
myCred Paid Memberships Pro Security & Risk Analysis
wordpress.org/plugins/mycred-paid-memberships-pro📢🚨Important Notice: myCred Paid Memberships Pro is now part of the myCred Toolkit and will no longer receive updates here.
Is myCred Paid Memberships Pro Safe to Use in 2026?
Generally Safe
Score 92/100myCred Paid Memberships Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mycred-paid-memberships-pro" v1.3.1 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history suggest a mature and well-maintained codebase. The code analysis reveals a good adherence to secure coding practices, with a high percentage of SQL queries using prepared statements and output being properly escaped. The attack surface is minimal, with no exposed AJAX handlers, REST API routes, or shortcodes without authentication or permission checks, which is a significant strength. Furthermore, the absence of file operations and external HTTP requests reduces potential vectors for compromise.
However, there are a few areas that warrant attention. The complete absence of nonce checks across the plugin, while not directly indicating a vulnerability in this specific version due to a lack of exploitable entry points, represents a missed opportunity to implement a fundamental WordPress security measure. This could be a potential weakness if future updates introduce new entry points or if the lack of nonces is a systemic issue. The moderate number of SQL queries (16 total) and the fact that 37% of them do not use prepared statements, while not critical given the current lack of exploitable flows, could pose a risk if data sources become untrusted in the future.
In conclusion, this plugin appears to be relatively secure in its current version. Its strengths lie in its limited attack surface and good output escaping. The primary area for improvement and a minor concern is the lack of nonce checks and the presence of some raw SQL queries, which, while not exploited in this version, represent potential areas of future risk. The vulnerability history is a strong positive indicator.
Key Concerns
- No nonce checks implemented
- SQL queries without prepared statements (37%)
myCred Paid Memberships Pro Security Vulnerabilities
myCred Paid Memberships Pro Release Timeline
myCred Paid Memberships Pro Code Analysis
SQL Query Safety
Output Escaping
myCred Paid Memberships Pro Attack Surface
WordPress Hooks 39
Scheduled Events 2
Maintenance & Trust
myCred Paid Memberships Pro Maintenance & Trust
Maintenance Signals
Community Trust
myCred Paid Memberships Pro Alternatives
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
paid-member-subscriptions
Feature-packed membership plugin for creating subscription plans, adding recurring payments & content restriction on your membership site.
Subscriptions & Memberships for PayPal
subscriptions-memberships-for-paypal
A simple and easy way to sell subscriptions and / or memberships with PayPal. No Coding Required. Official PayPal Partner.
Administrator Access to PMPro Protected Content
administrator-access-to-pmpro-protected-content
Overrides the PMPro "Require Membership" settings and grants view access to any user assigned to the WordPress "Administrator" rol …
IDPay For Paid Memberships Pro
idpay-paid-memberships-pro
After installing and enabling this plugin, your customers can pay through IDPay gateway.
AURPAY Paid Memberships Pro (PMP) – Bitcoin Crypto Payment Gateway
aurpay-crypto-payment-for-paid-memberships-pro
Accept ETH, USDC, USDT, DAI, BTC & Lightning in PMP. Non-custodial, low fees, no card chargebacks.
myCred Paid Memberships Pro Developer Profile
89 plugins · 1.4M total installs
How We Detect myCred Paid Memberships Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_purchase_membership_script.js/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_renew_membership_script.js/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_cancel_membership_script.js/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_expired_membership_script.js/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_point_payment_admin_script.js/wp-content/plugins/mycred-paid-memberships-pro/assets/css/pmp_purchase_membership_style.css/wp-content/plugins/mycred-paid-memberships-pro/assets/css/pmp_renew_membership_style.css/wp-content/plugins/mycred-paid-memberships-pro/assets/css/pmp_cancel_membership_style.css+1 more/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_purchase_membership_script.js/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_renew_membership_script.js/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_cancel_membership_script.js/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_expired_membership_script.js/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_point_payment_admin_script.js/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_purchase_membership_script.js?ver=/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_renew_membership_script.js?ver=/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_cancel_membership_script.js?ver=/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_expired_membership_script.js?ver=/wp-content/plugins/mycred-paid-memberships-pro/assets/js/pmp_point_payment_admin_script.js?ver=/wp-content/plugins/mycred-paid-memberships-pro/assets/css/pmp_purchase_membership_style.css?ver=/wp-content/plugins/mycred-paid-memberships-pro/assets/css/pmp_renew_membership_style.css?ver=/wp-content/plugins/mycred-paid-memberships-pro/assets/css/pmp_cancel_membership_style.css?ver=/wp-content/plugins/mycred-paid-memberships-pro/assets/css/pmp_expired_membership_style.css?ver=HTML / DOM Fingerprints
<!-- myCred Paid Memberships Pro is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be provided. -->