
HelloAsso Security & Risk Analysis
wordpress.org/plugins/helloassoHelloAsso est la solution gratuite des associations pour collecter des paiements et des dons sur internet.
Is HelloAsso Safe to Use in 2026?
Generally Safe
Score 97/100HelloAsso has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of helloasso v1.1.24 indicates a generally robust security posture with strong adherence to secure coding practices. All identified entry points, including AJAX handlers and shortcodes, appear to be protected by authentication and capability checks. The code exhibits excellent SQL query sanitization through prepared statements and comprehensive output escaping, eliminating risks associated with raw SQL injection and Cross-Site Scripting (XSS) from typical output vectors. The absence of file operations and the limited number of external HTTP requests also contribute positively to its security.
However, the plugin's vulnerability history presents a significant concern. With a total of 5 known CVEs, all classified as medium severity, and historical patterns including Missing Authorization and Cross-Site Scripting, it suggests recurring security weaknesses that have been addressed in past versions. While there are currently no unpatched vulnerabilities reported, the history indicates a tendency for such issues to emerge. The fact that these vulnerabilities were of medium severity and related to common attack types implies that attackers might find exploitable paths if new issues are introduced or if older ones are not meticulously patched in future updates.
In conclusion, helloasso v1.1.24 demonstrates strong technical security controls within its current codebase. Nevertheless, its past vulnerability record is a notable weakness. Users should remain vigilant and ensure prompt updates to address any future security advisories, as the plugin has a documented history of security flaws, albeit in older versions. The strong internal security of the current version is commendable, but the historical context warrants caution.
Key Concerns
- Multiple past medium severity CVEs found
- History of Missing Authorization vulnerabilities
- History of XSS vulnerabilities
HelloAsso Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
HelloAsso <= 1.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
HelloAsso <= 1.1.10 - Missing Authorization to Authenticated (Contributor+) Limited Options Update
HelloAsso <= 1.1.10 - Missing Authorization
HelloAsso <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
HelloAsso <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
HelloAsso Code Analysis
Output Escaping
Data Flow Analysis
HelloAsso Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
HelloAsso Maintenance & Trust
Maintenance Signals
Community Trust
HelloAsso Alternatives
HelloAsso Payments for WooCommerce
helloasso-payments-for-woocommerce
L’extension HelloAsso Payments for WooCommerce, votre solution de paiement gratuite pour votre boutique associative.
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
charitable
The best WordPress donation plugin. Create fundraising donation forms, accept recurring donations, easy donor management, add crowdfunding, and more.
WP Crowdfunding
wp-crowdfunding
WP Crowdfunding is a WordPress plugin for fundraising/backer sites. This WooCommerce based plugin lets you launch a site like Kickstarter easily.
Leyka
leyka
Leyka is a plugin for crowdfunding and donations collection via WordPress website.
HelloAsso Developer Profile
2 plugins · 4K total installs
How We Detect HelloAsso
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/helloasso/admin/css/hello-asso-admin.css/wp-content/plugins/helloasso/admin/js/hello-asso-admin.js/wp-content/plugins/helloasso/public/css/hello-asso-public.css/wp-content/plugins/helloasso/public/js/hello-asso-public.js/wp-content/plugins/helloasso/admin/js/hello-asso-admin.js/wp-content/plugins/helloasso/public/js/hello-asso-public.jshello-asso-admin.css?ver=hello-asso-admin.js?ver=hello-asso-public.css?ver=hello-asso-public.js?ver=HTML / DOM Fingerprints
helloasso-container<!-- Helloasso Payment Button --><!-- End Helloasso Payment Button --><!-- End Helloasso Payment --><!-- Helloasso Payment -->data-helloasso-campaign-iddata-helloasso-button-textdata-helloasso-button-styledata-helloasso-button-sizeHelloAssoPublic/wp-json/helloasso/v1/campaigns/wp-json/helloasso/v1/donations[helloasso_payment_button]