
Donorbox – Free Recurring Donation Plugin and Fundraising Platform Security & Risk Analysis
wordpress.org/plugins/donorbox-donation-formDonorbox is a powerful and secure donation management plugin for WordPress. We are the only donation plugin for WordPress that offers a fast feature-f …
Is Donorbox – Free Recurring Donation Plugin and Fundraising Platform Safe to Use in 2026?
Generally Safe
Score 99/100Donorbox – Free Recurring Donation Plugin and Fundraising Platform has a strong security track record. Known vulnerabilities have been patched promptly.
The donorbox-donation-form plugin v7.1.12 exhibits a mixed security posture. The static analysis reveals good practices in several key areas. There are no dangerous functions, all SQL queries use prepared statements, and all identified outputs are properly escaped. The absence of file operations and external HTTP requests further contributes positively to its security. Furthermore, the attack surface, while consisting of two shortcodes, is noted as having no unprotected entry points. The taint analysis also shows no identified flows with unsanitized paths, indicating a lack of evident code-level vulnerabilities in this version.
However, the plugin's vulnerability history presents a significant concern. With two known medium-severity CVEs, both historically related to Cross-site Scripting (XSS), and a last vulnerability recorded in April 2022, there's an indication of past weaknesses in input sanitization or output encoding. While there are currently no unpatched vulnerabilities, the recurring nature of XSS issues suggests a potential for these to reappear if not rigorously addressed in future development. The lack of explicit nonce checks and capability checks in the static analysis, while not directly flagged as vulnerabilities due to the absence of unprotected entry points, could represent a potential area for concern if the attack surface were to expand or change in future versions.
In conclusion, while the current version of donorbox-donation-form v7.1.12 appears to be free of critical or high-severity code-level vulnerabilities based on the static and taint analysis, its past history of medium-severity XSS vulnerabilities warrants careful consideration. Users should ensure they are running the absolute latest version, as the absence of unpatched CVEs is a positive sign. However, the historical pattern should prompt ongoing vigilance.
Key Concerns
- Past medium severity XSS vulnerabilities
- Missing nonce checks
- Missing capability checks
Donorbox – Free Recurring Donation Plugin and Fundraising Platform Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Donorbox – Free Recurring Donation Form <= 7.1.6 - Cross-Site Scripting
Donorbox <= 7.1.1 - Authenticated Stored Cross-Site Scripting
Donorbox – Free Recurring Donation Plugin and Fundraising Platform Code Analysis
Output Escaping
Donorbox – Free Recurring Donation Plugin and Fundraising Platform Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
Donorbox – Free Recurring Donation Plugin and Fundraising Platform Maintenance & Trust
Maintenance Signals
Community Trust
Donorbox – Free Recurring Donation Plugin and Fundraising Platform Alternatives
Philantro – Donations and Donor Management
philantro
Securely accept one-time and recurring donations with automated donor records, analytics and fundraising campaign tracking.
Crowded Collect — Dues & Fundraising
crowded-collect-dues-fundraising
Embed your Crowded collection directly into your WordPress site with no coding required!
FundCollector – Donations Plugin and Fundraising Platform for WordPress
fundcollector
Easily receive donations on your website. Accept payments made with PayPal. For bank transfers, it automatically sends payment instructions via email.
SureDonation
suredonation
A powerful donation management plugin for WordPress with campaign tracking, Stripe payment processing, and donor management.
Add Donation to Cart
youbehero
Add Donation to Cart by YouBeHero is a powerful WordPress plugin that adds a donation widget to your WooCommerce checkout.
Donorbox – Free Recurring Donation Plugin and Fundraising Platform Developer Profile
1 plugin · 9K total installs
How We Detect Donorbox – Free Recurring Donation Plugin and Fundraising Platform
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/donorbox-donation-form/donorbox_embed_campaign.phphttps://donorbox.org/widget.jsHTML / DOM Fingerprints
descriptionname="donorbox_embed_campaign_options[donorbox_embed_campaign_id]"<script src="https://donorbox.org/widget.js" type="text/javascript"></script><iframe src="https://donorbox.org/embed/style="max-width:500px; min-width:310px;"style="max-width:100%; min-width:100%;"