
Donate Me Security & Risk Analysis
wordpress.org/plugins/donate-meAdds PayPal Donation with Donate Me. Simple. Easy. Multiple button and colors.
Is Donate Me Safe to Use in 2026?
High Risk
Score 43/100Donate Me carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The "donate-me" plugin version 1.2.5 exhibits a mixed security posture. While it demonstrates strengths in areas like avoiding dangerous functions, employing prepared statements for SQL queries, and not making external HTTP requests, significant concerns emerge from other analysis points. The complete lack of output escaping is a major red flag, directly exposing users to Cross-Site Scripting (XSS) vulnerabilities as indicated by the vulnerability history. Furthermore, the absence of nonce and capability checks on its single shortcode entry point is a critical oversight, potentially allowing unauthorized actions or data manipulation.
The vulnerability history for "donate-me" is particularly worrying, with two medium severity CVEs, both of which are currently unpatched. The historical prevalence of XSS and CSRF vulnerabilities suggests a consistent pattern of input sanitization and authorization weaknesses within the plugin. While the static analysis did not reveal active taint flows in this specific version, the historical context and the identified code signals strongly imply that such issues are recurring and have not been adequately addressed. The plugin's strengths are overshadowed by these critical weaknesses in output sanitization and access control, presenting a significant risk to WordPress sites using this version.
Key Concerns
- Unpatched CVEs (2)
- Output escaping missing
- Nonce checks missing
- Capability checks missing
Donate Me Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Donate Me <= 1.2.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Donate Me <= 1.2.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Donate Me Code Analysis
Output Escaping
Donate Me Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Donate Me Maintenance & Trust
Maintenance Signals
Community Trust
Donate Me Alternatives
Easy Accept Payments via PayPal
wordpress-easy-paypal-payment-or-donation-accept-plugin
Easy to use Wordpress plugin to accept PayPal payments for a service or product or donation in one click
CP Contact Form with PayPal
cp-contact-form-with-paypal
Easily create contact forms with integrated PayPal payments. Accept service payments, orders, and more with a drag-and-drop form builder.
Accept PayPal Payments using Contact Form 7
contact-form-7-paypal-extension
Integrate PayPal Submit button in Contact Form 7 to Enjoy Quick Online Payments.
Donation Block For PayPal
donations-block
Create PayPal Donation Buttons as per your need in very simple way.
Paypal Donation
paypal-donation
This PayPal Donation WordPress Plugin gives high level of flexible to admin to share some of the real information for donation.
Donate Me Developer Profile
3 plugins · 30 total installs
How We Detect Donate Me
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- DONATEME START --><!-- DONATEME END --><!-- DONATEME SHORTCODE START --><!-- DONATEME SHORTCODE END -->