
myCred – GamiPress Importer Security & Risk Analysis
wordpress.org/plugins/mycred-gamipress-importermyCred GamiPress Importer helps you to transfer GamiPress achievements into myCred
Is myCred – GamiPress Importer Safe to Use in 2026?
Generally Safe
Score 92/100myCred – GamiPress Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'mycred-gamipress-importer' plugin version 1.1.8 presents a moderate security risk due to critical vulnerabilities in its handling of entry points. The static analysis reveals a significant concern with two AJAX handlers that lack any authentication checks. This means that any user, even unauthenticated ones, could potentially trigger these handlers, leading to unauthorized actions or information disclosure. The absence of nonce checks further exacerbates this risk, as it opens the door to Cross-Site Request Forgery (CSRF) attacks.
While the plugin demonstrates good practices in other areas, such as using prepared statements for most SQL queries and a lack of dangerous functions or file operations, the unprotected entry points are a major weakness. The fact that there are no recorded vulnerabilities in its history is a positive indicator of past security efforts, but it doesn't mitigate the immediate risks identified in the current code. The low percentage of properly escaped output is also a concern, potentially leading to Cross-Site Scripting (XSS) vulnerabilities.
Overall, the plugin's security posture is concerning primarily because of the unprotected AJAX endpoints. Despite a clean vulnerability history, the identified code signals necessitate caution. Users should be aware of the potential for unauthorized access and data manipulation. Further security hardening, particularly implementing proper authentication and authorization checks on all AJAX handlers, is strongly recommended.
Key Concerns
- AJAX handlers without auth checks
- Missing nonce checks on AJAX
- Low output escaping percentage
myCred – GamiPress Importer Security Vulnerabilities
myCred – GamiPress Importer Release Timeline
myCred – GamiPress Importer Code Analysis
SQL Query Safety
Output Escaping
myCred – GamiPress Importer Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
myCred – GamiPress Importer Maintenance & Trust
Maintenance Signals
Community Trust
myCred – GamiPress Importer Alternatives
Connect GamiPress to Discord
connect-gamipress-and-discord
Create a community of your Members by connecting your GamiPress Website to your Discord server.
GamiPress – myCRED Importer
gamipress-mycred-importer
Tool to migrate all stored data from myCRED to GamiPress
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
gamipress
Boost your gamification marketing & reward your users with points, achievements, badges & ranks to increase your site activity & loyalty!
GamiPress – Leaderboards Include/Exclude Users
gamipress-leaderboards-include-exclude-users
Include or exclude specific users or roles on any leaderboard.
GamiPress – Block Users
gamipress-block-users
Block users and roles from getting awarded through the GamiPress awards engine
myCred – GamiPress Importer Developer Profile
89 plugins · 1.4M total installs
How We Detect myCred – GamiPress Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycred-gamipress-importer/assets/js/custom.js/wp-content/plugins/mycred-gamipress-importer/assets/css/style.css/wp-content/plugins/mycred-gamipress-importer/assets/js/custom.jsmycred-gamipress-importer/assets/js/custom.js?ver=mycred-gamipress-importer/assets/css/style.css?ver=HTML / DOM Fingerprints
gi_import_points_typesgi_import_pointsgi_import_badgsgi_ranksgi_import_buttongi_iconmycred-gamipress-labelgi-right-div+1 morename="gi_import_types"id="gi_import_types"class="button button-primary gi_import_points_types gi_import_button"value="gi_import_types"name="gi_import_points"id="gi_import_points"+10 moreMYCRED_GI_PREFIXMYCRED_GI_VERSION