Redemption For myCred Security & Risk Analysis

wordpress.org/plugins/redemption-for-mycred

A lightweight plugin that lets users redeem myCred points into real money via Bank, UPI, PayPal, Skrill, with admin control and dynamic forms.

0 active installs v1.2.0 PHP 7.4+ WP 5.6+ Updated Aug 4, 2025
bankmycredredeemupiwithdrawal
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Redemption For myCred Safe to Use in 2026?

Generally Safe

Score 100/100

Redemption For myCred has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "redemption-for-mycred" plugin version 1.2.0 demonstrates a generally good security posture, with a strong adherence to secure coding practices. The plugin heavily utilizes prepared statements for its SQL queries and properly escapes most of its output, indicating a proactive approach to preventing common web vulnerabilities. The absence of known CVEs and critical or high-severity taint flows is also a positive indicator. However, there are specific areas that warrant attention. The presence of two AJAX handlers without authentication checks represents a potential entry point for unauthorized actions if these handlers are exploitable. While the total attack surface is not excessively large, these unprotected endpoints are a notable concern.

Key Concerns

  • AJAX handlers without authentication checks
Vulnerabilities
None known

Redemption For myCred Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Redemption For myCred Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
51 prepared
Unescaped Output
31
323 escaped
Nonce Checks
17
Capability Checks
16
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

91% prepared56 total queries

Output Escaping

91% escaped354 total outputs
Data Flows
All sanitized

Data Flow Analysis

10 flows
mycred_redemption_handle_admin_action (admin\admin-ajax.php:13)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Redemption For myCred Attack Surface

Entry Points11
Unprotected2

AJAX Handlers 5

authwp_ajax_mycred_redemption_admin_actionadmin\admin-ajax.php:11
authwp_ajax_mycred_redemption_view_method_dataadmin\admin-ajax.php:137
authwp_ajax_mycred_redemption_dismiss_noticeincludes\notices.php:82
authwp_ajax_mycred_get_point_type_dataincludes\redemption-form-ajax.php:9
authwp_ajax_mycred_cancel_redemptionincludes\redemption-history-ajax.php:13

Shortcodes 6

[mycred_redemption_method] includes\shortcodes.php:21
[mycred_redemption_form] includes\shortcodes.php:26
[mycred_redemption_history] includes\shortcodes.php:31
[mycred_redemption_method] shortcodes\method.php:131
[mycred_redemption_form] shortcodes\redemption-form.php:152
[mycred_redemption_history] shortcodes\redemption-history.php:194
WordPress Hooks 22
actionadmin_enqueue_scriptsadmin\admin-dashboard.php:11
actionadmin_noticesadmin\admin-dashboard.php:79
actionadmin_initadmin\cron.php:40
filterdisplay_post_statesadmin\hooks.php:14
filteradd_menu_classesadmin\menu.php:25
actionadmin_menuadmin\menu.php:128
actionadmin_enqueue_scriptsadmin\widget.php:11
actionwp_dashboard_setupadmin\widget.php:24
actionwp_enqueue_scriptsincludes\enqueue.php:78
actionadmin_footerincludes\enqueue.php:116
actionadmin_enqueue_scriptsincludes\enqueue.php:120
actionadmin_enqueue_scriptsincludes\enqueue.php:136
actionadmin_enqueue_scriptsincludes\enqueue.php:163
actionwp_footerincludes\form-method.php:59
actioninitincludes\form-method.php:64
filtermycred_setup_hooksincludes\functions.php:9
actionadmin_noticesincludes\notices.php:11
actionadmin_enqueue_scriptsincludes\notices.php:52
actioninitincludes\shortcodes.php:34
actionadmin_initredemption-for-mycred.php:23
actionadmin_noticesredemption-for-mycred.php:28
actionplugins_loadedredemption-for-mycred.php:49
Maintenance & Trust

Redemption For myCred Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 4, 2025
PHP min version7.4
Downloads272

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Redemption For myCred Developer Profile

SAUBHIK DAS

2 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Redemption For myCred

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/redemption-for-mycred/assets/css/dboard.css/wp-content/plugins/redemption-for-mycred/assets/js/dashboard.js
Script Paths
/wp-content/plugins/redemption-for-mycred/assets/js/dashboard.js
Version Parameters
redemption-for-mycred/assets/css/dboard.css?ver=redemption-for-mycred/assets/js/dashboard.js?ver=

HTML / DOM Fingerprints

CSS Classes
mycred-redemption-dashboard-table
Data Attributes
data-nonce="mycred_redemption_admin_nonce"
JS Globals
MyCredRedemptionAdmin
FAQ

Frequently Asked Questions about Redemption For myCred