
myCred BP Group Leaderboards Security & Risk Analysis
wordpress.org/plugins/mycred-bp-group-leaderboards📢🚨 Important Notice: myCred BP Group Leaderboards is now part of the myCred Toolkit and will no longer receive updates here.
Is myCred BP Group Leaderboards Safe to Use in 2026?
Generally Safe
Score 92/100myCred BP Group Leaderboards has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mycred-bp-group-leaderboards" plugin, version 1.3.2, exhibits a generally strong security posture based on the provided static analysis. The absence of known vulnerabilities in its history is a positive indicator, suggesting a history of secure development and maintenance. Furthermore, the code demonstrates good practices by exclusively using prepared statements for its SQL queries and a high percentage of properly escaped output, minimizing risks of SQL injection and XSS. The plugin also shows no file operations or external HTTP requests, further reducing its attack surface.
However, the analysis does reveal a concerning finding: a single flow with unsanitized paths identified during taint analysis. While it did not result in a critical or high severity finding, this indicates a potential avenue for attackers to manipulate file paths or other path-related operations, which could lead to unexpected behavior or security issues if exploited. Additionally, the complete absence of nonce checks and capability checks across all entry points is a significant concern. While there are no exposed entry points (AJAX, REST API, shortcodes, cron events) in this version, this pattern suggests a lack of fundamental security checks that would be critical if any new entry points were introduced or if existing, less obvious, entry points were discovered.
In conclusion, the plugin has strengths in its SQL and output sanitization and a clean vulnerability history. However, the identified unsanitized path flow and the complete lack of nonce and capability checks represent potential weaknesses that should be addressed to further enhance its security.
Key Concerns
- Flow with unsanitized paths
- 0 Nonce checks found
- 0 Capability checks found
myCred BP Group Leaderboards Security Vulnerabilities
myCred BP Group Leaderboards Release Timeline
myCred BP Group Leaderboards Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
myCred BP Group Leaderboards Attack Surface
WordPress Hooks 18
Maintenance & Trust
myCred BP Group Leaderboards Maintenance & Trust
Maintenance Signals
Community Trust
myCred BP Group Leaderboards Alternatives
Advanced XProfile Fields for BuddyPress
advanced-xprofile-fields-for-buddypress
Enhance your BuddyPress profile fields with Advanced XProfile Fields for BuddyPress. Manage fields labels, validation and show fields in admin.
Buddypress Xprofile Fields Custom Css Classes
bp-xprofile-fields-custom-css-classes
Add custom classes to xprofile fields for ease of styling.
myCred for BuddyPress Compliments
mycred-for-buddypress-compliments
📢 Important Notice: myCred for BuddyPress Compliments is now part of the myCred Toolkit and will no longer receive updates here.
BP Favorite Groups
bp-favorite-groups
BP Favorite Groups is an easy way for users to bookmark the best groups. Users can filter activity by their favorite groups.
BP Premiums for BuddyPress
bp-premiums
BP Premiums is an addon for monetizing social networks. Charge users a premium for accessing features on your network.
myCred BP Group Leaderboards Developer Profile
89 plugins · 1.4M total installs
How We Detect myCred BP Group Leaderboards
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycred-bp-group-leaderboards/assets/css/bpgl-admin.css/wp-content/plugins/mycred-bp-group-leaderboards/assets/css/bpgl-public.css/wp-content/plugins/mycred-bp-group-leaderboards/assets/js/bpgl-admin.jsmycred-bp-group-leaderboards/assets/css/bpgl-admin.css?ver=mycred-bp-group-leaderboards/assets/css/bpgl-public.css?ver=mycred-bp-group-leaderboards/assets/js/bpgl-admin.js?ver=HTML / DOM Fingerprints
bp-group-leaderboard-wrapbp-group-leaderboard-titlebp-group-leaderboard-contentbp-group-leaderboard-entrybp-group-leaderboard-rankbp-group-leaderboard-userbp-group-leaderboard-pointsbp-group-leaderboard-avatar+2 more<!-- BP Group Leaderboards Settings --><!-- BP Group Leaderboard Content -->data-bp-group-leaderboard-group-iddata-bp-group-leaderboard-point-typedata-bp-group-leaderboard-user-idBPGL_ADMINmycred_bp_group_leaderboards_ajaxurl[bp_group_leaderboard]