
FundPress – WordPress Donation Plugin Security & Risk Analysis
wordpress.org/plugins/fundpressEasily build your own crowdfunding platform like Kickstarter with this free WordPress donation plugin in just a few clicks. No coding required.
Is FundPress – WordPress Donation Plugin Safe to Use in 2026?
Generally Safe
Score 98/100FundPress – WordPress Donation Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The fundpress plugin v2.0.8 exhibits a generally good security posture with several strengths, notably the exclusive use of prepared statements for all SQL queries and a high percentage of properly escaped outputs. The presence of nonce and capability checks on its entry points (AJAX handlers) is also a positive indicator, suggesting an effort to prevent unauthorized access and actions. However, there are areas for concern. The taint analysis revealed two flows with unsanitized paths, which, while not classified as critical or high severity in this instance, represent potential avenues for injection vulnerabilities if not handled with utmost care. The plugin's vulnerability history includes one high severity CVE related to deserialization, indicating past issues with handling untrusted data which, even if patched now, warrants vigilance. The static analysis also identified two file operations and two external HTTP requests, which, depending on their implementation, could be points of exploitation if not secured properly.
Despite the positive signs of secure coding practices like prepared statements and output escaping, the presence of unsanitized paths in taint flows and the historical high-severity deserialization vulnerability are significant weaknesses. The number of entry points, while low and apparently protected, still constitutes an attack surface that requires constant scrutiny. The plugin's strengths lie in its diligent use of database security and output sanitization. However, the identified taint issues and past deserialization vulnerability highlight potential risks that require ongoing monitoring and a robust security strategy to mitigate. A balanced view suggests that while the plugin is making good efforts, these specific areas need to be prioritized for review and hardening.
Key Concerns
- Taint flows with unsanitized paths
- High severity historical CVE (Deserialization)
FundPress – WordPress Donation Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
FundPress <= 2.0.6 - Unauthenticated PHP Object Injection
FundPress – WordPress Donation Plugin Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
FundPress – WordPress Donation Plugin Attack Surface
AJAX Handlers 2
WordPress Hooks 129
Scheduled Events 1
Maintenance & Trust
FundPress – WordPress Donation Plugin Maintenance & Trust
Maintenance Signals
Community Trust
FundPress – WordPress Donation Plugin Alternatives
Mightycause Donation Forms and Embeds
mightycause-widgets
Easily embed Mightycause donation buttons, widgets, or forms on your WordPress website with no coding required.
Philantro – Donations and Donor Management
philantro
Securely accept one-time and recurring donations with automated donor records, analytics and fundraising campaign tracking.
Growfund – Ultimate Donation & Crowdfunding Solution
growfund
A complete crowdfunding and donation plugin for WordPress with dual operation modes, advanced analytics, and a modern user experience.
Fundrizer Lite – Donation Plugin for Transparent Fundraising
fundrizer
A donation plugin for charity fundraising, crowdfunding campaigns, and nonprofits with WooCommerce payments, donor management, and customizable forms …
Crowded Collect — Dues & Fundraising
crowded-collect-dues-fundraising
Embed your Crowded collection directly into your WordPress site with no coding required!
FundPress – WordPress Donation Plugin Developer Profile
21 plugins · 209K total installs
How We Detect FundPress – WordPress Donation Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fundpress/inc/class-dn-assets.php/wp-content/plugins/fundpress/inc/class-dn-shortcodes.php/wp-content/plugins/fundpress/inc/class-dn-template-include.php/wp-content/plugins/fundpress/inc/dn-template-hooks.php/wp-content/plugins/fundpress/inc/dn-core-hooks.php/wp-content/plugins/fundpress/inc/dn-core-functions.php/wp-content/plugins/fundpress/inc/class-dn-payment-gateways.php/wp-content/plugins/fundpress/inc/class-dn-email.php+14 moreHTML / DOM Fingerprints
fundpress-campaign-shortcodefundpress_campaign_formfundpress_campaign_detailfundpress-contentfundpress-shortcode<!-- FundPress is activated --><!-- End FundPress --><!-- FundPress Plugin -->data-fundpress-campaign-iddata-fundpress-target-amountFPFundPress[fundpress_campaign_form][fundpress_campaign_detail][fundpress_donors_list]