
myCred Credly Security & Risk Analysis
wordpress.org/plugins/mycred-credly📢🚨 Important Notice: myCred Credly is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be provided.
Is myCred Credly Safe to Use in 2026?
Generally Safe
Score 100/100myCred Credly has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mycred-credly v2.1.3 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin has no recorded vulnerabilities (CVEs), which is a significant positive indicator. The code analysis reveals a good adherence to secure coding practices, with 100% of SQL queries using prepared statements and a high percentage (87%) of output properly escaped. Furthermore, there are no observed dangerous functions, file operations, or taint flows indicating unsanitized paths, suggesting a low risk of common code execution vulnerabilities.
However, there are a few areas that warrant attention. The plugin relies on four nonce checks, which is positive, but the absence of capability checks on its entry points (AJAX handlers and shortcodes) is a notable concern. While the static analysis reported zero unprotected entry points, this likely means they are protected by general WordPress user authentication rather than specific role or capability checks. This could potentially leave them vulnerable to privilege escalation if an attacker can impersonate a logged-in user with insufficient privileges. The presence of external HTTP requests also introduces a minor risk, as these could be exploited in certain scenarios, though without further analysis of their purpose, it's difficult to quantify the exact risk.
In conclusion, mycred-credly v2.1.3 appears to be a well-developed plugin with a strong foundation in secure coding. Its lack of past vulnerabilities is a testament to its developers' efforts. The primary area for improvement lies in implementing more granular capability checks for its AJAX handlers and shortcodes to bolster its defense against unauthorized access and potential privilege escalation.
Key Concerns
- No capability checks on entry points
- External HTTP requests present
- Minor unescaped output detected
myCred Credly Security Vulnerabilities
myCred Credly Code Analysis
Output Escaping
Data Flow Analysis
myCred Credly Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
myCred Credly Maintenance & Trust
Maintenance Signals
Community Trust
myCred Credly Alternatives
BadgeOS Community Add-on
badgeos-community-add-on
Adds BadgeOS features to BuddyPress and bbPress. Earn badges/points/ranks based on community activity, and display them on user profiles and activity …
BadgeOS BadgeStack Add-on
badgeos-badgestack-add-on
This add-on to BadgeOS automatically creates achievement types, pages and sample content to jumpstart your own badging system.
BadgeOS Invite Codes Add-on
badgeos-invite-codes-add-on
Enhances sites running BuddyPress and BadgeOS by joining users to one or more specified groups when they use a special Invite Code to join your site.
Open Badges Issuer Add-on
badgeos-open-badges-issuer-add-on
Issue Mozilla Open Badges directly from your site with this add-on for BadgeOS
BadgeOS Suggested Achievements Add-on
badgeos-suggested-achievements-add-on
Enhances sites running BuddyPress and BadgeOS by suggesting next possible incomplete achievements that a user can earn.
myCred Credly Developer Profile
84 plugins · 1.4M total installs
How We Detect myCred Credly
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycred-credly/assets/css/style.css/wp-content/plugins/mycred-credly/assets/js/script.js/wp-content/plugins/mycred-credly/assets/js/script.jsmycred-credly/assets/css/style.css?ver=mycred-credly/assets/js/script.js?ver=HTML / DOM Fingerprints
overlay-credly-modalmycred-credly-badge-modalmycred-credly-badge-modal-wraperclose-modal-btndata-mycred-credly-access-tokendata-mycred-credly-organization-iddata-mycred-credly-badge-idmycred_credly/wp-json/mycred-credly/v1/badges[mycred_credly_login]