
myCred LearnDash Points Importer Security & Risk Analysis
wordpress.org/plugins/mycred-learndash-points-importer๐ข๐จ Important Notice: myCred LearnDash Points Importer is now part of the myCred Toolkit and will no longer receive updates here.
Is myCred LearnDash Points Importer Safe to Use in 2026?
Generally Safe
Score 100/100myCred LearnDash Points Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "mycred-learndash-points-importer" version 1.1.7 exhibits a concerning security posture primarily due to a significant lack of security checks on its single exposed entry point.
The static analysis reveals that the plugin has one AJAX handler that does not include any authentication checks. This is a major vulnerability, as it allows any user, including unauthenticated ones, to potentially interact with this handler. The absence of nonce checks and capability checks further exacerbates this issue, leaving the plugin vulnerable to various attacks, such as Cross-Site Request Forgery (CSRF) and unauthorized data manipulation.
While the plugin demonstrates good practices in output escaping and has no file operations or external HTTP requests, and crucially, has no recorded historical vulnerabilities, these strengths are overshadowed by the critical flaw in its AJAX handler. The lack of taint analysis flows is likely a consequence of the limited attack surface, but the absence of protective measures on that surface is a significant weakness. Until the unprotected AJAX handler is secured with appropriate authentication and capability checks, the plugin remains at high risk.
Key Concerns
- Unprotected AJAX handler
- Missing nonce checks
- Missing capability checks
- Raw SQL queries without prepare
myCred LearnDash Points Importer Security Vulnerabilities
myCred LearnDash Points Importer Code Analysis
SQL Query Safety
Output Escaping
myCred LearnDash Points Importer Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
myCred LearnDash Points Importer Maintenance & Trust
Maintenance Signals
Community Trust
myCred LearnDash Points Importer Alternatives
WPLMS MyCred AddOn
wplms-mycred-addon
Connect WP LMS with MyCred platform
myCred โ Learndash
mycred-learndash
๐ข Important Notice: myCred Learndash is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be provided.
myCred Tutor LMS โ Gamification in eLearning
mycred-tutor-lms-gamification-in-elearning
Connect mycred with Tutor LMS
GamiPress โ myCRED Importer
gamipress-mycred-importer
Tool to migrate all stored data from myCRED to GamiPress
myCred โ GamiPress Importer
mycred-gamipress-importer
myCred GamiPress Importer helps you to transfer GamiPress achievements into myCred
myCred LearnDash Points Importer Developer Profile
84 plugins ยท 1.4M total installs
How We Detect myCred LearnDash Points Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycred-learndash-points-importer/assets/js/custom.js/wp-content/plugins/mycred-learndash-points-importer/assets/css/style.cssmycred-learndash-points-importer/assets/js/custom.js?ver=mycred-learndash-points-importer/assets/css/style.css?ver=HTML / DOM Fingerprints
mycred-ui-accordionmycred-ui-accordion-headermycred-ui-accordion-header-titlemycred-ui-accordion-header-iconmycred-ui-accordion-header-actionsmycred-ui-toggle-indicatormycred-ui-accordion-bodymycred_learndash_label+5 moreid="mycred_learndash_points_importer_points_type"id="mycred_learndash_points_importer_workflow"id="mycred_learndash_points_importer_run"