
Crowdfunding Login Form – Make WPCF Login Page Security & Risk Analysis
wordpress.org/plugins/crowdfunding-login-formWP Crowdfunding Login Form. Create a simple login form.
Is Crowdfunding Login Form – Make WPCF Login Page Safe to Use in 2026?
Generally Safe
Score 85/100Crowdfunding Login Form – Make WPCF Login Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "crowdfunding-login-form" v1.0.2 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the lack of file operations or external HTTP requests are all positive indicators. Furthermore, the plugin doesn't appear to have any historical or known critical vulnerabilities. However, there are some areas that warrant attention and introduce potential risks.
The primary concern stems from the complete lack of nonce checks and capability checks. While the attack surface appears minimal with only one shortcode and no AJAX/REST API endpoints exposed without authentication, this absence of security checks means that any functionality exposed via the shortcode could potentially be abused if an attacker can trigger it without proper authorization or validation. The fact that 33% of output is not properly escaped also presents a potential risk for Cross-Site Scripting (XSS) vulnerabilities, especially if the unescaped output involves user-supplied data.
Overall, the plugin's developer seems to be employing good practices regarding SQL and avoiding risky code. The lack of vulnerability history is reassuring. However, the absence of essential security checks like nonces and capability checks, along with the unescaped output, are significant weaknesses that could be exploited. The plugin's security is good but not perfect, and these identified areas should be addressed to further harden its security.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Unescaped output (33%)
Crowdfunding Login Form – Make WPCF Login Page Security Vulnerabilities
Crowdfunding Login Form – Make WPCF Login Page Code Analysis
Output Escaping
Crowdfunding Login Form – Make WPCF Login Page Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Crowdfunding Login Form – Make WPCF Login Page Maintenance & Trust
Maintenance Signals
Community Trust
Crowdfunding Login Form – Make WPCF Login Page Alternatives
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
charitable
The best WordPress donation plugin. Create fundraising donation forms, accept recurring donations, easy donor management, add crowdfunding, and more.
WP Crowdfunding
wp-crowdfunding
WP Crowdfunding is a WordPress plugin for fundraising/backer sites. This WooCommerce based plugin lets you launch a site like Kickstarter easily.
Leyka
leyka
Leyka is a plugin for crowdfunding and donations collection via WordPress website.
FundEngine – Donation and Crowdfunding Platform
wp-fundraising-donation
FundEngine - Fundraising Donation plugin and Crowdfunding Platform comes with Single donation and crowdfunding solution. You can use our plugin Either …
Crowdfunding Login Form – Make WPCF Login Page Developer Profile
7 plugins · 1K total installs
How We Detect Crowdfunding Login Form – Make WPCF Login Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/crowdfunding-login-form/css/cfstyle.csscrowdfunding-login-form/css/cfstyle.css?ver=HTML / DOM Fingerprints
[wp_login_form[wp_login_form redirect=[wp_login_form form_id=[wp_login_form label_username=