
Donation or Tip For WooCommerce Security & Risk Analysis
wordpress.org/plugins/donation-or-tip-for-woocommerceAdd a customizable donation or tip field to your WooCommerce cart and checkout page. Support fixed amounts, percentage tips, and custom input — no cod …
Is Donation or Tip For WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Donation or Tip For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "donation-or-tip-for-woocommerce" plugin, version 1.0, exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding database interactions, with 100% of SQL queries utilizing prepared statements, and a commendable 96% of outputs being properly escaped. The absence of known CVEs and a clean vulnerability history are also significant strengths, suggesting a generally stable codebase. However, a notable concern arises from the substantial attack surface exposed through AJAX handlers. Out of 12 AJAX handlers, 10 lack authentication checks, presenting a significant opportunity for unauthorized actions if malicious input can be crafted.
The static analysis reveals no critical or high-severity issues in taint analysis, and the absence of dangerous functions or direct file operations is reassuring. The low number of nonce checks (2) is insufficient given the number of unprotected AJAX endpoints. While the lack of capability checks on these endpoints is the primary concern, the absence of nonce checks further exacerbates the risk by making it easier to trigger these unprotected handlers. The plugin's vulnerability history is clean, which is a good sign, but it doesn't negate the immediate risks identified in the current static analysis.
In conclusion, while the plugin avoids common pitfalls like raw SQL and unescaped output, the presence of numerous unprotected AJAX endpoints is a critical weakness that requires immediate attention. The clean vulnerability history is a positive indicator of past security efforts, but the current version's attack surface is a significant risk. Addressing the authentication and authorization on AJAX handlers should be the top priority to improve its overall security.
Key Concerns
- Unprotected AJAX handlers
- Low number of nonce checks
- No capability checks on AJAX
Donation or Tip For WooCommerce Security Vulnerabilities
Donation or Tip For WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Donation or Tip For WooCommerce Attack Surface
AJAX Handlers 12
Shortcodes 2
WordPress Hooks 23
Maintenance & Trust
Donation or Tip For WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Donation or Tip For WooCommerce Alternatives
Simple checkout page donations/tips for WooCommerce
simple-checkout-page-donationstips-for-woocommerce
This plugin lets you add custom tips for display in the checkout page. These tips are optional for the customer to add to the cart fee.
Donation Platform for WooCommerce: Fundraising & Donation Management
wc-donation-platform
Open source donation system for your fundraising that supports recurring donations and more
NS Free Price and Donation for WooCommerce
ns-free-price-and-donation-for-woocommerce
Let user can pay how much they like by setting one or more product with this plugin
Tips & Donations at WooCommerce Checkout
tips-donations-at-checkout
The plugin simply adds "Tips" field to your website's WooCommerce Checkout Form.
Simple Donation For Woo Lite
simple-donation-for-woo-lite
Accept donations for WooCommerce-powered eCommerce site. This plugin will add powerful donation functionality to your website.
Donation or Tip For WooCommerce Developer Profile
18 plugins · 5K total installs
How We Detect Donation or Tip For WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/donation-or-tip-for-woocommerce/public/js/design.js/wp-content/plugins/donation-or-tip-for-woocommerce/build/frontend/index.js/wp-content/plugins/donation-or-tip-for-woocommerce/src/assets/css/front-design.css/wp-content/plugins/donation-or-tip-for-woocommerce/admin/js/wp-color-picker-alpha.js/wp-content/plugins/donation-or-tip-for-woocommerce/admin/css/design.css/wp-content/plugins/donation-or-tip-for-woocommerce/admin/js/design.js/wp-content/plugins/donation-or-tip-for-woocommerce/public/js/design.js/wp-content/plugins/donation-or-tip-for-woocommerce/build/frontend/index.js/wp-content/plugins/donation-or-tip-for-woocommerce/admin/js/wp-color-picker-alpha.js/wp-content/plugins/donation-or-tip-for-woocommerce/admin/js/design.js/wp-content/plugins/donation-or-tip-for-woocommerce/public/js/design.js?ver=/wp-content/plugins/donation-or-tip-for-woocommerce/public/css/design.css?ver=/wp-content/plugins/donation-or-tip-for-woocommerce/build/frontend/index.js?ver=/wp-content/plugins/donation-or-tip-for-woocommerce/src/assets/css/front-design.css?ver=/wp-content/plugins/donation-or-tip-for-woocommerce/admin/js/wp-color-picker-alpha.js?ver=/wp-content/plugins/donation-or-tip-for-woocommerce/admin/css/design.css?ver=/wp-content/plugins/donation-or-tip-for-woocommerce/admin/js/design.js?ver=HTML / DOM Fingerprints
dotfw_donation_fielddotfw_donation_field_wrapperdata-dotfw-noncedot_pricesDOTFW_DATA