
Get Cash Security & Risk Analysis
wordpress.org/plugins/get-cashReceive payments, donations, tips on WordPress via Cash App, Venmo, Zelle, and PayPal with a button or QR Code anywhere on your website
Is Get Cash Safe to Use in 2026?
Use With Caution
Score 56/100Get Cash has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The "get-cash" plugin version 3.2.3 presents a mixed security posture. On the positive side, the static analysis reveals no instances of dangerous functions, raw SQL queries, file operations, or external HTTP requests. Output escaping is also quite robust at 89%, and there are no identified taint flows indicating potential for malicious data processing. The presence of Freemius v1.0, while a bundled library, doesn't immediately raise concerns without version-specific vulnerabilities. However, several significant weaknesses exist. The lack of nonce checks and capability checks across all entry points is a major red flag, particularly given the presence of unprotected REST API routes and AJAX handlers. The plugin also has a concerning vulnerability history with two unpatched medium-severity CVEs, both related to missing authorization and cross-site scripting, which indicates recurring security flaws that have not been addressed. The last vulnerability being dated in the future is a temporal anomaly but suggests a history of significant issues.
Despite the good practices in handling SQL and output, the critical absence of authorization and nonce checks on entry points, combined with a history of exploitable vulnerabilities, creates a substantial risk. The unprotected REST API route is a direct pathway for potential exploits. While the static analysis indicates no *current* critical taint issues, the historical pattern of missing authorization and XSS vulnerabilities, coupled with the lack of fundamental security checks on entry points, suggests a plugin that is prone to exploitation. Users of this plugin should be aware of these risks and prioritize patching any known vulnerabilities while advocating for more robust security implementations.
Key Concerns
- Unpatched CVEs (2 medium)
- REST API routes without permission callbacks (1)
- No nonce checks
- No capability checks
- Bundled outdated library (Freemius v1.0)
Get Cash Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Get Cash <= 3.2.3 - Missing Authorization
Get Cash <= 3.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Get Cash Code Analysis
Bundled Libraries
Output Escaping
Get Cash Attack Surface
REST API Routes 1
Shortcodes 6
WordPress Hooks 11
Maintenance & Trust
Get Cash Maintenance & Trust
Maintenance Signals
Community Trust
Get Cash Alternatives
Payment Plugins for PayPal WooCommerce
pymntpl-paypal-woocommerce
Developed exclusively between Payment Plugins and PayPal, PayPal for WooCommerce integrates with PayPal's newest API's.
Donations via PayPal
paypal-donations
Easy, simple setup to add a PayPal Donation button as a Widget or with a shortcode.
Payment Gateway for PayPal on WooCommerce
woo-paypal-gateway
PayPal, Credit/Debit Cards, Google Pay, Apple Pay, Pay Later, Venmo, SEPA, iDEAL, Mercado Pago, Bancontact & more - by an official PayPal Partner
Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More
better-payment
Better Payment allows you to automate payment transactions to manage payments, donations, subscriptions, sell products, etc on your Elementor website.
Receive customer payments on Woocommerce
momo-venmo
Receive Venmo payments on your website with WooCommerce + Venmo
Get Cash Developer Profile
6 plugins · 8K total installs
How We Detect Get Cash
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/get-cash/includes/css/bootstrap.min.css/wp-content/plugins/get-cash/includes/css/form.cssget-cash/style.css?ver=bootstrap.min.css?ver=form.css?ver=HTML / DOM Fingerprints
getcash_fs