
CharityGlow — Donations & Fundraising Security & Risk Analysis
wordpress.org/plugins/charityglowAccept donations via Stripe, PayPal, SSLCommerz (bKash, Nagad, Rocket) & Bank Transfer with high-converting forms, recurring donations, and built- …
Is CharityGlow — Donations & Fundraising Safe to Use in 2026?
Generally Safe
Score 100/100CharityGlow — Donations & Fundraising has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "charityglow" v1.1.0 plugin demonstrates a generally strong security posture with excellent output escaping and a high percentage of prepared SQL statements. The plugin also shows a good number of nonce and capability checks, indicating developers are aware of common WordPress security practices. However, there are significant concerns stemming from the static analysis. The presence of unprotected AJAX handlers is a major red flag, as these can be entry points for attackers. Additionally, the high number of flows with unsanitized paths, specifically 11 classified as high severity in the taint analysis, points to potential vulnerabilities related to how user input is handled, even if no critical severities were found. The lack of any recorded vulnerability history is positive but doesn't negate the immediate risks identified in the code analysis. While the plugin's adherence to many best practices is commendable, the identified unprotected entry points and high-severity taint flows warrant careful attention and remediation.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows (unsanitized paths)
- Use of dangerous function preg_replace(/e)
CharityGlow — Donations & Fundraising Security Vulnerabilities
CharityGlow — Donations & Fundraising Release Timeline
CharityGlow — Donations & Fundraising Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CharityGlow — Donations & Fundraising Attack Surface
AJAX Handlers 22
Shortcodes 14
WordPress Hooks 23
Maintenance & Trust
CharityGlow — Donations & Fundraising Maintenance & Trust
Maintenance Signals
Community Trust
CharityGlow — Donations & Fundraising Alternatives
Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More
better-payment
Better Payment allows you to automate payment transactions to manage payments, donations, subscriptions, sell products, etc on your Elementor website.
FundCollector – Donations Plugin and Fundraising Platform for WordPress
fundcollector
Easily receive donations on your website. Accept payments made with PayPal. For bank transfers, it automatically sends payment instructions via email.
Accept Donations with PayPal & Stripe
easy-paypal-donation
Add a PayPal or Stripe Donation Button to your website and start collecting donations today. No Coding Required. Official PayPal & Stripe Partner.
Donation Platform for WooCommerce: Fundraising & Donation Management
wc-donation-platform
Open source donation system for your fundraising that supports recurring donations and more
Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management
wp-payment-form
Create payment form, donate button to accept payments and donations. Manage subscription payment, recurring donation with customer/donor management.
CharityGlow — Donations & Fundraising Developer Profile
4 plugins · 50 total installs
How We Detect CharityGlow — Donations & Fundraising
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/charityglow/assets/css/frontend.css/wp-content/plugins/charityglow/assets/js/frontend.js/wp-content/plugins/charityglow/assets/js/frontend.jscharityglow/assets/css/frontend.css?ver=charityglow/assets/js/frontend.js?ver=HTML / DOM Fingerprints
charityglowData