
myCred GiveWP Security & Risk Analysis
wordpress.org/plugins/mycred-givewp📢🚨 Important Notice: myCred GiveWP is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be provided.
Is myCred GiveWP Safe to Use in 2026?
Generally Safe
Score 92/100myCred GiveWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "mycred-givewp" v1.0.8 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and has no known historical vulnerabilities. This suggests a generally well-maintained codebase and a commitment to security from the developers. The absence of file operations and external HTTP requests also limits potential attack vectors.
However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks. This creates a direct and unprotected attack surface, allowing any visitor to trigger these functions. Furthermore, the analysis indicates a lack of nonce and capability checks for these entry points, making them susceptible to Cross-Site Request Forgery (CSRF) and unauthorized actions. While no critical or high severity taint flows were detected, and output escaping is at a moderate 62%, the unprotected AJAX endpoints are the most pressing security issue.
In conclusion, the plugin's lack of historical vulnerabilities and use of prepared statements are strengths. However, the presence of unprotected AJAX endpoints represents a critical weakness that could be exploited. The absence of nonce and capability checks exacerbates this risk. Addressing these unprotected entry points should be the immediate priority to improve the plugin's security.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
- Moderate output escaping (38% not escaped)
myCred GiveWP Security Vulnerabilities
myCred GiveWP Release Timeline
myCred GiveWP Code Analysis
SQL Query Safety
Output Escaping
myCred GiveWP Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
myCred GiveWP Maintenance & Trust
Maintenance Signals
Community Trust
myCred GiveWP Alternatives
GiveWP Donation Widgets for Elementor
givewp-donation-widgets-for-elementor
A GiveWP add-on which allows you to embed any GiveWP shortcode into your Elementor-powered pages.
Give – Paystack Gateway
paystack-for-give
Fundraise with Paystack and GiveWP.
Charitable – Instamojo Payment Gateway
integrate-charitable-instamojo
Collect donations in INR via Debit Cards, Credit Cards, Net Banking, UPI, Wallets, EMI, NEFT, IMPS by integrating Instamojo Indian Payment Gateway.
LSX PayFast Gateway for Give
lsx-give-payfast-gateway
PayFast payment gateway for Give.
Give as you Live
give-as-you-live
Add a Give as you Live button or form to your website and start raising donations for your charity. The official plugin from Give as you Live.
myCred GiveWP Developer Profile
89 plugins · 1.4M total installs
How We Detect myCred GiveWP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycred-givewp/assets/js/give_wp_script.js/wp-content/plugins/mycred-givewp/assets/css/give_wp_style.css/wp-content/plugins/mycred-givewp/assets/js/mycred_give_wp_script.jswp-content/plugins/mycred-givewp/assets/js/give_wp_script.jswp-content/plugins/mycred-givewp/assets/css/give_wp_style.csswp-content/plugins/mycred-givewp/assets/js/mycred_give_wp_script.jsmycred_gwp_scriptmycred_gwp_stylemycred_give_wp_ajaxurlHTML / DOM Fingerprints
mycred_give_wp_frontend_scripts_objmycred_give_wp_frontend_scripts_obj