Donation Amount Tracker Security & Risk Analysis
wordpress.org/plugins/donation-amount-trackerTrack and display donation amounts from WooCommerce orders with customizable progress bars and displays for fundraising campaigns.
Is Donation Amount Tracker Safe to Use in 2026?
Generally Safe
Score 92/100Donation Amount Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "donation-amount-tracker" plugin v1.3.1 exhibits a generally strong security posture in many areas, demonstrating good development practices. Notably, it uses prepared statements for all SQL queries, properly escapes all output, and has no file operations or external HTTP requests, which are common sources of vulnerabilities. The absence of known CVEs and a clean vulnerability history further reinforce this positive outlook.
However, a significant concern arises from its attack surface. With 6 total entry points, 4 of them are AJAX handlers that lack authentication checks. This means that any unauthenticated user could potentially interact with these AJAX endpoints, which could lead to unintended actions or information disclosure depending on the functionality of these handlers. While taint analysis found no issues, the presence of unprotected AJAX handlers represents a tangible risk that warrants attention. The plugin also implements nonce checks and capability checks, which are good security measures, but their effectiveness is diminished when applied to entry points that can be accessed without any prior authentication.
In conclusion, the plugin's core code quality is high, with robust handling of data and a clean security record. The primary weakness lies in the exposure of critical functionality through unauthenticated AJAX endpoints. Addressing these unprotected entry points should be the priority to further harden the plugin's security.
Key Concerns
- Unprotected AJAX handlers
Donation Amount Tracker Security Vulnerabilities
Donation Amount Tracker Code Analysis
Output Escaping
Donation Amount Tracker Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
Donation Amount Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Donation Amount Tracker Alternatives
Donation Platform for WooCommerce: Fundraising & Donation Management
wc-donation-platform
Open source donation system for your fundraising that supports recurring donations and more
Potent Donations for WooCommerce
donations-for-woocommerce
Easily accept donations of varying amounts through your WooCommerce store.
Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms
kudos-donations
Add a donation button to any page on your website. Easy & fast setup. Works with Mollie payments.
Philantro – Donations and Donor Management
philantro
Securely accept one-time and recurring donations with automated donor records, analytics and fundraising campaign tracking.
Donation Addon WooCommerce
donation-addon-woocommerce
The WooCommerce Donation plugin (Addon) allows you to accept donations in WooCommerce with amounts specified by the end-user.
Donation Amount Tracker Developer Profile
1 plugin · 0 total installs
How We Detect Donation Amount Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/donation-amount-tracker/admin/css/donamt-admin.css/wp-content/plugins/donation-amount-tracker/admin/js/donamt-admin.js/wp-content/plugins/donation-amount-tracker/public/css/donamt-public.css/wp-content/plugins/donation-amount-tracker/public/js/donamt-public.jsdonation-amount-tracker/admin/css/donamt-admin.css?ver=donation-amount-tracker/admin/js/donamt-admin.js?ver=donation-amount-tracker/public/css/donamt-public.css?ver=donation-amount-tracker/public/js/donamt-public.js?ver=HTML / DOM Fingerprints
donamt-progress-bardonamt-progress-bar-innerdonamt-donation-goaldonamt-donation-raiseddonamt-donation-remainingdonamt-settings-pagedonamt-admin-sectiondata-donamt-goaldata-donamt-raiseddonamt_public_params[donation_progress_bar][donation_tracker]