
Click & Pledge CONNECT Security & Risk Analysis
wordpress.org/plugins/click-pledge-connect
Is Click & Pledge CONNECT Safe to Use in 2026?
Generally Safe
Score 93/100Click & Pledge CONNECT has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin 'click-pledge-connect' v25.09000000-WP6.8.2 exhibits a mixed security posture. On the positive side, the static analysis indicates a strong adherence to secure coding practices, with 100% of AJAX handlers and REST API routes protected by authentication checks. The vast majority of SQL queries (99%) utilize prepared statements, and a significant portion of outputs (83%) are properly escaped, which are excellent indicators. However, there are several areas of concern. The taint analysis reveals 4 flows with unsanitized paths, including 2 of high severity, suggesting potential vulnerabilities where user input might not be adequately validated before being used in sensitive operations. Additionally, the presence of 2 file operations and the bundling of a library (DataTables) could introduce risks if not managed carefully or if the library is outdated. The vulnerability history is particularly concerning, with 2 previously discovered CVEs, one critical and one high, both related to SQL injection. While the current version shows no unpatched CVEs, the historical pattern of SQL injection vulnerabilities, especially critical ones, indicates a recurring weakness in how user input is handled. The last vulnerability being in July 2025 is also a recent occurrence. Overall, while the plugin implements many good security practices, the identified taint flows and historical vulnerability patterns necessitate careful review and ongoing vigilance to mitigate potential risks.
Key Concerns
- High severity unsanitized taint flows
- Unsanitized taint flows
- Historical critical SQL injection CVE
- Historical high SQL injection CVE
- Bundled library
- File operations present
Click & Pledge CONNECT Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Click & Pledge Connect <= 25.04010101-WP6.8 - Unauthenticated SQL Injection to Privilege Escalation
Click & Pledge Connect Plugin <= 2.24080000-WP6.6.1 - Unauthenticated SQL Injection
Click & Pledge CONNECT Release Timeline
Click & Pledge CONNECT Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Click & Pledge CONNECT Attack Surface
AJAX Handlers 18
Shortcodes 3
WordPress Hooks 14
Maintenance & Trust
Click & Pledge CONNECT Maintenance & Trust
Maintenance Signals
Community Trust
Click & Pledge CONNECT Alternatives
Donorbox – Free Recurring Donation Plugin and Fundraising Platform
donorbox-donation-form
Donorbox is a powerful and secure donation management plugin for WordPress. We are the only donation plugin for WordPress that offers a fast feature-f …
Zeffy Donate Button
zeffy-donate-button
Embed Zeffy donation forms on your WordPress site with customizable popup buttons. Simple setup with no coding required.
FundPress – WordPress Donation Plugin
fundpress
Easily build your own crowdfunding platform like Kickstarter with this free WordPress donation plugin in just a few clicks. No coding required.
Funraise Giving Form
funraise-donation-form
Use Funraise to add donation forms to your website with a shortcode. Manage donations and donors in Funraise's free platform.
Mightycause Donation Forms and Embeds
mightycause-widgets
Easily embed Mightycause donation buttons, widgets, or forms on your WordPress website with no coding required.
Click & Pledge CONNECT Developer Profile
5 plugins · 200 total installs
How We Detect Click & Pledge CONNECT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/click-pledge-connect/css/cnp_connect.css/wp-content/plugins/click-pledge-connect/js/cnp_connect.js/wp-content/plugins/click-pledge-connect/js/cp_donate.js/wp-content/plugins/click-pledge-connect/js/cnp_connect.js/wp-content/plugins/click-pledge-connect/js/cp_donate.jsclick-pledge-connect/css/cnp_connect.css?ver=click-pledge-connect/js/cnp_connect.js?ver=click-pledge-connect/js/cp_donate.js?ver=HTML / DOM Fingerprints
cnp-form-containerdata-cnp-campaign-idcnp_donate_obj[cp_connect_form]