Braintree Donations Security & Risk Analysis

wordpress.org/plugins/braintree-donations

The Braintree Donations plugin allows websites to accept one time or recurring donations using Braintree payment Gateway.

10 active installs v1.0 PHP + WP 2.8+ Updated Jun 23, 2014
braintreedonationpayment-gatewaypayments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Braintree Donations Safe to Use in 2026?

Generally Safe

Score 85/100

Braintree Donations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The braintree-donations plugin version 1.0 exhibits a generally good security posture due to its minimal attack surface and adherence to some security best practices. The plugin has a single entry point via a shortcode and no recorded vulnerabilities in its history, which are positive indicators. However, a significant concern arises from the static analysis, specifically the complete lack of proper output escaping. With 13 total outputs and 0% properly escaped, this presents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface.

Key Concerns

  • All outputs are unescaped, indicating XSS risk.
Vulnerabilities
None known

Braintree Donations Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Braintree Donations Release Timeline

v1.0Current
Code Analysis
Analyzed Mar 17, 2026

Braintree Donations Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped13 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<settings> (settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Braintree Donations Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[BrainTree] braintreedonations.php:75
WordPress Hooks 3
actionwp_enqueue_scriptsbraintreedonations.php:37
actionadmin_enqueue_scriptsbraintreedonations.php:45
actionadmin_menubraintreedonations.php:49
Maintenance & Trust

Braintree Donations Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJun 23, 2014
PHP min version
Downloads2K

Community Trust

Rating20/100
Number of ratings3
Active installs10
Developer Profile

Braintree Donations Developer Profile

FasterThemes

3 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Braintree Donations

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/braintree-donations/css/bootstrap.css/wp-content/plugins/braintree-donations/css/mycustomestyle.css

HTML / DOM Fingerprints

Shortcode Output
BrainTree
FAQ

Frequently Asked Questions about Braintree Donations