DonatePress – Donation, Crowdfunding and Fundraising Platform Security & Risk Analysis

wordpress.org/plugins/donatepress

Add a donation button using Gutenberg and accept payment via PayPal.

0 active installs v0.1 PHP + WP 5.0+ Updated Mar 16, 2024
crowdfundingdonationkickstarter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DonatePress – Donation, Crowdfunding and Fundraising Platform Safe to Use in 2026?

Generally Safe

Score 85/100

DonatePress – Donation, Crowdfunding and Fundraising Platform has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The donatepress plugin version 0.1 exhibits a seemingly strong security posture based on the static analysis. There are no identified dangerous functions, SQL queries are all prepared, and outputs are properly escaped. Crucially, there are no detected taint flows or vulnerabilities in its history. The attack surface is minimal, with only one shortcode and no AJAX handlers or REST API routes exposed without authentication. This suggests diligent adherence to secure coding practices within the analyzed code itself. However, the complete lack of nonce checks and capability checks across all entry points is a significant concern. While there are no current issues, this absence of critical security controls leaves the plugin vulnerable to potential attacks if any input were ever to be processed without proper authorization or validation in future versions or through unforeseen interactions. The clean vulnerability history is positive but doesn't negate the inherent risk posed by missing essential security mechanisms.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
Vulnerabilities
None known

DonatePress – Donation, Crowdfunding and Fundraising Platform Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DonatePress – Donation, Crowdfunding and Fundraising Platform Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

DonatePress – Donation, Crowdfunding and Fundraising Platform Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[donatepress_payment_block] src\init.php:122
WordPress Hooks 4
actioninitsrc\init.php:90
actioninitsrc\init.php:121
filterwidget_textsrc\init.php:123
actionplugins_loadedsrc\init.php:191
Maintenance & Trust

DonatePress – Donation, Crowdfunding and Fundraising Platform Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMar 16, 2024
PHP min version
Downloads837

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

DonatePress – Donation, Crowdfunding and Fundraising Platform Developer Profile

DonatePress

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DonatePress – Donation, Crowdfunding and Fundraising Platform

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/donatepress/dist/blocks.style.build.css/wp-content/plugins/donatepress/dist/blocks.build.js/wp-content/plugins/donatepress/dist/blocks.editor.build.css
Script Paths
/wp-content/plugins/donatepress/dist/blocks.build.js

HTML / DOM Fingerprints

CSS Classes
Donatepress_Payment_Blockdontepress_tem
Data Attributes
data-plugin-dir-pathdata-plugin-dir-url
JS Globals
cgbGlobal
Shortcode Output
<form target="_blank" action="https://www.paypal.com/cgi-bin/webscr" method="post"><div class="Donatepress_Payment_Block"><input type="hidden" name="cmd" value="_donations"><input type="hidden" name="item_name"
FAQ

Frequently Asked Questions about DonatePress – Donation, Crowdfunding and Fundraising Platform