
myCred – myCred Githubreviews Security & Risk Analysis
wordpress.org/plugins/mycred-githubreviewsEmpower your Website with myCred Github! Reward users with points for approved pull requests on designated repositories. Easy GitHub integration.
Is myCred – myCred Githubreviews Safe to Use in 2026?
Generally Safe
Score 92/100myCred – myCred Githubreviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "mycred-githubreviews" v1.1 exhibits a concerning security posture due to a significant number of unprotected entry points. While the plugin demonstrates good practices in handling SQL queries and a high rate of output escaping, the presence of 5 AJAX handlers without authentication checks presents a substantial risk. This means that any unauthenticated user could potentially interact with these AJAX endpoints, leading to unintended actions or information disclosure. The lack of nonce checks further exacerbates this issue, as it allows for potential cross-site request forgery (CSRF) attacks.
The static analysis reveals no critical or high-severity taint flows, which is a positive sign. The absence of known vulnerabilities in its history is also encouraging and suggests a potentially stable codebase. However, this is overshadowed by the critical design flaw of exposing so many functionalities without proper authorization. The bundled Select2 library, while not inherently a vulnerability, could become one if it is outdated and known exploits exist for it, though this is not explicitly stated in the provided data.
In conclusion, the plugin has strengths in its SQL handling and output escaping. Nevertheless, the critical weakness of unprotected AJAX handlers and missing nonce checks makes it a high-risk plugin in its current state. Remediation of these entry points is essential to improve its security posture.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks
- Unprotected shortcodes
myCred – myCred Githubreviews Security Vulnerabilities
myCred – myCred Githubreviews Release Timeline
myCred – myCred Githubreviews Code Analysis
Bundled Libraries
Output Escaping
myCred – myCred Githubreviews Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
myCred – myCred Githubreviews Maintenance & Trust
Maintenance Signals
Community Trust
myCred – myCred Githubreviews Alternatives
Github Embed
github-embed
Plugin that allows you to embed details from GitHub just by pasting in the URL as you would any other embed source. Currently supports:
WPLMS MyCred AddOn
wplms-mycred-addon
Connect WP LMS with MyCred platform
Static Site Exporter
jekyll-exporter
Features
Pastacode
pastacode
Use Pastacode to add code into your posts with the awesome PrismJs coloration library. So, past'a code!
WP Plugin Info Card
wp-plugin-info-card
Add beautiful, customizable cards to showcase plugins, themes, and projects from WordPress.org, GitHub, EDD, and third-party plugins.
myCred – myCred Githubreviews Developer Profile
89 plugins · 1.4M total installs
How We Detect myCred – myCred Githubreviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycred-githubreviews/assets/css/github-review-styles.css/wp-content/plugins/mycred-githubreviews/assets/js/github-review-script.js/wp-content/plugins/mycred-githubreviews/assets/js/github-review-script.jsmycred-githubreviews/assets/css/github-review-styles.css?ver=mycred-githubreviews/assets/js/github-review-script.js?ver=HTML / DOM Fingerprints
mg-github-reviews-wrap<!-- myCred Github Reviews Settings --><!-- myCred Github Reviews Status Check --><!-- myCred Github Reviews Admin Settings --><!-- myCred Github Reviews App Settings -->+1 moredata-github-repodata-github-client-iddata-github-redirect-urimyCredGithubReviews[mycred_github_reviews]