
myCred Rank Plus Security & Risk Analysis
wordpress.org/plugins/mycred-rank-plusmyCred Rank Plus gives you the power to add rank types and set multiple rank requirements including priority and sequential control, and more.
Is myCred Rank Plus Safe to Use in 2026?
Generally Safe
Score 100/100myCred Rank Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mycred-rank-plus plugin version 1.0.5 exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices by utilizing prepared statements for all SQL queries and performing proper output escaping on nearly all outputs. The plugin also incorporates nonce and capability checks for its entry points, which is crucial for preventing unauthorized actions. The absence of dangerous functions, file operations, external HTTP requests, and any taint flows with unsanitized paths further strengthens its security profile. Furthermore, the plugin has no recorded vulnerability history, indicating a history of secure development or a lack of prior exploitation. The limited attack surface, consisting solely of two AJAX handlers with apparent authentication checks, is a significant positive.
While the static analysis reveals no immediate critical or high-severity vulnerabilities, a perfect score is not achievable due to minor areas where absolute perfection isn't demonstrated. The slight deviation from 100% output escaping, though minimal, represents a potential, albeit low, risk. Similarly, the presence of AJAX handlers, even with checks, inherently carries a slightly higher risk than entry points with no direct user interaction. The lack of shortcodes or cron events is a neutral observation in terms of risk, but the absence of REST API routes with permission callbacks is a positive in that regard. Overall, this plugin appears to be well-secured, with a low risk profile, and its development team seems to prioritize security best practices.
Key Concerns
- Minor output escaping inefficiency
myCred Rank Plus Security Vulnerabilities
myCred Rank Plus Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
myCred Rank Plus Attack Surface
AJAX Handlers 2
WordPress Hooks 26
Maintenance & Trust
myCred Rank Plus Maintenance & Trust
Maintenance Signals
Community Trust
myCred Rank Plus Alternatives
Loyalty Suite – Loyalty Program, Gamification, Ranks, Rewards, Points & Wallets
loyalty-suite
Loyalty Suite for WordPress & WooCommerce is published on WordPress.org for general preview with the plugin’s interface and core concepts.
myLoyal – reward, point, gamification and loyalty plugin with easy but smart yet rules
myloyal
Manage points, rewards, gamifications, ranks, badges on user activities on your site
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
gamipress
Boost your gamification marketing & reward your users with points, achievements, badges & ranks to increase your site activity & loyalty!
Points and Rewards for WooCommerce – Create Loyalty Programs, Reward Customer Purchases, User Badges, Gamification
points-and-rewards-for-woocommerce
Points and Rewards for WooCommerce offer a reward for points to your customers for their activities & increase customer loyalty.
myCred Toolkit – Ultimate myCred Modules To Support WordPress Gamification and Loyalty Rewards
mycred-toolkit
A bag of myCred addons for user engagement through WordPress & WooCommerce gamification. Get multiple free add-ons with one point rewards system.
myCred Rank Plus Developer Profile
84 plugins · 1.4M total installs
How We Detect myCred Rank Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycred-rank-plus/includes/mycred-rank-plus-functions.php/wp-content/plugins/mycred-rank-plus/includes/mycred-rank-plus-module.php/wp-content/plugins/mycred-rank-plus/includes/requirements/mycred-rank-plus-requirements.phpwp-content/plugins/mycred-rank-plus/includes/blocks/mycred-rank-earners-block/block.phpmycred-rank-plus/includes/mycred-rank-plus-functions.php?ver=mycred-rank-plus/includes/mycred-rank-plus-module.php?ver=mycred-rank-plus/includes/requirements/mycred-rank-plus-requirements.php?ver=HTML / DOM Fingerprints
wp-block-mycred-rank-blocks-mycred-rank-earners-blockdata-alignmrpAssetsUrl