
Civist – Petitions and Fundraising Security & Risk Analysis
wordpress.org/plugins/civistWith Civist you create petitions directly in WordPress, raise funds and build strong supporter networks.
Is Civist – Petitions and Fundraising Safe to Use in 2026?
Generally Safe
Score 100/100Civist – Petitions and Fundraising has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "civist" plugin version 7.9.0 presents a strong security posture based on the static analysis and vulnerability history provided. The plugin exhibits good security practices by having zero AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting its attack surface. Furthermore, the absence of dangerous functions and file operations is a positive indicator. The code signals show a single SQL query, which is concerning due to the 0% usage of prepared statements, indicating a potential for SQL injection if that query processes user-supplied input. While the output escaping is reasonably high at 79%, the remaining unescaped outputs could still pose a risk, depending on the nature of the data being outputted. The presence of a nonce check and capability checks is positive, demonstrating an awareness of basic WordPress security mechanisms.
The vulnerability history for "civist" is exceptionally clean, with no recorded CVEs of any severity. This suggests a history of well-maintained code and a lack of exploitable vulnerabilities discovered to date. The complete absence of critical or high-severity vulnerabilities in its history, combined with the limited attack surface and generally good code signals (aside from the SQL query and unescaped output percentage), points to a plugin that is likely robust and secure. The plugin's strengths lie in its minimal attack surface and lack of historical vulnerabilities. Its primary weakness, derived from the static analysis, is the single SQL query that does not use prepared statements, which warrants further investigation into its context and potential for exploitation. The unescaped output percentage, while not critically high, also represents a minor area of concern.
Key Concerns
- SQL query without prepared statements
- Percentage of unescaped outputs
Civist – Petitions and Fundraising Security Vulnerabilities
Civist – Petitions and Fundraising Release Timeline
Civist – Petitions and Fundraising Code Analysis
SQL Query Safety
Output Escaping
Civist – Petitions and Fundraising Attack Surface
WordPress Hooks 16
Maintenance & Trust
Civist – Petitions and Fundraising Maintenance & Trust
Maintenance Signals
Community Trust
Civist – Petitions and Fundraising Alternatives
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
charitable
The best WordPress donation plugin. Create fundraising donation forms, accept recurring donations, easy donor management, add crowdfunding, and more.
Donorbox – Free Recurring Donation Plugin and Fundraising Platform
donorbox-donation-form
Donorbox is a powerful and secure donation management plugin for WordPress. We are the only donation plugin for WordPress that offers a fast feature-f …
GiveWP Donation Widgets for Elementor
givewp-donation-widgets-for-elementor
A GiveWP add-on which allows you to embed any GiveWP shortcode into your Elementor-powered pages.
Donation Platform for WooCommerce: Fundraising & Donation Management
wc-donation-platform
Open source donation system for your fundraising that supports recurring donations and more
Civist – Petitions and Fundraising Developer Profile
1 plugin · 1K total installs
How We Detect Civist – Petitions and Fundraising
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/civist/civist2017.css/wp-content/plugins/civist/registration.js/wp-content/plugins/civist/plugins.js/wp-content/plugins/civist/manager.js/wp-content/plugins/civist/settings.js/wp-content/plugins/civist/editor.js/wp-content/plugins/civist/civist.css/wp-content/plugins/civist/civist2017.css/wp-content/plugins/civist/registration.js/wp-content/plugins/civist/plugins.js/wp-content/plugins/civist/manager.js/wp-content/plugins/civist/settings.js/wp-content/plugins/civist/editor.js+1 morecivist2017.css?ver=registration.js?ver=plugins.js?ver=manager.js?ver=settings.js?ver=editor.js?ver=civist.css?ver=HTML / DOM Fingerprints
civist-registration-appcivist