Fee recovery for GiveWP Security & Risk Analysis

wordpress.org/plugins/fee-recovery-for-givewp

Define a recovery fee for your donations forms, give the option to your donor cover you payment fees.

10 active installs v1.3.1 PHP 8.0+ WP 5.0+ Updated Mar 12, 2026
donationfeeformgivewprecover
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fee recovery for GiveWP Safe to Use in 2026?

Generally Safe

Score 100/100

Fee recovery for GiveWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21d ago
Risk Assessment

The "fee-recovery-for-givewp" plugin v1.3.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified entry points, including AJAX handlers, REST API routes, shortcodes, and cron events, significantly limits the potential attack surface. Furthermore, the code demonstrates excellent security practices with 100% of SQL queries using prepared statements and all output being properly escaped, eliminating common risks associated with data manipulation and cross-site scripting. The presence of a nonce check is a positive sign, indicating some level of protection against CSRF attacks.

However, the complete lack of capability checks across all entry points, while currently moot due to the zero entry points, could become a concern if new functionalities are added without proper authorization checks. The absence of identified taint flows and dangerous functions is commendable. The plugin's vulnerability history is entirely clean, with no recorded CVEs, which suggests a history of secure development and maintenance. The overall assessment indicates a very low-risk plugin, with its primary strength being its minimal attack surface and strong adherence to secure coding practices for the implemented features. The only area for potential future consideration would be ensuring capability checks are implemented if the plugin's functionality expands.

Vulnerabilities
None known

Fee recovery for GiveWP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fee recovery for GiveWP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
22 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped22 total outputs
Attack Surface

Fee recovery for GiveWP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
filtergive_get_sections_generaladmin\class-fee-recovery-for-givewp-admin.php:51
filtergive_get_settings_generaladmin\class-fee-recovery-for-givewp-admin.php:52
actionplugins_loadedfee-recovery-for-givewp.php:64
actionadmin_noticesincludes\class-fee-recovery-for-givewp-activator.php:37
actionplugins_loadedincludes\class-fee-recovery-for-givewp.php:219
actionadmin_enqueue_scriptsincludes\class-fee-recovery-for-givewp.php:232
actionadmin_enqueue_scriptsincludes\class-fee-recovery-for-givewp.php:233
actionwp_enqueue_scriptsincludes\class-fee-recovery-for-givewp.php:247
actionwp_enqueue_scriptsincludes\class-fee-recovery-for-givewp.php:248
filtergive_donation_data_before_gatewayincludes\class-fee-recovery-for-givewp.php:249
actiongive_initincludes\class-fee-recovery-for-givewp.php:250
filterget_post_metadataincludes\class-fee-recovery-for-givewp.php:251
actiongivewp_donation_form_schemaincludes\class-fee-recovery-for-givewp.php:253
filterget_post_metadataincludes\class-fee-recovery-for-givewp.php:305
actiongive_after_donation_levelspublic\class-fee-recovery-for-givewp-public.php:52
Maintenance & Trust

Fee recovery for GiveWP Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 12, 2026
PHP min version8.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Fee recovery for GiveWP Developer Profile

linknacional

18 plugins · 5K total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Fee recovery for GiveWP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fee-recovery-for-givewp/admin/css/fee-recovery-for-givewp-admin.css/wp-content/plugins/fee-recovery-for-givewp/admin/js/fee-recovery-for-givewp-admin.js
Script Paths
/wp-content/plugins/fee-recovery-for-givewp/admin/js/fee-recovery-for-givewp-admin.js
Version Parameters
fee-recovery-for-givewp/admin/css/fee-recovery-for-givewp-admin.css?ver=fee-recovery-for-givewp/admin/js/fee-recovery-for-givewp-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
lkn-fee-recovery
Data Attributes
lkn_fee_recovery_setting_fieldlkn_fee_recovery_setting_field_fixed
JS Globals
lknRecoveryFeeAdmin
FAQ

Frequently Asked Questions about Fee recovery for GiveWP