Double the Donation – A workplace giving tool Security & Risk Analysis

wordpress.org/plugins/double-the-donation

Double the Donation – Easily add our matching gifts plugin and volunteering plugin on your site to help your fundraising efforts

1K active installs v3.1.0 PHP 5.6.20+ WP 3.0+ Updated Nov 10, 2025
donation-matchingdouble-the-donationmatching-gifts
97
A · Safe
CVEs total3
Unpatched0
Last CVENov 10, 2025
Safety Verdict

Is Double the Donation – A workplace giving tool Safe to Use in 2026?

Generally Safe

Score 97/100

Double the Donation – A workplace giving tool has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Nov 10, 2025Updated 6mo ago
Risk Assessment

The "double-the-donation" plugin v3.1.0 exhibits a generally strong security posture based on the static analysis. It demonstrates good practices by utilizing prepared statements for all SQL queries, proper output escaping for the vast majority of outputs, and incorporating nonce and capability checks. The absence of dangerous functions, file operations, and critical/high severity taint flows is also positive. However, the plugin does make two external HTTP requests, which, while not inherently problematic, could represent a potential attack vector if the target endpoints are compromised or if the requests are made without proper validation of the returned data.

The vulnerability history presents a significant concern. While there are currently no unpatched vulnerabilities, the plugin has a history of 3 medium severity CVEs, specifically related to Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). The commonality of these vulnerability types in the past suggests a recurring pattern in how user input is handled or how actions are protected. The fact that these vulnerabilities existed and were later patched indicates that the developers are responsive to security issues, but it also highlights areas where the plugin has previously been susceptible to exploitation.

In conclusion, "double-the-donation" v3.1.0 has commendable technical security practices in its current build. The code analysis reveals a well-hardened codebase with minimal exploitable entry points and secure data handling for SQL. The primary area of caution stems from its past vulnerability record, which indicates a need for continued vigilance and robust security testing to prevent the recurrence of XSS and CSRF issues. The presence of external HTTP requests warrants a review of their implementation for potential security implications.

Key Concerns

  • Previous Medium severity XSS vulnerabilities
  • Previous Medium severity CSRF vulnerabilities
  • External HTTP requests present
Vulnerabilities
3 published

Double the Donation – A workplace giving tool Security Vulnerabilities

CVEs by Year

3 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-12020medium · 4.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Double the Donation <= 3.0.0 - Authenticated (Admin+) Stored Cross-Site Scripting

Nov 10, 2025 Patched in 3.1.0 (3d)
CVE-2025-57930medium · 4.3Cross-Site Request Forgery (CSRF)

Double the Donation <= 2.0.0 - Cross-Site Request Forgery

Sep 22, 2025 Patched in 3.0.0 (11d)
CVE-2025-57929medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Double the Donation <= 2.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 22, 2025 Patched in 3.0.0 (11d)
Version History

Double the Donation – A workplace giving tool Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Double the Donation – A workplace giving tool Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
20 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

95% escaped21 total outputs
Attack Surface

Double the Donation – A workplace giving tool Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[doublethedonation] doublethedonation.php:95
[doublethedonation_volunteer] doublethedonation.php:96
WordPress Hooks 4
actionplugins_loadeddoublethedonation.php:29
actionadmin_menudoublethedonation.php:103
actionadmin_initdoublethedonation.php:104
actionadmin_initdoublethedonation.php:118
Maintenance & Trust

Double the Donation – A workplace giving tool Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 10, 2025
PHP min version5.6.20
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

Double the Donation – A workplace giving tool Developer Profile

kanwei_doublethedonation

1 plugin · 1K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Double the Donation – A workplace giving tool

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/double-the-donation/includes/css/dtddonation.css/wp-content/plugins/double-the-donation/includes/js/dtddonation.js
Script Paths
https://doublethedonation.com/api/js/ddplugin.js

HTML / DOM Fingerprints

CSS Classes
dd-container
HTML Comments
<!-- Double the Donation Admin --><!-- Matching gifts plugin for nonprofits, powered by Double the Donation --><!-- API Key is empty. Double the Donation will not load. --><!-- If the api key is present, print the following. -->+5 more
Data Attributes
data-api-keydata-volunteer-grant-specific
JS Globals
DDCONF
Shortcode Output
<div id="dd-container"></div>
FAQ

Frequently Asked Questions about Double the Donation – A workplace giving tool