
Donation QR Block Security & Risk Analysis
wordpress.org/plugins/donation-qr-blockDisplay an EPC/GiroCode QR code for SEPA bank donations. Scannable by banking apps to pre-fill transfer details.
Is Donation QR Block Safe to Use in 2026?
Generally Safe
Score 100/100Donation QR Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "donation-qr-block" plugin v1.0.1 demonstrates a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, particularly those without authentication or permission checks, significantly limits the attack surface. Furthermore, the code signals indicate good practices such as the exclusive use of prepared statements for SQL queries and a substantial portion of output being properly escaped. The absence of dangerous functions, file operations, external HTTP requests, and the lack of recorded vulnerabilities further reinforce this positive assessment. However, a notable concern is the complete absence of nonce checks and capability checks. While the current attack surface is minimal, if functionality were to be added in the future without these crucial security measures, it could introduce significant vulnerabilities. The 70% proper escaping on output, while good, also implies that 30% of outputs are not escaped, which could lead to cross-site scripting (XSS) vulnerabilities if the unescaped data is user-controlled or originates from an untrusted source. Overall, the plugin is currently very secure due to its limited functionality, but future development should prioritize implementing nonce and capability checks to maintain this security.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
- 30% of outputs not properly escaped
Donation QR Block Security Vulnerabilities
Donation QR Block Code Analysis
Output Escaping
Donation QR Block Attack Surface
WordPress Hooks 1
Maintenance & Trust
Donation QR Block Maintenance & Trust
Maintenance Signals
Community Trust
Donation QR Block Alternatives
GiroCode
girocode
This plugin displays GiroCodes for easy bank transfers. A GiroCode is a QR code with data for a transfer which can be scanned into a banking app.
scan2payme
scan2payme
Plugin for displaying payment QR-Codes in WooCommerce order pages.
Checkout Gateway for IRIS
checkout-gateway-iris
Unofficial IRIS checkout payment gateway for WooCommerce. Accept payments via IRIS and manage order statuses efficiently.
SEPA QR-Code for Woocommerce (GDPR-compliant)
mxp-sepa-qr-code-addon-for-woocommerce
Adds a SEPA-QR Code for bank transfer payments (bacs) in the WooCommerce Thankyou page and Woocommerce emails. The QR-Code can be hooked into other pl …
Czech QR Payments for WooCommerce
czech-qr-code-bank-transfer-payment-for-woocommerce
Payment method for fast QR code bank transfer payment from Czech banking mobile apps
Donation QR Block Developer Profile
1 plugin · 0 total installs
How We Detect Donation QR Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/donation-qr-block/build/index.js/wp-content/plugins/donation-qr-block/build/style-index.css/wp-content/plugins/donation-qr-block/build/index.jsdonation-qr-block/build/index.js?ver=donation-qr-block/build/style-index.css?ver=HTML / DOM Fingerprints
donation-qr-blockdonation-qr-block__innerdonation-qr-block__titledonation-qr-block__descriptiondonation-qr-block__qr-wrapperdonation-qr-block__detailsdonation-qr-block__detaildonation-qr-block__hintdata-block-name="donation-qr-block/donation-qr-block"<section class="donation-qr-block"><div class="donation-qr-block__inner"<h2 class="donation-qr-block__title"><p class="donation-qr-block__description">