All-in-one WPML Crowdfunding Campaigns Security & Risk Analysis

wordpress.org/plugins/all-in-one-wpml-crowdfunding-campaigns

Unify WPML translation versions of a crowdfunding campaign so that contributions to each language version count towards the main campaign.

10 active installs v1.1.1 PHP + WP 4.2+ Updated Jul 2, 2015
crowd-fundcrowdfundinglanguagemultilingualwpml
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is All-in-one WPML Crowdfunding Campaigns Safe to Use in 2026?

Generally Safe

Score 85/100

All-in-one WPML Crowdfunding Campaigns has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "all-in-one-wpml-crowdfunding-campaigns" plugin v1.1.1 appears to have a strong security posture. The static analysis reveals no identified entry points such as AJAX handlers, REST API routes, or shortcodes that are not protected by authentication or permission checks. Furthermore, the code shows no usage of dangerous functions, all SQL queries are properly prepared, and all outputs are correctly escaped, indicating good development practices in these critical areas. The absence of file operations and external HTTP requests also reduces the potential attack surface.

The plugin also has a clean vulnerability history, with no recorded CVEs of any severity. This, combined with the lack of identified critical or high-severity taint flows, suggests a well-maintained and secure codebase. The absence of bundled libraries is also a positive sign, as it avoids potential vulnerabilities associated with outdated third-party components.

While the lack of nonce checks and capability checks are noted, the overall absence of exposed entry points significantly mitigates the risk associated with these omissions. The plugin's strengths lie in its minimal attack surface and adherence to secure coding practices for database interactions and output handling. The lack of historical vulnerabilities further reinforces a perception of security. However, it is always prudent to maintain vigilance and apply security updates promptly when they become available.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

All-in-one WPML Crowdfunding Campaigns Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

All-in-one WPML Crowdfunding Campaigns Release Timeline

v1.1.1Current
v1.0.2
v1.0.1
Code Analysis
Analyzed Mar 17, 2026

All-in-one WPML Crowdfunding Campaigns Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries
Attack Surface

All-in-one WPML Crowdfunding Campaigns Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filteratcf_campaign_pledged_amount_idcrowdfunding-wpml.class.php:14
actionplugins_loadedcrowdfunding-wpml.php:43
Maintenance & Trust

All-in-one WPML Crowdfunding Campaigns Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJul 2, 2015
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

All-in-one WPML Crowdfunding Campaigns Developer Profile

Eric Daams

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect All-in-one WPML Crowdfunding Campaigns

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

JS Globals
sitepress
FAQ

Frequently Asked Questions about All-in-one WPML Crowdfunding Campaigns