
Cryptocurrency Donation Box – Bitcoin & Crypto Donations Security & Risk Analysis
wordpress.org/plugins/cryptocurrency-donation-boxAccept crypto payments and donations on your WordPress site easily with this free cryptocurrency donation box plugin
Is Cryptocurrency Donation Box – Bitcoin & Crypto Donations Safe to Use in 2026?
Generally Safe
Score 91/100Cryptocurrency Donation Box – Bitcoin & Crypto Donations has a strong security track record. Known vulnerabilities have been patched promptly.
The cryptocurrency-donation-box plugin exhibits a mixed security posture. While it shows strengths in its handling of dangerous functions and file operations, and a notable absence of critical or high severity taint flows, several concerns warrant attention. A significant number of AJAX handlers (5 out of 12) lack authentication checks, creating potential entry points for unauthorized actions. Furthermore, the presence of a past high severity SQL Injection vulnerability, even though currently patched, indicates a potential area for future risk if not diligently maintained. The vulnerability history, with a past high severity SQLi, suggests that input sanitization and database query security are areas that have required attention in the past and may require ongoing vigilance.
Despite the good percentage of properly escaped output and a respectable number of nonce and capability checks, the unprotected AJAX endpoints represent a clear attack vector. The static analysis doesn't reveal any immediate critical vulnerabilities in the current version, but the past SQLi and the unprotected AJAX handlers are significant weaknesses. The plugin's overall security is moderate, with potential for improvement in securing its AJAX endpoints and ensuring continued robust database query protection, even though no current high-risk issues are evident in the static analysis.
Key Concerns
- Unprotected AJAX handlers
- Past high severity SQLi vulnerability
- 50% of SQL queries not using prepared statements
- 28% of outputs not properly escaped
Cryptocurrency Donation Box – Bitcoin & Crypto Donations Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Cryptocurrency Donation Box – Bitcoin & Crypto Donations <= 2.2.7 - Authenticated (Administrator+) SQL Injection
Cryptocurrency Donation Box – Bitcoin & Crypto Donations Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Cryptocurrency Donation Box – Bitcoin & Crypto Donations Attack Surface
AJAX Handlers 12
Shortcodes 1
WordPress Hooks 83
Maintenance & Trust
Cryptocurrency Donation Box – Bitcoin & Crypto Donations Maintenance & Trust
Maintenance Signals
Community Trust
Cryptocurrency Donation Box – Bitcoin & Crypto Donations Alternatives
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
Cryptocurrency Widgets For Elementor
cryptocurrency-widgets-for-elementor
Easily display cryptocurrency prices and generate customizable widgets for 250+ coins, including Bitcoin, Ethereum, and more in Elementor.
Crypto Price Widgets – CryptoWP
cryptowp
A lightweight plugin to show the latest Bitcoin, Ethereum, and other cryptocurrency widgets on your website.
Cryptocurrency Payment Gateway
cryptocurrency-payment-gateway
Digital Currency Payment Gateway for WooCommerce. Easily accept Bitcoin, Bitcoin Cash, Litecoin, Dogecoin, and more in your store.
EthPress – Web3 Login
ethpress
EthPress Web3 Login Wordpress Plugin adds the capability to connect with cryptocurrency wallets such as MetaMask or WalletConnect QR code.
Cryptocurrency Donation Box – Bitcoin & Crypto Donations Developer Profile
1 plugin · 600 total installs
How We Detect Cryptocurrency Donation Box – Bitcoin & Crypto Donations
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cryptocurrency-donation-box/assets/css/cdbbc-admin.css/wp-content/plugins/cryptocurrency-donation-box/assets/js/cdbbc-replace.js/wp-content/plugins/cryptocurrency-donation-box/includes/php-jwt/include-jwt.php/wp-content/plugins/cryptocurrency-donation-box/includes/Api.php/wp-content/plugins/cryptocurrency-donation-box/includes/cdbbc-payment-verify.php/wp-content/plugins/cryptocurrency-donation-box/admin/table/cdbbc-transaction-table.php/wp-content/plugins/cryptocurrency-donation-box/admin/table/cdbbc-list-table.php/wp-content/plugins/cryptocurrency-donation-box/admin/codestar-framework/codestar-framework.php+6 morecryptocurrency-donation-box/assets/css/cdbbc-admin.css?ver=cryptocurrency-donation-box/assets/js/cdbbc-replace.js?ver=HTML / DOM Fingerprints
cdbbc-donation-box-wrapcdbbc-walletscdbbc-coinscdbbc-coincdbbc-qr-code-displaycdbbc-payment-dialogcdbbc-close-btncdbbc-modal-content+5 more<!-- cryptocurrency-donation-box start --><!-- cryptocurrency-donation-box end --><!-- The donation box will be shown here --><!-- Donation Box Options -->+3 moredata-cdbbc-coindata-cdbbc-addressdata-cdbbc-amountdata-cdbbc-donation-iddata-cdbbc-plugin-nameCDBBC_PREFIXCDBBC_AJAX_URLCDBBC_NONCE/wp-json/cdbbc-crypto-donations/v1/activate/wp-json/cdbbc-crypto-donations/v1/status[donationbox][donationbox title="" text="" style="" ]