Get Cash Security & Risk Analysis

wordpress.org/plugins/get-cash

Receive payments, donations, tips on WordPress via Cash App, Venmo, Zelle, and PayPal with a button or QR Code anywhere on your website

500 active installs v3.2.3 PHP 5.0+ WP 5.0+ Updated Nov 22, 2025
cashappdonationspaypalvenmozelle
56
C · Use Caution
CVEs total2
Unpatched2
Last CVEDec 1, 2025
Safety Verdict

Is Get Cash Safe to Use in 2026?

Use With Caution

Score 56/100

Get Cash has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.

2 known CVEs 2 unpatched Last CVE: Dec 1, 2025Updated 4mo ago
Risk Assessment

The "get-cash" plugin version 3.2.3 presents a mixed security posture. On the positive side, the static analysis reveals no instances of dangerous functions, raw SQL queries, file operations, or external HTTP requests. Output escaping is also quite robust at 89%, and there are no identified taint flows indicating potential for malicious data processing. The presence of Freemius v1.0, while a bundled library, doesn't immediately raise concerns without version-specific vulnerabilities. However, several significant weaknesses exist. The lack of nonce checks and capability checks across all entry points is a major red flag, particularly given the presence of unprotected REST API routes and AJAX handlers. The plugin also has a concerning vulnerability history with two unpatched medium-severity CVEs, both related to missing authorization and cross-site scripting, which indicates recurring security flaws that have not been addressed. The last vulnerability being dated in the future is a temporal anomaly but suggests a history of significant issues.

Despite the good practices in handling SQL and output, the critical absence of authorization and nonce checks on entry points, combined with a history of exploitable vulnerabilities, creates a substantial risk. The unprotected REST API route is a direct pathway for potential exploits. While the static analysis indicates no *current* critical taint issues, the historical pattern of missing authorization and XSS vulnerabilities, coupled with the lack of fundamental security checks on entry points, suggests a plugin that is prone to exploitation. Users of this plugin should be aware of these risks and prioritize patching any known vulnerabilities while advocating for more robust security implementations.

Key Concerns

  • Unpatched CVEs (2 medium)
  • REST API routes without permission callbacks (1)
  • No nonce checks
  • No capability checks
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
2

Get Cash Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-49041medium · 5.3Missing Authorization

Get Cash <= 3.2.3 - Missing Authorization

Dec 1, 2025Unpatched
CVE-2025-58823medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Get Cash <= 3.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 5, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Get Cash Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
72 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

89% escaped81 total outputs
Attack Surface
1 unprotected

Get Cash Attack Surface

Entry Points7
Unprotected1

REST API Routes 1

POST/wp-json/get-cash/v1/formincludes\form-post.php:37

Shortcodes 6

[cashapp] includes\shortcodes.php:53
[venmo] includes\shortcodes.php:79
[paypal] includes\shortcodes.php:106
[zelle] includes\shortcodes.php:133
[get-cash] includes\shortcodes.php:160
[get-cash-form] includes\shortcodes.php:237
WordPress Hooks 11
actionplugins_loadedget-cash.php:96
actioninitget-cash.php:98
filterwidget_textget-cash.php:104
filterwidget_textget-cash.php:105
actionadmin_enqueue_scriptsincludes\admin\dashboard.php:3
actionadmin_menuincludes\admin\dashboard.php:15
actionadmin_initincludes\class-get_cash.php:12
actionwp_enqueue_scriptsincludes\form-post.php:3
actioninitincludes\form-post.php:13
actionrest_api_initincludes\form-post.php:34
actionwp_enqueue_scriptsincludes\shortcodes.php:6
Maintenance & Trust

Get Cash Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 22, 2025
PHP min version5.0
Downloads13K

Community Trust

Rating100/100
Number of ratings1
Active installs500
Developer Profile

Get Cash Developer Profile

The African Boss

6 plugins · 8K total installs

81
trust score
Avg Security Score
90/100
Avg Patch Time
66 days
View full developer profile
Detection Fingerprints

How We Detect Get Cash

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/get-cash/includes/css/bootstrap.min.css/wp-content/plugins/get-cash/includes/css/form.css
Version Parameters
get-cash/style.css?ver=bootstrap.min.css?ver=form.css?ver=

HTML / DOM Fingerprints

JS Globals
getcash_fs
FAQ

Frequently Asked Questions about Get Cash