myCred Retro Security & Risk Analysis

wordpress.org/plugins/mycred-retro

๐Ÿ“ข๐Ÿšจ Important Notice: myCred Retro is now part of the myCred Toolkit and will no longer receive updates here. Only security fixes will be provided.

10 active installs v1.2.9 PHP 7.0+ WP 4.8+ Updated Apr 17, 2025
loyaltymycredpointsretroactivereward
100
A ยท Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is myCred Retro Safe to Use in 2026?

Generally Safe

Score 100/100

myCred Retro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The plugin "mycred-retro" v1.2.9 exhibits a strong security posture based on the provided static analysis. There is no evidence of a significant attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events, indicating a well-contained plugin. Furthermore, the code signals suggest good development practices, as there are no dangerous functions, file operations, or external HTTP requests. The high percentage of prepared statements for SQL queries and proper output escaping are positive indicators of secure coding. The absence of any recorded vulnerabilities or CVEs in its history also contributes to a favorable security assessment.

Key Concerns

  • No capability checks found
  • Low number of nonce checks relative to SQL queries
Vulnerabilities
None known

myCred Retro Security Vulnerabilities

No known vulnerabilities โ€” this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

myCred Retro Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
8 prepared
Unescaped Output
5
72 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

53% prepared15 total queries

Output Escaping

94% escaped77 total outputs
Data Flows
All sanitized

Data Flow Analysis

6 flows
ajax_handler (importers\retro-comments.php:453)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

myCred Retro Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_noticesmycred-retro.php:101
actionmycred_pre_initmycred-retro.php:111
actionmycred_initmycred-retro.php:112
actionmycred_admin_initmycred-retro.php:113
actionmycred_retro_register_importermycred-retro.php:195
Maintenance & Trust

myCred Retro Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 17, 2025
PHP min version7.0
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

myCred Retro Developer Profile

Saad Iqbal

84 plugins ยท 1.4M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
287 days
View full developer profile
Detection Fingerprints

How We Detect myCred Retro

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mycred-retro/assets/css/admin.css/wp-content/plugins/mycred-retro/assets/js/admin.js
Script Paths
/wp-content/plugins/mycred-retro/assets/js/admin.js
Version Parameters
mycred-retro/assets/css/admin.css?ver=mycred-retro/assets/js/admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<h2>Retroactive Content</h2> <p>This tool allows you give points to users for registering on your website.</p> <p>To prevent to heavy queries, this tool will process <strong>150</strong> users at a time.</p> <p>If you feel your site can handle more in one session, use the <code>MYCRED_RETRO_MAX</code> constant to change the threshold, by defining it in your wp-config.php file.</p><h2>Not Excluded</h2><p>Only users tha
FAQ

Frequently Asked Questions about myCred Retro