Fundraising Thermometer by CouponBirds Security & Risk Analysis

wordpress.org/plugins/fundraising-thermometer-by-couponbirds

Thousands of online campaigns are using this gauge. It is the No.1 rating giving thermometer WordPress plugin. And it is Totally FREE!

400 active installs v1.7 PHP 5.2+ WP 2.7+ Updated Mar 3, 2021
charitydonatedonationfundraising-thermometernon-profit
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fundraising Thermometer by CouponBirds Safe to Use in 2026?

Generally Safe

Score 85/100

Fundraising Thermometer by CouponBirds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The fundraising-thermometer-by-couponbirds plugin v1.7 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no raw SQL queries, and no file operations. The absence of known vulnerabilities in its history is also a strong indicator of good past development practices. However, several concerning aspects arise from the static analysis. The very low percentage of properly escaped output (19%) is a significant weakness, suggesting a high potential for cross-site scripting (XSS) vulnerabilities, especially when user-supplied data is reflected in the output. The lack of nonce checks and capability checks across all entry points, even though the attack surface appears small, is a critical oversight that could allow unauthorized actions if an attacker can trigger the shortcode or other potential (though not explicitly identified) entry points without proper authentication or authorization.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Fundraising Thermometer by CouponBirds Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Fundraising Thermometer by CouponBirds Release Timeline

v1.7Current
v1.6
v1.5
v1.4
v1.3
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Fundraising Thermometer by CouponBirds Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

19% escaped31 total outputs
Attack Surface

Fundraising Thermometer by CouponBirds Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[birdsmeter] class_birdsmeter_shortcode.php:7
WordPress Hooks 2
actionadmin_menuclass_birdsmeter.php:27
actionadmin_initclass_birdsmeter_setting.php:8
Maintenance & Trust

Fundraising Thermometer by CouponBirds Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedMar 3, 2021
PHP min version5.2
Downloads5K

Community Trust

Rating98/100
Number of ratings7
Active installs400
Developer Profile

Fundraising Thermometer by CouponBirds Developer Profile

CouponBirds

1 plugin · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fundraising Thermometer by CouponBirds

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fundraising-thermometer-by-couponbirds/init_colorpicker.js
Script Paths
/wp-content/plugins/fundraising-thermometer-by-couponbirds/init_colorpicker.js

HTML / DOM Fingerprints

CSS Classes
birdsmeter_targetbirdsmeter_raisedbirdsmeter_campaign
Shortcode Output
<div class="wrap"><div class="icon32"></div><h1>Fundraising Thermometer Settings</h1><div class="nav-tab-wrapper"><a href="?page=birdsmeter-setting&tab=setting" class="nav-tab<a href="?page=birdsmeter-setting&tab=preview" class="nav-tab
FAQ

Frequently Asked Questions about Fundraising Thermometer by CouponBirds