
myCred for Elementor Security & Risk Analysis
wordpress.org/plugins/mycred-for-elementor📢 🚨 Important Notice: The myCred for Elementor is now part of myCred Core plugin and will no longer receive updates here. Only security fixes will be …
Is myCred for Elementor Safe to Use in 2026?
Generally Safe
Score 99/100myCred for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The "mycred-for-elementor" v1.3 plugin presents a mixed security posture. On one hand, the static analysis reveals a complete absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events, indicating a very small attack surface. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests. This suggests a developer mindful of common plugin vulnerabilities related to data handling and external interactions.
However, significant concerns arise from the lack of output escaping and capability checks. With 35 total outputs and only 11% properly escaped, there is a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, especially as the vulnerability history confirms XSS as a common past issue. The absence of capability checks on any entry points (though there are none reported) is also a theoretical weakness, as it implies that if any new entry points were introduced without proper checks, they would be immediately unprotected.
The plugin's vulnerability history, including a medium severity XSS vulnerability, reinforces the output escaping concerns. While currently unpatched CVEs are zero, the past occurrence of XSS, coupled with the low output escaping rate, suggests a persistent risk in how user-generated content might be rendered. In conclusion, while the plugin excels in reducing its attack surface and handling database interactions securely, the critical lack of comprehensive output escaping and the historical pattern of XSS vulnerabilities present a notable security risk that requires immediate attention.
Key Concerns
- Low output escaping rate (11%)
- No capability checks on entry points
- Past medium XSS vulnerability
myCred for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
myCred Elementor <= 1.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
myCred for Elementor Code Analysis
Output Escaping
myCred for Elementor Attack Surface
WordPress Hooks 9
Maintenance & Trust
myCred for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
myCred for Elementor Alternatives
Easy Elements for Elementor – Addons & Website Templates
easy-elements
Modern Elementor Addons: A lightweight, powerful addon with beautifully designed widgets and extensions to build creative, animated websites.
Qi Addons For Elementor
qi-addons-for-elementor
Qi Addons for Elementor is a comprehensive library of 60+ custom, flexible & easily styled Elementor widgets developed by Qode Interactive.
Addon Elements for Elementor (formerly Elementor Addon Elements)
addon-elements-for-elementor-page-builder
Addon Elements for Elementor comes with 40+ widgets and extensions to extend the power of Elementor Page Builder.
HT Mega Addons for Elementor – Elementor Widgets & Template Builder
ht-mega-for-elementor
Elementor addon offering 135+ widgets — Mega Menu, Ready Templates, Page Builder, Slider, Gallery, Post Grid, AI Writer & more.
Livemesh Addons by Elementor
addons-for-elementor
Elementor Addons that saves time with multiple ready-to-use drag and drop styles for 30+ essential widgets built for Elementor page builder.
myCred for Elementor Developer Profile
84 plugins · 1.4M total installs
How We Detect myCred for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycred-for-elementor/assets/css/mycred-elementor-editor.css/wp-content/plugins/mycred-for-elementor/assets/js/mycred-elementor-editor.js/wp-content/plugins/mycred-for-elementor/assets/css/mycred-elementor-frontend.css/wp-content/plugins/mycred-for-elementor/assets/js/mycred-elementor-frontend.jsmycred-for-elementor/assets/css/mycred-elementor-editor.css?ver=mycred-for-elementor/assets/js/mycred-elementor-editor.js?ver=mycred-for-elementor/assets/css/mycred-elementor-frontend.css?ver=mycred-for-elementor/assets/js/mycred-elementor-frontend.js?ver=HTML / DOM Fingerprints
mycred-elementor-balancemycred-elementor-leaderboardmycred-elementor-historymycred-elementor-exchangemycred-elementor-givemycred-elementor-linkmycred-elementor-affiliate-idmycred-elementor-affiliate-link+3 moredata-mycred-typedata-mycred-iddata-mycred-titleMyCredElementorFrontend[mycred_total_pts][mycred_total_balance][mycred_history][mycred_total_since]