
myCred for Events Manager Pro Security & Risk Analysis
wordpress.org/plugins/mycred-for-events-manager-pro📢🚨 Important Notice: myCred for Events Manager Pro is now part of the myCred Toolkit and will no longer receive updates here.
Is myCred for Events Manager Pro Safe to Use in 2026?
Generally Safe
Score 92/100myCred for Events Manager Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "mycred-for-events-manager-pro" v3.1 reveals a generally strong security posture in several key areas. The plugin exhibits a complete absence of AJAX handlers, REST API routes, shortcodes, and cron events, resulting in a zero-attack surface for direct external interaction. Furthermore, there are no identified dangerous functions, file operations, or external HTTP requests, which significantly reduces potential attack vectors. The plugin also demonstrates a commitment to secure data handling by using prepared statements for all its SQL queries and showing a high percentage of properly escaped output. The taint analysis found no unsanitized paths or critical/high severity flows, indicating a good level of protection against common injection vulnerabilities.
However, there are notable areas for concern. The complete lack of nonce checks and capability checks across all potential entry points (though there are none currently defined) is a significant weakness. Should any new entry points be introduced in future versions without proper authorization mechanisms, the plugin would be highly vulnerable. The fact that 19% of output is not properly escaped, while not resulting in critical taint flows in this analysis, still presents a risk of Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is present in those unescaped outputs. The plugin's vulnerability history is clean, with zero known CVEs, which is a positive indicator of past security diligence. However, the absence of vulnerabilities does not negate the risks identified in the current code analysis.
Key Concerns
- No Nonce Checks
- No Capability Checks
- Unescaped Output (19%)
myCred for Events Manager Pro Security Vulnerabilities
myCred for Events Manager Pro Release Timeline
myCred for Events Manager Pro Code Analysis
Output Escaping
Data Flow Analysis
myCred for Events Manager Pro Attack Surface
WordPress Hooks 37
Maintenance & Trust
myCred for Events Manager Pro Maintenance & Trust
Maintenance Signals
Community Trust
myCred for Events Manager Pro Alternatives
Events Manager – Calendar, Bookings, Tickets, and more!
events-manager
Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.
Events Manager – Move Bookings
stonehenge-em-move-bookings
Moves an upcoming Booking to different upcoming Event in Events Manager with a simple select dropdown.
myCred for Event Espresso 4
mycred-for-event-espresso-4
📢🚨 Important Notice: myCred for Event Espresso 4 is now part of the myCred Toolkit and will no longer receive updates here.
Events Manager – MultiSite Email
events-manager-add-on-multisite-mail-settings
This add-on has been integrated into Events Manager Email Users as of 21-03-2019. Please install that plugin instead.
WP Events Manager
wp-events-manager
The all in one Events Manager for WordPress: create and manage events, sell event tickets online easily. No Coding Required.
myCred for Events Manager Pro Developer Profile
89 plugins · 1.4M total installs
How We Detect myCred for Events Manager Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycred-for-events-manager-pro/css/mycred-em.css/wp-content/plugins/mycred-for-events-manager-pro/js/mycred-em.js/wp-content/plugins/mycred-for-events-manager-pro/js/mycred-em.jsHTML / DOM Fingerprints
mycred-em-tickets-row<!-- IMPORTANT: This plugin is now part of the myCred Toolkit and will no longer be updated separately. Please install the myCred Toolkit for continued support and updates. --><!-- myCred for Events Manager Pro Plugin --><!-- myCred for Events Manager Pro --><!-- myCred for Events Manager Pro - Gateway -->+2 moredata-mycred-reward-typedata-mycred-reward-pointsmycred_em_ajax