Crowdfunding and Fundraising Campaign Builder for PayForm Security & Risk Analysis

wordpress.org/plugins/crowdfunding-and-fundraising-campaign-builder-by-payform

Add a crowdfunding campaign to any Wordpress website in seconds, connected to Stripe or PayPal, using Crowdfunding for PayForm

40 active installs v2.0 PHP + WP 3.0.1+ Updated Aug 31, 2018
membershippaymentsrecurring-paymentsstripestripe-checkout
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Crowdfunding and Fundraising Campaign Builder for PayForm Safe to Use in 2026?

Generally Safe

Score 85/100

Crowdfunding and Fundraising Campaign Builder for PayForm has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The static analysis of the "crowdfunding-and-fundraising-campaign-builder-by-payform" plugin v2.0 reveals a seemingly secure codebase on the surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that constitute an attack surface. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests, coupled with the exclusive use of prepared statements for SQL queries, are strong indicators of good security practices. The plugin also demonstrates some level of security awareness with a capability check present.

However, there are significant concerns raised by the analysis. The complete lack of output escaping is a major vulnerability, as it indicates that any data outputted by the plugin is potentially susceptible to Cross-Site Scripting (XSS) attacks. This is further compounded by the absence of any nonce checks, leaving entry points (though none were identified in this analysis, this could change with future updates or configurations) vulnerable to CSRF attacks. The taint analysis showing zero flows, while positive, could be due to the limited scope of the analysis or the absence of dynamic interactions that would trigger such flows. The vulnerability history shows no prior issues, which is positive, but it doesn't negate the immediate risks identified in the code. In conclusion, while the plugin has a clean history and avoids common pitfalls like raw SQL, the critical oversight in output escaping and the lack of nonce checks present a substantial risk of XSS and potentially CSRF vulnerabilities.

Key Concerns

  • No output escaping
  • No nonce checks
Vulnerabilities
None known

Crowdfunding and Fundraising Campaign Builder for PayForm Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Crowdfunding and Fundraising Campaign Builder for PayForm Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Crowdfunding and Fundraising Campaign Builder for PayForm Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initpayform.php:16
actionadmin_noticespayform.php:23
actiondeactivated_pluginpayform.php:52
Maintenance & Trust

Crowdfunding and Fundraising Campaign Builder for PayForm Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedAug 31, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Crowdfunding and Fundraising Campaign Builder for PayForm Developer Profile

payform

2 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Crowdfunding and Fundraising Campaign Builder for PayForm

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Crowdfunding and Fundraising Campaign Builder for PayForm