myCred Amelia – Gamification with Events & Appointments Booking Developer Profile
84 plugins · 1.4M total installs
How We Detect myCred Amelia – Gamification with Events & Appointments Booking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
am-confirmation-booking-costam-fs__payments-heading-mainam-cabinetdata-mycred-amelia-booking-urlmyCredPrefixmyCredBalanceisUserLoggedInbuyCredUrlameliaActionsbeforeConfirmBookingLoaded+1 more/wp-json/mycred-amelia/v1/get-balance<h4>Login to Book.</h4><a href="/buypoints"><h4>You dont have enough Points. Click here to Buy.</h4></a>