
myCred H5P Security & Risk Analysis
wordpress.org/plugins/mycred-h5p๐ข๐จ Important Notice: myCred H5P is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be provided.
Is myCred H5P Safe to Use in 2026?
Generally Safe
Score 100/100myCred H5P has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mycred-h5p" plugin v1.2.9 exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with a near-perfect rate of output escaping and a majority of its SQL queries utilizing prepared statements. The absence of file operations and external HTTP requests further reduces potential attack vectors. Critically, the plugin has no known vulnerabilities or CVEs, historical or current, which is a very positive indicator of its stability and the developer's diligence.
However, the analysis reveals a significant area of concern: a complete lack of nonce checks and capability checks across all identified entry points. While the current entry point count is zero, this absence of fundamental security mechanisms is a critical oversight. Should any new entry points be introduced in future versions, or if an existing, uncounted entry point is discovered, these unchecked areas would be immediately vulnerable to various attacks, including Cross-Site Request Forgery (CSRF) and unauthorized actions. The lack of recorded vulnerability history is a strength, but it does not mitigate the inherent risk posed by the missing authentication and authorization checks.
Key Concerns
- Missing nonce checks
- Missing capability checks
myCred H5P Security Vulnerabilities
myCred H5P Code Analysis
SQL Query Safety
Output Escaping
myCred H5P Attack Surface
WordPress Hooks 12
Maintenance & Trust
myCred H5P Maintenance & Trust
Maintenance Signals
Community Trust
myCred H5P Alternatives
myCred โ AnsPress (Gamify your Question and answer Sites)
mycred-anspress-integration
๐ข๐จ Important Notice: myCred AnsPress is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be provided.
GamiPress โ Gamification plugin to reward points, achievements, badges & ranks in WordPress
gamipress
Boost your gamification marketing & reward your users with points, achievements, badges & ranks to increase your site activity & loyalty!
myCred Birthdays
mycred-birthdays
๐ข ๐จ Important Notice: The myCred Birthdays is now part of myCred Core plugin and will no longer receive updates here. Only security fixes will be prov …
myCred Tutor LMS โ Gamification in eLearning
mycred-tutor-lms-gamification-in-elearning
Connect mycred with Tutor LMS
myCred Badgr Integration
mycred-badgr-achievement-badge
๐ข๐จ Important Notice: myCred Badgr is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be provided.
myCred H5P Developer Profile
84 plugins ยท 1.4M total installs
How We Detect myCred H5P
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycred-h5p/assets/js/script.js/wp-content/plugins/mycred-h5p/assets/css/style.css/wp-content/plugins/mycred-h5p/assets/js/script.jsmycred-h5p/assets/js/script.js?ver=1.0mycred-h5p/assets/css/style.css?ver=1.0