Grants for Nonprofits Widget Security & Risk Analysis

wordpress.org/plugins/grants-for-nonprofits-widget

The Grants for Nonprofits Widget is an aggregation of new grant opportunities for nonprofits and other organizations.

10 active installs v1.1 PHP + WP 2.8+ Updated Sep 30, 2014
501-c-3feedgrantsrsswidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Grants for Nonprofits Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Grants for Nonprofits Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "grants-for-nonprofits-widget" v1.1 plugin exhibits a strong security posture based on the provided static analysis. It reports zero AJAX handlers, REST API routes, shortcodes, or cron events, resulting in no identified entry points that could be exploited. Furthermore, the absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and the complete lack of taint analysis flows with unsanitized paths all contribute to a generally secure codebase. The plugin also has no known vulnerabilities in its history, which is a positive indicator. However, a significant concern arises from the complete lack of output escaping (0% properly escaped). This means that any dynamic data displayed by the widget is vulnerable to Cross-Site Scripting (XSS) attacks. Additionally, the absence of nonce and capability checks, while not directly exploitable due to the lack of entry points, indicates a potential oversight in securing future functionalities should they be added. The plugin demonstrates good practices in preventing direct code execution vulnerabilities but falls short in protecting against common output-based attacks.

Key Concerns

  • No output escaping implemented
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Grants for Nonprofits Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Grants for Nonprofits Widget Release Timeline

vgrantfeed.php
vreadme.txt
vscreenshot-1.JPG
Code Analysis
Analyzed Mar 16, 2026

Grants for Nonprofits Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

Grants for Nonprofits Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initgrantfeed.php:16
Maintenance & Trust

Grants for Nonprofits Widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedSep 30, 2014
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Grants for Nonprofits Widget Developer Profile

kutu62

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Grants for Nonprofits Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
grants
Data Attributes
id="Nonprofit Grants"
Shortcode Output
<small><a target="_blank" href="http://feeds.feedburner.com/EasyGrantsForNonProfitsAndBusinesses" title="RSS of source feed for non profit grants">Get The RSS Feed</a></small><br><iframe longdesc="Grants for Nonprofits Feed" title="Grants for Nonprofits Feed" id="Nonprofit Grants" frameBorder="0" scrolling=no width="100%" frameborder="0" height="304px" src="http://fantasyknuckleheads.com/mashed/easy-grants-iframe.html"></iframe>
FAQ

Frequently Asked Questions about Grants for Nonprofits Widget