
Doneren met Mollie Security & Risk Analysis
wordpress.org/plugins/doneren-met-mollieThis plugin is both suitable for one-time donations and for periodic payments. All payment methods of Mollie are integrated into the plugin.
Is Doneren met Mollie Safe to Use in 2026?
Generally Safe
Score 98/100Doneren met Mollie has a strong security track record. Known vulnerabilities have been patched promptly.
The "doneren-met-mollie" plugin v2.10.10 exhibits a generally good security posture with several positive indicators. The static analysis reveals a relatively small attack surface consisting of four shortcodes, all of which appear to be protected by nonce and capability checks. The plugin also demonstrates a strong commitment to secure coding practices, with a high percentage of SQL queries using prepared statements and a significant majority of outputs being properly escaped. The presence of file operations and external HTTP requests is noted, but their context and security implications are not detailed in the provided data.
However, the taint analysis reveals a potential area of concern. While no critical or high severity taint flows were identified, seven high-severity flows with unsanitized paths were detected. This suggests that user-supplied input might not be adequately sanitized in certain execution paths, potentially leading to vulnerabilities if exploited. Furthermore, the plugin's vulnerability history shows three medium-severity CVEs, specifically related to Cross-site Scripting and Exposure of Sensitive Information. Although currently unpatched CVEs are zero, the recurring nature of these vulnerability types indicates a persistent weakness in input validation or output escaping in specific scenarios.
In conclusion, "doneren-met-mollie" v2.10.10 has strengths in its controlled attack surface and adoption of secure coding practices for SQL and output escaping. Nevertheless, the identified taint flows and historical vulnerability patterns necessitate careful attention. The seven high-severity taint flows with unsanitized paths are the most pressing concern, alongside the historical tendency towards XSS and information exposure vulnerabilities. Addressing these specific areas is crucial for further enhancing the plugin's security.
Key Concerns
- High severity taint flows with unsanitized paths
- Medium severity historical CVEs (3 total)
Doneren met Mollie Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Doneren met Mollie <= 2.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Doneren met Mollie <= 2.10.2 - Unauthenticated Reflected Cross-Site Scripting via search
Doneren met Mollie <= 2.8.4 - Information Disclosure
Doneren met Mollie Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Doneren met Mollie Attack Surface
Shortcodes 4
WordPress Hooks 9
Maintenance & Trust
Doneren met Mollie Maintenance & Trust
Maintenance Signals
Community Trust
Doneren met Mollie Alternatives
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
charitable
The best WordPress donation plugin. Create fundraising donation forms, accept recurring donations, easy donor management, add crowdfunding, and more.
Mollie Forms
mollie-forms
Create registration forms with payment methods of Mollie. One-time and recurring payments are possible.
Paytium: Mollie payment forms & donations
paytium
Mollie forms for payments and donations. With iDEAL | WERO , PayPal, Credit/Debet cards, subscriptions and recurring payments!
GF Mollie by Indigo
gf-mollie-by-indigo
You can link Mollie to Gravity Forms with GF Mollie by Indigo.
Doneren met Mollie Developer Profile
2 plugins · 7K total installs
How We Detect Doneren met Mollie
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/doneren-met-mollie/assets/js/custom.js/wp-content/plugins/doneren-met-mollie/assets/css/style.css/wp-content/plugins/doneren-met-mollie/assets/js/custom.jsdoneren-met-mollie/assets/js/custom.js?ver=doneren-met-mollie/assets/css/style.css?ver=HTML / DOM Fingerprints
dmm-donate-formdata-plugin-name="doneren-met-mollie"data-plugin-version="2.10.10"dmm_plugin_options[doneren_met_mollie][doneren_met_mollie_total][doneren_met_mollie_donors][doneren_met_mollie_goal]