myCred for BuddyPress Compliments Security & Risk Analysis

wordpress.org/plugins/mycred-for-buddypress-compliments

📢 Important Notice: myCred for BuddyPress Compliments is now part of the myCred Toolkit and will no longer receive updates here.

20 active installs v1.1.9 PHP 7.0+ WP 4.8+ Updated Mar 27, 2025
badgesbuddypressbuddypress-complimentsmycredrewards
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is myCred for BuddyPress Compliments Safe to Use in 2026?

Generally Safe

Score 92/100

myCred for BuddyPress Compliments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "mycred-for-buddypress-compliments" v1.1.9 plugin exhibits a strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are exclusively using prepared statements, and all identified outputs are properly escaped. The absence of file operations, external HTTP requests, and any identified taint flows further contributes to a secure coding profile. The plugin also shows a clean vulnerability history with zero known CVEs, indicating a history of secure development or diligent patching by developers.

However, a notable concern arises from the complete absence of nonces, capability checks, and authentication checks on any of its entry points (AJAX handlers, REST API routes, shortcodes, and cron events). While the current attack surface is reported as zero, this lack of fundamental security checks means that if any new entry points were introduced or if the reported zero is an artifact of the analysis not covering all potential interactions, they would be entirely unprotected. This represents a significant potential weakness that, despite the current clean slate, could be exploited if the attack surface were to expand or be misinterpreted.

In conclusion, the plugin demonstrates excellent secure coding practices in its current implementation. The absence of vulnerabilities and the use of secure coding patterns are highly commendable. The primary weakness lies in the lack of basic security controls on its entry points, which, while not currently exploitable due to a zero attack surface, leaves room for potential future issues if not addressed. Developers should prioritize implementing capability checks and nonces on all entry points as a preventative measure.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
  • No authentication checks on AJAX
  • No authentication checks on REST API
  • No authentication checks on shortcodes
  • No authentication checks on cron events
Vulnerabilities
None known

myCred for BuddyPress Compliments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

myCred for BuddyPress Compliments Release Timeline

v1.1.9Current
v1.1.8
v1.1.7
v1.1.6
v1.1.5
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1
Code Analysis
Analyzed Mar 16, 2026

myCred for BuddyPress Compliments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
49 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped49 total outputs
Attack Surface

myCred for BuddyPress Compliments Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_noticesmycred-buddypress-compliments.php:93
filtermycred_setup_hooksmycred-buddypress-compliments.php:97
actionmycred_initmycred-buddypress-compliments.php:98
actionmycred_all_referencesmycred-buddypress-compliments.php:99
actionmycred_load_hooksmycred-buddypress-compliments.php:100
actionbp_compliments_after_savemycred-buddypress-compliments.php:251
Maintenance & Trust

myCred for BuddyPress Compliments Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 27, 2025
PHP min version7.0
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

myCred for BuddyPress Compliments Developer Profile

Saad Iqbal

89 plugins · 1.4M total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
267 days
View full developer profile
Detection Fingerprints

How We Detect myCred for BuddyPress Compliments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about myCred for BuddyPress Compliments