
FundCollector – Donations Plugin and Fundraising Platform for WordPress Security & Risk Analysis
wordpress.org/plugins/fundcollectorEasily receive donations on your website. Accept payments made with PayPal. For bank transfers, it automatically sends payment instructions via email.
Is FundCollector – Donations Plugin and Fundraising Platform for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100FundCollector – Donations Plugin and Fundraising Platform for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The fundcollector plugin v1.1.4 presents a mixed security posture. On the positive side, there are no known CVEs, and the plugin demonstrates good practices by utilizing prepared statements for a high percentage of its SQL queries and performing a reasonable number of nonce and capability checks. However, the static analysis reveals significant areas for concern. The presence of 2 AJAX handlers without authentication checks creates a direct entry point for potential attacks. Furthermore, the taint analysis indicates 6 high-severity flows with unsanitized paths, suggesting a risk of data being processed or used in a dangerous manner without proper validation. The substantial number of SQL queries and output operations, even with a good percentage of prepared statements and proper escaping, still represent a large surface area where vulnerabilities could potentially be introduced. The lack of any historical vulnerabilities is a positive indicator, but it doesn't negate the risks identified in the current code analysis. Overall, while the plugin has some strengths in its adoption of security best practices, the identified unauthenticated AJAX endpoints and high-severity taint flows represent immediate and significant risks that require attention.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows
FundCollector – Donations Plugin and Fundraising Platform for WordPress Security Vulnerabilities
FundCollector – Donations Plugin and Fundraising Platform for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
FundCollector – Donations Plugin and Fundraising Platform for WordPress Attack Surface
AJAX Handlers 19
Shortcodes 2
WordPress Hooks 45
Scheduled Events 2
Maintenance & Trust
FundCollector – Donations Plugin and Fundraising Platform for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
FundCollector – Donations Plugin and Fundraising Platform for WordPress Alternatives
Philantro – Donations and Donor Management
philantro
Securely accept one-time and recurring donations with automated donor records, analytics and fundraising campaign tracking.
Donorbox – Free Recurring Donation Plugin and Fundraising Platform
donorbox-donation-form
Donorbox is a powerful and secure donation management plugin for WordPress. We are the only donation plugin for WordPress that offers a fast feature-f …
Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More
better-payment
Better Payment allows you to automate payment transactions to manage payments, donations, subscriptions, sell products, etc on your Elementor website.
FundPress – WordPress Donation Plugin
fundpress
Easily build your own crowdfunding platform like Kickstarter with this free WordPress donation plugin in just a few clicks. No coding required.
Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms
kudos-donations
Add a donation button to any page on your website. Easy & fast setup. Works with Mollie payments.
FundCollector – Donations Plugin and Fundraising Platform for WordPress Developer Profile
1 plugin · 0 total installs
How We Detect FundCollector – Donations Plugin and Fundraising Platform for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fundcollector/assets/css/fundcollector-public.css/wp-content/plugins/fundcollector/assets/css/fundcollector-donation-form.css/wp-content/plugins/fundcollector/assets/css/fundcollector-admin.css/wp-content/plugins/fundcollector/assets/js/fundcollector-public.js/wp-content/plugins/fundcollector/assets/js/fundcollector-donation-form.js/wp-content/plugins/fundcollector/assets/js/fundcollector-admin.js/wp-content/plugins/fundcollector/assets/js/fundcollector-public.js/wp-content/plugins/fundcollector/assets/js/fundcollector-donation-form.js/wp-content/plugins/fundcollector/assets/js/fundcollector-admin.jsfundcollector/assets/css/fundcollector-public.css?ver=fundcollector/assets/css/fundcollector-donation-form.css?ver=fundcollector/assets/css/fundcollector-admin.css?ver=fundcollector/assets/js/fundcollector-public.js?ver=fundcollector/assets/js/fundcollector-donation-form.js?ver=fundcollector/assets/js/fundcollector-admin.js?ver=HTML / DOM Fingerprints
fundcollector-donation-formfundcollector-wrapperfundcollector-form-fieldfundcollector-submit-buttonfundcollector-paypal-buttonfundcollector-bank-transfer-instructionsfundcollector-admin-wrapfundcollector-settings-page<!-- Fundcollector Donation Form --><!-- End Fundcollector Donation Form --><!-- Fundcollector Admin Settings Page --><!-- End Fundcollector Admin Settings Page -->data-fundcollector-iddata-fundcollector-amountdata-fundcollector-currencydata-fundcollector-post-idfundcollector_paramsFundcollectorPublic/wp-json/fundcollector/v1/donation/wp-json/fundcollector/v1/settings[fundcollector_donation_form][fundcollector_donate_button]