
Accept Donations with PayPal & Stripe Security & Risk Analysis
wordpress.org/plugins/easy-paypal-donationAdd a PayPal or Stripe Donation Button to your website and start collecting donations today. No Coding Required. Official PayPal & Stripe Partner.
Is Accept Donations with PayPal & Stripe Safe to Use in 2026?
Generally Safe
Score 92/100Accept Donations with PayPal & Stripe has a strong security track record. Known vulnerabilities have been patched promptly.
The "easy-paypal-donation" plugin exhibits a mixed security posture. On the positive side, the static analysis indicates a strong adherence to secure coding practices concerning SQL queries, which are all prepared, and a significant number of nonce and capability checks are present. The absence of unprotected entry points further suggests a foundational level of security awareness. However, the taint analysis reveals a concerning weakness with a high-severity flow involving unsanitized paths, indicating a potential for path traversal or other file-related vulnerabilities. The plugin also makes numerous external HTTP requests, which can be a vector for various attacks if not properly validated and sanitized. The vulnerability history is a significant red flag, with a substantial number of past CVEs, including a high-severity one, and recurring patterns of Open Redirect, CSRF, and Cross-Site Scripting. While there are currently no unpatched vulnerabilities, the historical prevalence of these types of issues suggests a persistent lack of robust input validation and output escaping in certain areas, despite some positive indicators in the static analysis.
Key Concerns
- High severity taint flow with unsanitized paths
- Vulnerability history indicates recurring security weaknesses
- High percentage of outputs not properly escaped
- Significant number of external HTTP requests
Accept Donations with PayPal & Stripe Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
Accept Donations with PayPal <= 1.5.2 - Unauthenticated Open Redirect
Accept Donations with PayPal <= 1.4.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Accept Donations with PayPal & Stripe <= 1.4.4 - Reflected Cross-Site Scripting
Accept Donations with PayPal <= 1.3 - Reflected Cross-Site Scripting via Page
Accept Donations with PayPal <= 1.3.3 - Arbitrary Post Deletion via Cross-Site Request Forgery
Paypal Donation <= 1.3.1 - Admin+ Stored Cross-Site Scripting
Paypal Donation <= 1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Accept Donations with PayPal <= 1.3.0 Cross-Site Request Forgery to Post Deletion
Accept Donations with PayPal & Stripe Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Accept Donations with PayPal & Stripe Attack Surface
AJAX Handlers 10
Shortcodes 1
WordPress Hooks 26
Maintenance & Trust
Accept Donations with PayPal & Stripe Maintenance & Trust
Maintenance Signals
Community Trust
Accept Donations with PayPal & Stripe Alternatives
Recurring PayPal Donations
recurring-donation
Accept PayPal subscription or recurring donation payment from your WordPress site easily.
ActBlue Contributions
actblue-contributions
Easily embed your ActBlue contribution forms on any WordPress page. Designed and built by Upstatement.
Fundraising Thermometer by CouponBirds
fundraising-thermometer-by-couponbirds
Thousands of online campaigns are using this gauge. It is the No.1 rating giving thermometer WordPress plugin. And it is Totally FREE!
SKT Donation – Charity and Fundraising Plugin
skt-donation
SKT Donation plugin has been created to facilitate donations for NGO, non profit, charity, charitable organizations, crowdfunding, fundraisers via pay …
Give as you Live
give-as-you-live
Add a Give as you Live button or form to your website and start raising donations for your charity. The official plugin from Give as you Live.
Accept Donations with PayPal & Stripe Developer Profile
12 plugins · 44K total installs
How We Detect Accept Donations with PayPal & Stripe
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-paypal-donation/assets/css/wpedon-admin.css/wp-content/plugins/easy-paypal-donation/assets/js/wpedon-admin.js/wp-content/plugins/easy-paypal-donation/assets/css/wpedon.css/wp-content/plugins/easy-paypal-donation/assets/js/wpedon.js/wp-content/plugins/easy-paypal-donation/assets/js/deactivation-survey.jshttps://js.stripe.com/v3/easy-paypal-donation/assets/css/wpedon-admin.css?ver=easy-paypal-donation/assets/js/wpedon-admin.js?ver=easy-paypal-donation/assets/css/wpedon.css?ver=easy-paypal-donation/assets/js/wpedon.js?ver=easy-paypal-donation/assets/js/deactivation-survey.js?ver=HTML / DOM Fingerprints
wpedon-donation-buttonwpedon-payment-formEasy PayPal Donation ButtonCopyright 2014-2026 Scott PatersonThis program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful+11 moredata-wpedon-payment-typedata-wpedon-paypal-emaildata-wpedon-amountdata-wpedon-currencydata-wpedon-button-iddata-wpedon-stripe-checkout-session-idwpedonDeactivationSurveywpedon[wpedon]