Civist – Petitions and Fundraising Security & Risk Analysis

wordpress.org/plugins/civist

With Civist you create petitions directly in WordPress, raise funds and build strong supporter networks.

1K active installs v7.9.0 PHP 7.1+ WP 4.4+ Updated Dec 18, 2025
activismdonationfundraisingpetition
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Civist – Petitions and Fundraising Safe to Use in 2026?

Generally Safe

Score 100/100

Civist – Petitions and Fundraising has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "civist" plugin version 7.9.0 presents a strong security posture based on the static analysis and vulnerability history provided. The plugin exhibits good security practices by having zero AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting its attack surface. Furthermore, the absence of dangerous functions and file operations is a positive indicator. The code signals show a single SQL query, which is concerning due to the 0% usage of prepared statements, indicating a potential for SQL injection if that query processes user-supplied input. While the output escaping is reasonably high at 79%, the remaining unescaped outputs could still pose a risk, depending on the nature of the data being outputted. The presence of a nonce check and capability checks is positive, demonstrating an awareness of basic WordPress security mechanisms.

The vulnerability history for "civist" is exceptionally clean, with no recorded CVEs of any severity. This suggests a history of well-maintained code and a lack of exploitable vulnerabilities discovered to date. The complete absence of critical or high-severity vulnerabilities in its history, combined with the limited attack surface and generally good code signals (aside from the SQL query and unescaped output percentage), points to a plugin that is likely robust and secure. The plugin's strengths lie in its minimal attack surface and lack of historical vulnerabilities. Its primary weakness, derived from the static analysis, is the single SQL query that does not use prepared statements, which warrants further investigation into its context and potential for exploitation. The unescaped output percentage, while not critically high, also represents a minor area of concern.

Key Concerns

  • SQL query without prepared statements
  • Percentage of unescaped outputs
Vulnerabilities
None known

Civist – Petitions and Fundraising Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Civist – Petitions and Fundraising Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Civist – Petitions and Fundraising Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
9
33 escaped
Nonce Checks
1
Capability Checks
5
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

79% escaped42 total outputs
Attack Surface

Civist – Petitions and Fundraising Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_noticesclass-civist-registration.php:32
actionwp_dashboard_setupclass-civist-registration.php:33
actionadmin_initclass-civist.php:188
filterscript_loader_tagclass-civist.php:191
actionadmin_menuclass-civist.php:194
actionadmin_enqueue_scriptsclass-civist.php:195
actionload-plugins.phpclass-civist.php:200
actionload-index.phpclass-civist.php:201
actionmedia_buttonsclass-civist.php:203
filterembed_oembed_htmlclass-civist.php:212
actionplugins_loadedclass-civist.php:220
actioninitclass-civist.php:223
filterhttp_request_host_is_externalclass-civist.php:224
actionplugins_loadedclass-civist.php:228
actioninitclass-civist.php:231
actioninitclass-civist.php:233
Maintenance & Trust

Civist – Petitions and Fundraising Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 18, 2025
PHP min version7.1
Downloads30K

Community Trust

Rating92/100
Number of ratings19
Active installs1K
Developer Profile

Civist – Petitions and Fundraising Developer Profile

Civist

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Civist – Petitions and Fundraising

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/civist/civist2017.css/wp-content/plugins/civist/registration.js/wp-content/plugins/civist/plugins.js/wp-content/plugins/civist/manager.js/wp-content/plugins/civist/settings.js/wp-content/plugins/civist/editor.js/wp-content/plugins/civist/civist.css
Script Paths
/wp-content/plugins/civist/civist2017.css/wp-content/plugins/civist/registration.js/wp-content/plugins/civist/plugins.js/wp-content/plugins/civist/manager.js/wp-content/plugins/civist/settings.js/wp-content/plugins/civist/editor.js+1 more
Version Parameters
civist2017.css?ver=registration.js?ver=plugins.js?ver=manager.js?ver=settings.js?ver=editor.js?ver=civist.css?ver=

HTML / DOM Fingerprints

CSS Classes
civist-registration-app
JS Globals
civist
FAQ

Frequently Asked Questions about Civist – Petitions and Fundraising