Donation Addon WooCommerce Security & Risk Analysis

wordpress.org/plugins/donation-addon-woocommerce

The WooCommerce Donation plugin (Addon) allows you to accept donations in WooCommerce with amounts specified by the end-user.

10 active installs v1.0.0 PHP 7.4+ WP 4.0+ Updated Apr 25, 2024
donation-for-woocommercewoocommerce-donate-to-charitywoocommerce-fundraising-pluginwordpress-donation-plugin-woocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Donation Addon WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Donation Addon WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "donation-addon-woocommerce" v1.0.0 plugin demonstrates several good security practices, including 100% use of prepared statements for SQL queries and proper output escaping. The absence of known vulnerabilities and critical taint analysis findings further contributes to a positive security posture. However, there are notable concerns regarding the attack surface. The presence of two unprotected AJAX handlers represents a significant risk, as these can be exploited by unauthenticated users, potentially leading to unintended actions or data manipulation if they interact with sensitive functionality. While the plugin has no recorded vulnerability history, the lack of comprehensive authorization checks on critical entry points means that newly discovered vulnerabilities could have a significant impact.

Overall, the plugin's commitment to secure coding for database interactions and output handling is commendable. Nevertheless, the unprotected AJAX handlers create a substantial weakness that needs immediate attention. The lack of any recorded vulnerabilities in its history might indicate a relatively new or less-targeted plugin, but this should not lead to complacency. Future security assessments should prioritize auditing the functionality exposed by these unprotected AJAX endpoints to identify and mitigate potential risks.

Key Concerns

  • Unprotected AJAX handlers
  • Limited capability checks on entry points
Vulnerabilities
None known

Donation Addon WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Donation Addon WooCommerce Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Donation Addon WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
28 escaped
Nonce Checks
1
Capability Checks
1
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped28 total outputs
Attack Surface
2 unprotected

Donation Addon WooCommerce Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_donationaddon_donation_formdonationaddon.php:371
noprivwp_ajax_donationaddon_donation_formdonationaddon.php:372

Shortcodes 1

[donationaddon_donation] donationaddon.php:121
WordPress Hooks 15
actionadmin_menudonationaddon.php:24
actionadmin_print_stylesdonationaddon.php:26
actionwp_enqueue_scriptsdonationaddon.php:73
actionwoocommerce_proceed_to_checkoutdonationaddon.php:115
actionwoocommerce_before_checkout_formdonationaddon.php:118
actionwp_headdonationaddon.php:279
filterwoocommerce_add_cart_item_datadonationaddon.php:323
actionwoocommerce_before_calculate_totalsdonationaddon.php:324
filterwoocommerce_cart_item_pricedonationaddon.php:347
filterwoocommerce_cart_item_subtotaldonationaddon.php:358
filterwoocommerce_get_item_datadonationaddon.php:402
actionwoocommerce_checkout_create_order_line_itemdonationaddon.php:416
filterwoocommerce_order_item_namedonationaddon.php:432
filtermanage_edit-shop_order_columnsdonationaddon.php:436
actionmanage_shop_order_posts_custom_columndonationaddon.php:442
Maintenance & Trust

Donation Addon WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 25, 2024
PHP min version7.4
Downloads964

Community Trust

Rating100/100
Number of ratings1
Active installs10
Alternatives

Donation Addon WooCommerce Alternatives

No alternatives data available yet.

Developer Profile

Donation Addon WooCommerce Developer Profile

Tushar Satani

4 plugins · 140 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Donation Addon WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/donation-addon-woocommerce/assets/css/donationaddon_front_style.css/wp-content/plugins/donation-addon-woocommerce/assets/css/donationaddon_admin_style.css/wp-content/plugins/donation-addon-woocommerce/assets/js/donationaddon_front_script.js
Script Paths
/wp-content/plugins/donation-addon-woocommerce/assets/js/donationaddon_front_script.js
Version Parameters
donationaddon_front_style.css?ver=donationaddon_donation_script.js?ver=

HTML / DOM Fingerprints

CSS Classes
donationaddon_donation_contentdonationaddon_display_optiondonationaddon_donationktdonation-btndonationaddon_add_donationdonationaddon_product_iddonationaddon_ajax_urldonationaddon_loader+2 more
Data Attributes
data-product-iddata-product-url
JS Globals
donationaddon_get_wc_donation_settingdonationaddon_donation_form_shortcode_htmldonationaddon_add_donation_on_checkout_pagedonationaddon_donation_form_front_htmldonationaddon_plugin_active_donationdonationaddon_admin_style+3 more
Shortcode Output
[donationaddon_donation]
FAQ

Frequently Asked Questions about Donation Addon WooCommerce