
myCred – Zapier Integration Security & Risk Analysis
wordpress.org/plugins/mycred-zapierBoost myCred with myCred Zapier! Automate rewards & connect to 3000+ apps using custom webhooks. Effortless setup to boost productivity.
Is myCred – Zapier Integration Safe to Use in 2026?
Generally Safe
Score 100/100myCred – Zapier Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mycred-zapier" v1.0.9 plugin presents a significant security risk due to a large attack surface with no authentication or authorization checks on its entry points. All 6 identified REST API routes lack permission callbacks, meaning any authenticated user, regardless of role, could potentially interact with these endpoints. While the code analysis indicates good practices in using prepared statements for SQL queries and a lack of dangerous functions or file operations, the absence of capability checks and nonce verification on these REST API routes is a critical oversight. The vulnerability history shows no past issues, which is positive, but it doesn't mitigate the current high-risk configuration. The plugin's security posture is concerningly weak in its access control mechanisms despite seemingly solid internal coding practices. The lack of output escaping on over half of the identified outputs also introduces a risk of cross-site scripting (XSS) vulnerabilities.
Key Concerns
- REST API routes without permission callbacks
- Unprotected AJAX handlers (0 without auth checks)
- Unescaped output detected
- No nonce checks
- No capability checks
myCred – Zapier Integration Security Vulnerabilities
myCred – Zapier Integration Code Analysis
SQL Query Safety
Output Escaping
myCred – Zapier Integration Attack Surface
REST API Routes 6
WordPress Hooks 10
Scheduled Events 1
Maintenance & Trust
myCred – Zapier Integration Maintenance & Trust
Maintenance Signals
Community Trust
myCred – Zapier Integration Alternatives
Zapier for WordPress
zapier
Zapier saves you time on tedious tasks by moving info between WordPress and your other favorite apps, so you can focus on your most important work.
Bit integrations – Easy Automator with no-code automation, integrate Webhook and automate 300+ Platform
bit-integrations
Perfect Automation and integration plugin: Connect 300+ platforms and automate CRM, Email marketing tools, Google Sheets, Contact forms, LMS and more
Hookly – Webhook Automator
hookly-webhook-automator
Connect WordPress events to external services via webhooks. A lightweight, developer-friendly automation tool.
CF7 to Webhook
cf7-to-zapier
Use Contact Form 7 as a trigger to any webhook!
WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress
wp-webhooks
Automate everything & connect your website, plugins and services together with no-code automations. Browse 100+ integrations...
myCred – Zapier Integration Developer Profile
84 plugins · 1.4M total installs
How We Detect myCred – Zapier Integration
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycred-zapier/assets/js/zapier-settings-scripts.js/wp-content/plugins/mycred-zapier/assets/js/zapier-settings-scripts.jsmycred-zapier/assets/js/zapier-settings-scripts.js?ver=HTML / DOM Fingerprints
mycred-zapier-form-controldata-nonceMYCRED_ZAPIER/wp-json/mycredzapier/v1/hook