myCred – AnsPress (Gamify your Question and answer Sites) Security & Risk Analysis

wordpress.org/plugins/mycred-anspress-integration

📢🚨 Important Notice: myCred AnsPress is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be provided.

10 active installs v1.1.9 PHP 7.0+ WP 4.8+ Updated Apr 17, 2025
achievementanspressmycredquizranks
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is myCred – AnsPress (Gamify your Question and answer Sites) Safe to Use in 2026?

Generally Safe

Score 100/100

myCred – AnsPress (Gamify your Question and answer Sites) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "mycred-anspress-integration" plugin v1.1.9 presents a seemingly good security posture at first glance, with no direct entry points like AJAX handlers, REST API routes, or shortcodes identified. The absence of dangerous functions, external HTTP requests, and file operations is also positive. Furthermore, all identified SQL queries utilize prepared statements, which is a critical security best practice. The plugin also boasts a clean vulnerability history with no known CVEs.

However, a significant concern arises from the low percentage of properly escaped output (34%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or plugin-generated content might not be sufficiently sanitized before being displayed in the browser. The lack of any identified capability checks is also a weakness, as it suggests that sensitive operations, if they exist, might not be adequately protected against unauthorized access. While the attack surface is reported as zero, this is based on the static analysis and might not capture all potential interaction points.

In conclusion, the plugin demonstrates strengths in areas like SQL query handling and vulnerability history. Nevertheless, the widespread lack of output escaping and the absence of capability checks represent notable weaknesses that could expose users to security risks. Further investigation into the specific areas where output is not properly escaped is strongly recommended.

Key Concerns

  • Low percentage of properly escaped output
  • No capability checks identified
Vulnerabilities
None known

myCred – AnsPress (Gamify your Question and answer Sites) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

myCred – AnsPress (Gamify your Question and answer Sites) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
99
50 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

34% escaped149 total outputs
Attack Surface

myCred – AnsPress (Gamify your Question and answer Sites) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionap_select_answerincludes\mycred-anspress-best-answer.php:50
actionap_select_answerincludes\mycred-anspress-get-best-answer.php:50
actionap_vote_downincludes\mycred-anspress-get-vote-down.php:49
actionap_vote_upincludes\mycred-anspress-get-vote-up.php:49
actionap_after_new_answerincludes\mycred-anspress-new-answer.php:42
actionactivated_pluginincludes\mycred-anspress-new-question.php:21
actionap_after_new_questionincludes\mycred-anspress-new-question.php:57
actionap_publish_commentincludes\mycred-anspress-publish-comment.php:52
actionap_vote_downincludes\mycred-anspress-vote-down.php:49
actionap_vote_upincludes\mycred-anspress-vote-up.php:48
actionadmin_noticesmycred-anspress-integration.php:100
actionadmin_enqueue_scriptsmycred-anspress-integration.php:134
filtermycred_setup_hooksmycred-anspress-integration.php:135
actionmycred_load_hooksmycred-anspress-integration.php:136
filtermycred_all_referencesmycred-anspress-integration.php:137
actionadmin_noticesmycred-anspress-integration.php:140
Maintenance & Trust

myCred – AnsPress (Gamify your Question and answer Sites) Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 17, 2025
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

myCred – AnsPress (Gamify your Question and answer Sites) Developer Profile

Saad Iqbal

84 plugins · 1.4M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
287 days
View full developer profile
Detection Fingerprints

How We Detect myCred – AnsPress (Gamify your Question and answer Sites)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mycred-anspress-integration/assets/css/mycred-anspress.css/wp-content/plugins/mycred-anspress-integration/assets/js/mycred-anspress.js
Script Paths
/wp-content/plugins/mycred-anspress-integration/assets/js/mycred-anspress.js
Version Parameters
mycred-anspress-integration/assets/css/mycred-anspress.css?ver=mycred-anspress-integration/assets/js/mycred-anspress.js?ver=

HTML / DOM Fingerprints

CSS Classes
mycred-anspress-wrapper
FAQ

Frequently Asked Questions about myCred – AnsPress (Gamify your Question and answer Sites)