myCred – MemberPress Integration (Gamification for Membership Sites) Security & Risk Analysis

wordpress.org/plugins/mycred-memberpress

Take your MemberPress process to the next level with myCred MemberPress add-on - The best WordPress gamification add-on for MemberPress.

30 active installs v1.0.9 PHP 7.2+ WP 4.4+ Updated Apr 17, 2025
memberpressmembershipmycred-memberpress-integrationpointsrewards
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is myCred – MemberPress Integration (Gamification for Membership Sites) Safe to Use in 2026?

Generally Safe

Score 100/100

myCred – MemberPress Integration (Gamification for Membership Sites) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The 'mycred-memberpress' v1.0.9 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events suggests a minimal attack surface. Furthermore, the lack of dangerous functions, file operations, external HTTP requests, and the presence of no taint flows are all positive indicators. The code also reports no known CVEs, which is excellent. However, a significant concern is the sole SQL query not utilizing prepared statements, which presents a potential SQL injection risk. Additionally, while a large percentage of outputs are escaped, the 46% that are not could still lead to cross-site scripting (XSS) vulnerabilities in specific scenarios. The absence of nonce and capability checks also warrants attention, as these are fundamental security controls that, when missing, can expose functionalities to unauthorized access or manipulation, especially if new entry points were to be introduced.

Key Concerns

  • SQL query without prepared statement
  • Significant unescaped output (46%)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

myCred – MemberPress Integration (Gamification for Membership Sites) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

myCred – MemberPress Integration (Gamification for Membership Sites) Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
50
58 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

54% escaped108 total outputs
Attack Surface

myCred – MemberPress Integration (Gamification for Membership Sites) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionmepr-event-transaction-completedincludes\mycred-memberpress-product.php:51
filtermycred_memberpress_hook_limitsincludes\mycred-memberpress-product.php:308
actionadmin_noticesmycred-memberpress.php:75
actionadmin_enqueue_scriptsmycred-memberpress.php:110
filtermycred_setup_hooksmycred-memberpress.php:111
actionmycred_load_hooksmycred-memberpress.php:112
filtermycred_all_referencesmycred-memberpress.php:113
actionadmin_noticesmycred-memberpress.php:117
actionplugins_loadedmycred-memberpress.php:214
actionmepr-event-non-recurring-transaction-completedmycred-memberpress.php:245
actionmepr-event-recurring-transaction-completedmycred-memberpress.php:246
Maintenance & Trust

myCred – MemberPress Integration (Gamification for Membership Sites) Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 17, 2025
PHP min version7.2
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

myCred – MemberPress Integration (Gamification for Membership Sites) Developer Profile

Saad Iqbal

84 plugins · 1.4M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
287 days
View full developer profile
Detection Fingerprints

How We Detect myCred – MemberPress Integration (Gamification for Membership Sites)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mycred-memberpress/assets/css/style.css/wp-content/plugins/mycred-memberpress/assets/js/script.js
Script Paths
/wp-content/plugins/mycred-memberpress/assets/js/script.js
Version Parameters
mycred-memberpress/assets/css/style.css?ver=mycred-memberpress/assets/js/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about myCred – MemberPress Integration (Gamification for Membership Sites)