Give – Divi Donation Modules Security & Risk Analysis

wordpress.org/plugins/give-donation-modules-for-divi

A GiveWP add-on which allows you to embed any GiveWP shortcode into your Divi-powered pages.

600 active installs v2.0.1 PHP 7.2+ WP 6.5+ Updated Feb 11, 2025
dividivi-modulesdonationfundraisinggivewp
91
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 12, 2025
Safety Verdict

Is Give – Divi Donation Modules Safe to Use in 2026?

Generally Safe

Score 91/100

Give – Divi Donation Modules has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 12, 2025Updated 1yr ago
Risk Assessment

The "give-donation-modules-for-divi" plugin v2.0.1 exhibits a generally positive security posture based on the provided static analysis. The absence of identified dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the plugin demonstrates good practices in output escaping, with a high percentage of outputs properly handled, and it includes at least one capability check, which is a fundamental security control. The lack of critical or high-severity taint analysis findings suggests a reduced risk of common injection vulnerabilities.

However, there are areas that warrant attention. The plugin has a history of one known CVE, which, although currently patched, indicates past security weaknesses. The specific type of past vulnerability, "Insertion of Sensitive Information into Externally-Accessible File or Directory," suggests a need for ongoing vigilance regarding file permissions and input validation in future updates. The complete absence of identified entry points (AJAX, REST API, shortcodes, cron events) in this analysis is unusual and could either reflect an extremely limited plugin functionality or potential limitations in the analysis itself. The lack of nonce checks, while not explicitly tied to an entry point in this analysis, is a general security best practice that is missing.

In conclusion, the plugin has a good foundation with its current code practices. The past CVE, however, serves as a reminder that even well-developed plugins can have vulnerabilities. The plugin's strengths lie in its controlled use of potentially dangerous functions and its SQL query handling. Its weaknesses include a lack of nonce checks and a historical vulnerability that, while patched, points to a specific risk vector.

Key Concerns

  • Past CVE found
  • No nonce checks found
Vulnerabilities
1

Give – Divi Donation Modules Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22633medium · 5.8Insertion of Sensitive Information into Externally-Accessible File or Directory

Give – Divi Donation Modules <= 2.0.0 - Sensitive Information Dislcosure

Feb 12, 2025 Patched in 2.0.1 (13d)
Code Analysis
Analyzed Mar 16, 2026

Give – Divi Donation Modules Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
18 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped21 total outputs
Attack Surface

Give – Divi Donation Modules Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionbefore_give_initgive-divi.php:37
actionadmin_initgive-divi.php:48
actionadmin_noticessrc\Addon\Environment.php:24
actionadmin_noticessrc\Addon\Environment.php:30
actionet_builder_readysrc\Divi\AddonServiceProvider.php:47
actiongive_embed_footersrc\Divi\Modules\DonationForm\Module.php:44
Maintenance & Trust

Give – Divi Donation Modules Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 11, 2025
PHP min version7.2
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs600
Developer Profile

Give – Divi Donation Modules Developer Profile

StellarWP

26 plugins · 3.1M total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
462 days
View full developer profile
Detection Fingerprints

How We Detect Give – Divi Donation Modules

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/give-donation-modules-for-divi/public/js/give-divi.js
Script Paths
/wp-content/plugins/give-donation-modules-for-divi/public/js/give-divi.js
Version Parameters
give-donation-modules-for-divi/public/js/give-divi.js?ver=

HTML / DOM Fingerprints

JS Globals
GiveDivi
REST Endpoints
/wp-json/give-api/v2/give-divi/render-donation-form
Shortcode Output
[give_donation_form[give_donation_goals[give_donation_receipt[give_donor_wall
FAQ

Frequently Asked Questions about Give – Divi Donation Modules