
CustomDonations – Donation, Membership, and Fundraising Forms with Stripe, PayPal and DAF Pay Security & Risk Analysis
wordpress.org/plugins/customdonationsBest WordPress plugin for highly customizable and secure online giving forms. Drag & Drop form builder. No Coding. Official PayPal & Stripe Partner.
Is CustomDonations – Donation, Membership, and Fundraising Forms with Stripe, PayPal and DAF Pay Safe to Use in 2026?
Generally Safe
Score 100/100CustomDonations – Donation, Membership, and Fundraising Forms with Stripe, PayPal and DAF Pay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The customdonations plugin version 1.3.1 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and any SQL queries not using prepared statements are excellent indicators of secure coding practices. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of stability and security.
However, there are a few areas that warrant attention. The presence of two shortcodes, while not inherently insecure, represent potential entry points that could be exploited if not properly secured. The lack of nonce checks on these shortcodes is a concern, as it could open the door to Cross-Site Request Forgery (CSRF) attacks. While capability checks are present, the effectiveness of these checks in preventing unauthorized access is not fully clear without further context. The relatively high percentage of unescaped output, although not critical, could lead to Cross-Site Scripting (XSS) vulnerabilities if sensitive data is displayed without proper sanitization.
In conclusion, customdonations v1.3.1 demonstrates several strengths in its code and vulnerability history. The primary weaknesses lie in the potential for CSRF due to missing nonce checks on shortcodes and the possibility of XSS from unescaped output. Addressing these specific areas would further enhance the plugin's security.
Key Concerns
- Missing nonce checks on shortcodes
- Significant unescaped output percentage
CustomDonations – Donation, Membership, and Fundraising Forms with Stripe, PayPal and DAF Pay Security Vulnerabilities
CustomDonations – Donation, Membership, and Fundraising Forms with Stripe, PayPal and DAF Pay Code Analysis
Output Escaping
CustomDonations – Donation, Membership, and Fundraising Forms with Stripe, PayPal and DAF Pay Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
CustomDonations – Donation, Membership, and Fundraising Forms with Stripe, PayPal and DAF Pay Maintenance & Trust
Maintenance Signals
Community Trust
CustomDonations – Donation, Membership, and Fundraising Forms with Stripe, PayPal and DAF Pay Alternatives
Church Tithe WP
churchtithewp
Smoothly, easily, and quickly accepting online tithes and donations is an important thing for every church today. Church Tithe WP makes it simple for …
Custom Donations
custom-donations
This plugin allows sites to accept user-entered custom donation amounts through Paypal, including recurring donations. This plugin was created in res …
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
Donations via PayPal
paypal-donations
Easy, simple setup to add a PayPal Donation button as a Widget or with a shortcode.
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
charitable
The best WordPress donation plugin. Create fundraising donation forms, accept recurring donations, easy donor management, add crowdfunding, and more.
CustomDonations – Donation, Membership, and Fundraising Forms with Stripe, PayPal and DAF Pay Developer Profile
1 plugin · 100 total installs
How We Detect CustomDonations – Donation, Membership, and Fundraising Forms with Stripe, PayPal and DAF Pay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/customdonations/js/customdonations-admin.js/wp-content/plugins/customdonations/css/customdonations-admin.css/wp-content/plugins/customdonations/js/customdonations-admin.jscustomdonations/js/customdonations-admin.js?ver=customdonations/css/customdonations-admin.css?ver=HTML / DOM Fingerprints
customdonations_memberid_enabled_rowcustomdonations_memberid_field_rowcustomdonations_account_rowcustomdonations_custom_data