myCred for Elementor Security & Risk Analysis

wordpress.org/plugins/mycred-for-elementor

📢 🚨 Important Notice: The myCred for Elementor is now part of myCred Core plugin and will no longer receive updates here. Only security fixes will be …

500 active installs v1.3 PHP 7.0+ WP 4.8+ Updated Oct 15, 2025
elementorelementor-addonelementor-widgetelementspage-builder
99
A · Safe
CVEs total1
Unpatched0
Last CVEOct 21, 2024
Download
Safety Verdict

Is myCred for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

myCred for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 21, 2024Updated 5mo ago
Risk Assessment

The "mycred-for-elementor" v1.3 plugin presents a mixed security posture. On one hand, the static analysis reveals a complete absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events, indicating a very small attack surface. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests. This suggests a developer mindful of common plugin vulnerabilities related to data handling and external interactions.

However, significant concerns arise from the lack of output escaping and capability checks. With 35 total outputs and only 11% properly escaped, there is a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, especially as the vulnerability history confirms XSS as a common past issue. The absence of capability checks on any entry points (though there are none reported) is also a theoretical weakness, as it implies that if any new entry points were introduced without proper checks, they would be immediately unprotected.

The plugin's vulnerability history, including a medium severity XSS vulnerability, reinforces the output escaping concerns. While currently unpatched CVEs are zero, the past occurrence of XSS, coupled with the low output escaping rate, suggests a persistent risk in how user-generated content might be rendered. In conclusion, while the plugin excels in reducing its attack surface and handling database interactions securely, the critical lack of comprehensive output escaping and the historical pattern of XSS vulnerabilities present a notable security risk that requires immediate attention.

Key Concerns

  • Low output escaping rate (11%)
  • No capability checks on entry points
  • Past medium XSS vulnerability
Vulnerabilities
1

myCred for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-49702medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

myCred Elementor <= 1.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 21, 2024 Patched in 1.2.7 (10d)
Code Analysis
Analyzed Mar 16, 2026

myCred for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
31
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

11% escaped35 total outputs
Attack Surface

myCred for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionelementor/elements/categories_registeredincludes\mycred-elem-functions.php:13
actioninitmycred-elementor.php:98
actionplugins_loadedmycred-elementor.php:99
actionadmin_noticesmycred-elementor.php:136
actionadmin_noticesmycred-elementor.php:141
actionadmin_noticesmycred-elementor.php:146
actionadmin_noticesmycred-elementor.php:152
actionelementor/widgets/widgets_registeredmycred-elementor.php:159
actionadmin_noticesmycred-elementor.php:386
Maintenance & Trust

myCred for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 15, 2025
PHP min version7.0
Downloads28K

Community Trust

Rating100/100
Number of ratings2
Active installs500
Developer Profile

myCred for Elementor Developer Profile

Saad Iqbal

84 plugins · 1.4M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
287 days
View full developer profile
Detection Fingerprints

How We Detect myCred for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mycred-for-elementor/assets/css/mycred-elementor-editor.css/wp-content/plugins/mycred-for-elementor/assets/js/mycred-elementor-editor.js/wp-content/plugins/mycred-for-elementor/assets/css/mycred-elementor-frontend.css/wp-content/plugins/mycred-for-elementor/assets/js/mycred-elementor-frontend.js
Version Parameters
mycred-for-elementor/assets/css/mycred-elementor-editor.css?ver=mycred-for-elementor/assets/js/mycred-elementor-editor.js?ver=mycred-for-elementor/assets/css/mycred-elementor-frontend.css?ver=mycred-for-elementor/assets/js/mycred-elementor-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
mycred-elementor-balancemycred-elementor-leaderboardmycred-elementor-historymycred-elementor-exchangemycred-elementor-givemycred-elementor-linkmycred-elementor-affiliate-idmycred-elementor-affiliate-link+3 more
Data Attributes
data-mycred-typedata-mycred-iddata-mycred-title
JS Globals
MyCredElementorFrontend
Shortcode Output
[mycred_total_pts][mycred_total_balance][mycred_history][mycred_total_since]
FAQ

Frequently Asked Questions about myCred for Elementor