
Donation Addon WooCommerce Security & Risk Analysis
wordpress.org/plugins/donation-addon-woocommerceThe WooCommerce Donation plugin (Addon) allows you to accept donations in WooCommerce with amounts specified by the end-user.
Is Donation Addon WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Donation Addon WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "donation-addon-woocommerce" v1.0.0 plugin demonstrates several good security practices, including 100% use of prepared statements for SQL queries and proper output escaping. The absence of known vulnerabilities and critical taint analysis findings further contributes to a positive security posture. However, there are notable concerns regarding the attack surface. The presence of two unprotected AJAX handlers represents a significant risk, as these can be exploited by unauthenticated users, potentially leading to unintended actions or data manipulation if they interact with sensitive functionality. While the plugin has no recorded vulnerability history, the lack of comprehensive authorization checks on critical entry points means that newly discovered vulnerabilities could have a significant impact.
Overall, the plugin's commitment to secure coding for database interactions and output handling is commendable. Nevertheless, the unprotected AJAX handlers create a substantial weakness that needs immediate attention. The lack of any recorded vulnerabilities in its history might indicate a relatively new or less-targeted plugin, but this should not lead to complacency. Future security assessments should prioritize auditing the functionality exposed by these unprotected AJAX endpoints to identify and mitigate potential risks.
Key Concerns
- Unprotected AJAX handlers
- Limited capability checks on entry points
Donation Addon WooCommerce Security Vulnerabilities
Donation Addon WooCommerce Release Timeline
Donation Addon WooCommerce Code Analysis
Output Escaping
Donation Addon WooCommerce Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
Donation Addon WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Donation Addon WooCommerce Alternatives
No alternatives data available yet.
Donation Addon WooCommerce Developer Profile
4 plugins · 140 total installs
How We Detect Donation Addon WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/donation-addon-woocommerce/assets/css/donationaddon_front_style.css/wp-content/plugins/donation-addon-woocommerce/assets/css/donationaddon_admin_style.css/wp-content/plugins/donation-addon-woocommerce/assets/js/donationaddon_front_script.js/wp-content/plugins/donation-addon-woocommerce/assets/js/donationaddon_front_script.jsdonationaddon_front_style.css?ver=donationaddon_donation_script.js?ver=HTML / DOM Fingerprints
donationaddon_donation_contentdonationaddon_display_optiondonationaddon_donationktdonation-btndonationaddon_add_donationdonationaddon_product_iddonationaddon_ajax_urldonationaddon_loader+2 moredata-product-iddata-product-urldonationaddon_get_wc_donation_settingdonationaddon_donation_form_shortcode_htmldonationaddon_add_donation_on_checkout_pagedonationaddon_donation_form_front_htmldonationaddon_plugin_active_donationdonationaddon_admin_style+3 more[donationaddon_donation]