
Formipay – Donations & Instant Payment Forms (Paystack, Flutterwave & More) Security & Risk Analysis
wordpress.org/plugins/formipayReceive donations and payments instantly via Paystack and Flutterwave using lightweight, secure, and conversion-focused forms.
Is Formipay – Donations & Instant Payment Forms (Paystack, Flutterwave & More) Safe to Use in 2026?
Generally Safe
Score 100/100Formipay – Donations & Instant Payment Forms (Paystack, Flutterwave & More) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "formipay" v2.0.1 exhibits a generally good security posture with several positive indicators. The absence of any recorded vulnerabilities, including critical or high severity ones, is a significant strength. Furthermore, the code demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage (94%) of output properly escaped, mitigating common attack vectors like SQL injection and Cross-Site Scripting (XSS). Taint analysis also found no critical or high severity flows with unsanitized paths. However, the plugin does present some areas of concern. It has two AJAX handlers that lack authentication checks, representing a direct entry point for potential unauthorized actions or information disclosure if these handlers perform sensitive operations. While the total number of entry points is relatively small, these unprotected AJAX handlers are a notable weakness. The presence of one file operation and two external HTTP requests, while not inherently malicious, warrants careful scrutiny for potential vulnerabilities if not handled securely, especially in conjunction with the unprotected AJAX endpoints. Overall, the plugin is built on a solid foundation with good security practices, but the unprotected AJAX handlers introduce a specific, actionable risk that needs attention.
Key Concerns
- AJAX handlers without authentication checks
Formipay – Donations & Instant Payment Forms (Paystack, Flutterwave & More) Security Vulnerabilities
Formipay – Donations & Instant Payment Forms (Paystack, Flutterwave & More) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Formipay – Donations & Instant Payment Forms (Paystack, Flutterwave & More) Attack Surface
AJAX Handlers 4
Shortcodes 3
WordPress Hooks 24
Maintenance & Trust
Formipay – Donations & Instant Payment Forms (Paystack, Flutterwave & More) Maintenance & Trust
Maintenance Signals
Community Trust
Formipay – Donations & Instant Payment Forms (Paystack, Flutterwave & More) Alternatives
ZERTH Pay Payment Gateway
zerth-pay-payment-gateway
ZERTH Pay for WooCommerce allows your store in Nigeria to accept secure payments via Bank transfer witthin Nigeria banks and cryptocurrency payment ch …
Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More
better-payment
Better Payment allows you to automate payment transactions to manage payments, donations, subscriptions, sell products, etc on your Elementor website.
Payment Forms for Paystack
payment-forms-for-paystack
Create forms with multiple input fields and have your users pay before submission. Form submission results are available on your dashboard.
Flutterwave WooCommerce
rave-woocommerce-payment-gateway
The WooCommerce Plugin makes it very easy and quick to add Flutterwave Payment option on Checkout for your online store. Accept Credit card, Debit car …
Paystack Easy Digital Downloads Payment Gateway
edd-paystack
Paystack for Easy Digital Downloads allows your store to accept secure payments from multiple local and global payment channels.
Formipay – Donations & Instant Payment Forms (Paystack, Flutterwave & More) Developer Profile
2 plugins · 50 total installs
How We Detect Formipay – Donations & Instant Payment Forms (Paystack, Flutterwave & More)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formipay/assets/js/formipay-admin.jsformipay-admin-js?ver=HTML / DOM Fingerprints
formipay-donation-form<!-- wp:paragraph --><!-- /wp:paragraph -->data-formipay-gatewaydata-formipay-amountdata-formipay-currencydata-formipay-emaildata-formipay-namedata-formipay-phone+3 morewindow.formipay_gatewaywindow.formipay_paystack_pkwindow.formipay_flutterwave_pkwindow.formipay_currency[formipay_donation_form]