Easy Donation for Woocommerce Security & Risk Analysis

wordpress.org/plugins/easy-donation-for-woocommerce

Allow customers to add Donation directly from WooCommerce checkout page

0 active installs v1.0.3 PHP 7.4+ WP 6.0+ Updated Apr 3, 2024
checkoutdonationtipwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Donation for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Donation for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "easy-donation-for-woocommerce" plugin v1.0.3 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Furthermore, all identified SQL queries utilize prepared statements, and the vast majority of output is properly escaped, indicating good coding practices for preventing common vulnerabilities like SQL injection and cross-site scripting.

The analysis reveals a notably small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. This significantly limits potential entry points for attackers. The presence of one capability check, while not extensive, suggests some level of access control is implemented. The taint analysis also shows no high-severity issues, reinforcing the impression of a secure codebase.

However, the complete lack of nonce checks is a significant concern, especially given the plugin's interaction with WooCommerce. Without proper nonces, authenticated users could potentially perform unintended actions if tricked into clicking malicious links or submitting forms. The plugin's vulnerability history is completely clean, which is a positive indicator, but this does not negate the risks identified in the static analysis. The overall conclusion is that while the plugin is well-constructed with good defensive coding, the absence of nonce checks represents a critical gap that needs immediate attention.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

Easy Donation for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy Donation for Woocommerce Release Timeline

v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Easy Donation for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
89 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped90 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
edfw_update_settings (admin/class-easy-donation-for-woocommerce-admin.php:147)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Easy Donation for Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedincludes/class-easy-donation-for-woocommerce.php:142
actionadmin_noticesincludes/class-easy-donation-for-woocommerce.php:156
actionadmin_enqueue_scriptsincludes/class-easy-donation-for-woocommerce.php:157
actionadmin_enqueue_scriptsincludes/class-easy-donation-for-woocommerce.php:158
actionadmin_menuincludes/class-easy-donation-for-woocommerce.php:159
actionadmin_post_save_edfw_update_settingsincludes/class-easy-donation-for-woocommerce.php:160
actionwp_enqueue_scriptsincludes/class-easy-donation-for-woocommerce.php:176
actionwp_enqueue_scriptsincludes/class-easy-donation-for-woocommerce.php:177
actionwp_headincludes/class-easy-donation-for-woocommerce.php:180
actionwp_footerincludes/class-easy-donation-for-woocommerce.php:184
actionwoocommerce_cart_calculate_feesincludes/class-easy-donation-for-woocommerce.php:185
Maintenance & Trust

Easy Donation for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 3, 2024
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Easy Donation for Woocommerce Developer Profile

IT Path Solutions

13 plugins · 11K total installs

80
trust score
Avg Security Score
89/100
Avg Patch Time
77 days
View full developer profile
Detection Fingerprints

How We Detect Easy Donation for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-donation-for-woocommerce/css/easy-donation-for-woocommerce-admin.css/wp-content/plugins/easy-donation-for-woocommerce/js/easy-donation-for-woocommerce-admin.js/wp-content/plugins/easy-donation-for-woocommerce/js/custom.js/wp-content/plugins/easy-donation-for-woocommerce/js/admin.js
Script Paths
js/easy-donation-for-woocommerce-admin.jsjs/custom.jsjs/admin.js
Version Parameters
easy-donation-for-woocommerce?ver=easy-donation-for-woocommerce-admin?ver=custom?ver=admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
easy-donation-for-woocommerce-wrapedfw-donation-options
HTML Comments
<!-- Set Donation Field Position --><!-- Custom Options -->
Data Attributes
data-nonce
JS Globals
easy_donation_for_woocommerce_paramsedfw_admin_params
FAQ

Frequently Asked Questions about Easy Donation for Woocommerce