
myCred – Learndash Security & Risk Analysis
wordpress.org/plugins/mycred-learndash📢 Important Notice: myCred Learndash is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be provided.
Is myCred – Learndash Safe to Use in 2026?
Generally Safe
Score 100/100myCred – Learndash has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mycred-learndash plugin v2.3 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding database interactions, with all SQL queries utilizing prepared statements, and a lack of file operations or external HTTP requests, which are common vectors for attacks. The absence of recorded vulnerabilities in its history is also a strong indicator of past security diligence. However, a significant concern arises from the substantial attack surface exposed through AJAX handlers. With 23 AJAX handlers, all of which lack authentication checks, a large portion of the plugin's functionality is exposed to unauthenticated users, creating a prime target for malicious exploitation. While the static analysis didn't reveal critical taint flows or dangerous functions, the sheer number of unprotected entry points is a considerable risk that could potentially lead to various vulnerabilities if not properly secured at the application level.
Key Concerns
- High number of unprotected AJAX handlers
- Low percentage of properly escaped output
- Low number of capability checks relative to entry points
myCred – Learndash Security Vulnerabilities
myCred – Learndash Code Analysis
SQL Query Safety
Output Escaping
myCred – Learndash Attack Surface
AJAX Handlers 23
Shortcodes 2
WordPress Hooks 93
Maintenance & Trust
myCred – Learndash Maintenance & Trust
Maintenance Signals
Community Trust
myCred – Learndash Alternatives
Uncanny Toolkit for LearnDash
uncanny-learndash-toolkit
Extend LearnDash with a variety of useful modules that make it even easier to build great learner experiences with LearnDash.
Design Upgrade for LearnDash
design-upgrade-learndash
Instantly improve LearnDash's design -- focus mode, course content, profile page, course navigation & course grid -- to more closely match yo …
BuddyPress for LearnDash
buddypress-learndash
BuddyPress for LearnDash integrates the LearnDash LMS plugin with BuddyPress, so you can add groups, activity, members, and forums to your courses.
Autocomplete LearnDash Lessons and Topics
autocomplete-learndash
Autocomplete for LearnDash Lessons and Topics will automatically mark the lessons and topics as completed.
PowerPack for LearnDash
powerpack-for-learndash
PowerPack for LearnDash offers 42 modules you can activate in a click to power up your LearnDash LMS website. What's included with PowerPack for …
myCred – Learndash Developer Profile
84 plugins · 1.4M total installs
How We Detect myCred – Learndash
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycred-learndash/inc/assets/css/mycred-leaderboard-style.css/wp-content/plugins/mycred-learndash/inc/assets/js/learndash-mycred-pts-handler.js/wp-content/plugins/mycred-learndash/inc/assets/js/learndash-mycred-pts-handler.jsHTML / DOM Fingerprints
mycred-learndash-noticedata-course_idLD_MYCRED_Handler