
Buy Me a Coffee button & widgets – Fundraise with Stripe and PayPal Security & Risk Analysis
wordpress.org/plugins/buy-me-coffeeEasy way to collect donations like "buy me a coffee" directly your own Stripe and PayPal for free.
Is Buy Me a Coffee button & widgets – Fundraise with Stripe and PayPal Safe to Use in 2026?
Generally Safe
Score 100/100Buy Me a Coffee button & widgets – Fundraise with Stripe and PayPal has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "buy-me-coffee" v1.0.6 plugin exhibits a generally strong security posture, characterized by the diligent use of prepared statements for SQL queries and a high percentage of properly escaped outputs. The absence of any recorded vulnerabilities in its history further suggests a commitment to security. However, the presence of two unprotected AJAX handlers represents a notable weakness in its attack surface. While the taint analysis did not reveal critical or high severity issues, a flow with unsanitized paths, though not explicitly classified as critical, warrants attention as it could potentially lead to unintended behavior or data exposure if exploited.
The plugin's strength lies in its adherence to fundamental security practices like prepared SQL statements and output escaping. This indicates a developer with a good understanding of common web application vulnerabilities. The clean vulnerability history is a significant positive, implying stability and a lack of previously exploited weaknesses. The primary concern stems from the attack surface analysis, specifically the unprotected AJAX endpoints. These can serve as entry points for attackers, and without proper authorization or nonce checks, they could be leveraged to perform unintended actions.
In conclusion, "buy-me-coffee" v1.0.6 is a reasonably secure plugin, bolstered by robust SQL handling and output escaping. The lack of historical vulnerabilities is a testament to its quality. The main area for improvement is addressing the unprotected AJAX handlers to fully secure its entry points. While the taint analysis did not flag major issues, the presence of an unsanitized path indicates a need for continued vigilance and code review, even in the absence of critical findings.
Key Concerns
- Unprotected AJAX handlers
- Flow with unsanitized paths
Buy Me a Coffee button & widgets – Fundraise with Stripe and PayPal Security Vulnerabilities
Buy Me a Coffee button & widgets – Fundraise with Stripe and PayPal Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Buy Me a Coffee button & widgets – Fundraise with Stripe and PayPal Attack Surface
AJAX Handlers 3
Shortcodes 3
WordPress Hooks 19
Maintenance & Trust
Buy Me a Coffee button & widgets – Fundraise with Stripe and PayPal Maintenance & Trust
Maintenance Signals
Community Trust
Buy Me a Coffee button & widgets – Fundraise with Stripe and PayPal Alternatives
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions
wp-full-stripe-free
🚀 Create Stripe payment forms for WordPress. Accept credit cards, Apple Pay, donations, subscriptions & more. Easy setup, no coding needed!
Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More
better-payment
Better Payment allows you to automate payment transactions to manage payments, donations, subscriptions, sell products, etc on your Elementor website.
Crowded Collect — Dues & Fundraising
crowded-collect-dues-fundraising
Embed your Crowded collection directly into your WordPress site with no coding required!
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
Accept Stripe Payments
stripe-payments
Easily accept payments on your WordPress site via Stripe payment gateway.
Buy Me a Coffee button & widgets – Fundraise with Stripe and PayPal Developer Profile
1 plugin · 50 total installs
How We Detect Buy Me a Coffee button & widgets – Fundraise with Stripe and PayPal
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buy-me-coffee/js/BmcPublic.jsjs/BmcPublic.jsbuy-me-coffee/buy-me-coffee.phpHTML / DOM Fingerprints
data-noncebuymecoffee[buymecoffee_button][buymecoffee_form][buymecoffee_basic]