
BitMate Author Donations Security & Risk Analysis
wordpress.org/plugins/bitmate-author-donationsBitMate Author Donations is a WordPress plugin for authors on WordPress powered sites to accept cryptocurrency donations.
Is BitMate Author Donations Safe to Use in 2026?
Generally Safe
Score 85/100BitMate Author Donations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bitmate-author-donations plugin v2.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and avoids external HTTP requests. The absence of known CVEs and bundled libraries is also a strong indicator of a secure past and present. However, significant concerns arise from the static analysis. The presence of an unprotected AJAX handler represents a critical entry point that could be exploited if it performs sensitive operations or exposes data without proper authentication. Furthermore, the low percentage of properly escaped output (40%) suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site. The taint analysis, while showing no critical or high severity flows, did reveal two flows with unsanitized paths, which warrants further investigation to understand the potential impact.
Key Concerns
- Unprotected AJAX handler
- Low output escaping percentage
- Unsanitized paths in taint flows
- No nonce checks on AJAX
BitMate Author Donations Security Vulnerabilities
BitMate Author Donations Code Analysis
Output Escaping
Data Flow Analysis
BitMate Author Donations Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 13
Maintenance & Trust
BitMate Author Donations Maintenance & Trust
Maintenance Signals
Community Trust
BitMate Author Donations Alternatives
Cryptocurrency Widgets For Elementor
cryptocurrency-widgets-for-elementor
Easily display cryptocurrency prices and generate customizable widgets for 250+ coins, including Bitcoin, Ethereum, and more in Elementor.
Cryptothanks
cryptothanks
This is the plugin where your visitors make payment to you. You can change the label of the button to make it either donation or payment button.
BTCPay for GiveWP
btcpay-for-givewp
A BTCPay Server Bitcoin / Lightning Network (and other cryptocurrencies) payment gateway for GiveWP.
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
BitMate Author Donations Developer Profile
2 plugins · 70 total installs
How We Detect BitMate Author Donations
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bitmate-author-donations/style.css/wp-content/plugins/bitmate-author-donations/css/cryptofont.min.css/wp-content/plugins/bitmate-author-donations/js/bm-admin.js/wp-content/plugins/bitmate-author-donations/includes/qrme.php/wp-content/plugins/bitmate-author-donations/js/bm-admin.jsbitmate-author-donations/style.css?ver=bitmate-author-donations/css/cryptofont.min.css?ver=bitmate-author-donations/js/bm-admin.js?ver=HTML / DOM Fingerprints
bitmate-author-creditbm-cc-btcbm-cc-btc-altbm-cc-ethbm-cc-ltcbm-cc-xmrbm-cc-zecbm-qr-code+3 moreid="bitmate-author-donation"id="bm-cc-btc"class="bm-cc-tabs"id="bm-qr-code"id="bm-window-detail"id="bm-classic"+3 moreplugins_url