
Tap To Donate for GiveWP by Jovvie Security & Risk Analysis
wordpress.org/plugins/jovvie-in-person-payments-givewpTap To Donate uses GiveWP forms, your phone with Tap to Pay, and Stripe to collect in-person swipe, tap, or scan donations.
Is Tap To Donate for GiveWP by Jovvie Safe to Use in 2026?
Generally Safe
Score 100/100Tap To Donate for GiveWP by Jovvie has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "jovvie-in-person-payments-givewp" plugin, version 1.0.34, exhibits a mixed security posture. While it demonstrates good practices in SQL query handling and a lack of reported vulnerabilities, it presents significant concerns regarding its attack surface. The plugin exposes six AJAX handlers, with a substantial four of them lacking proper authentication checks. This creates a considerable risk for unauthorized actions or data manipulation if these handlers are not adequately secured by other means within the WordPress environment.
The static analysis reveals no critical taint analysis findings, suggesting that sensitive data flows are likely managed with some degree of caution. However, the absence of taint analysis flows being analyzed at all might indicate limited depth in the static analysis process itself, or that the plugin's code structure inherently avoids such complex data flows. The presence of file operations and external HTTP requests, while not flagged as inherently malicious, warrants attention in a broader security audit to ensure they are used for legitimate purposes and are not vectors for compromise.
Given the complete absence of historical vulnerabilities and CVEs, the plugin may have a history of being well-maintained and secure. This could imply that the developers are responsive to security issues, or that the plugin's functionality does not lend itself to common vulnerability types. Nevertheless, the identified unprotected AJAX handlers represent a clear and present risk that overshadows the positive indicators. A balanced conclusion is that the plugin has strengths in its SQL practices and vulnerability history, but its significant number of unprotected AJAX endpoints demands immediate attention to mitigate potential security risks.
Key Concerns
- Unprotected AJAX handlers
- Limited taint analysis coverage
- External HTTP requests present
- File operations present
Tap To Donate for GiveWP by Jovvie Security Vulnerabilities
Tap To Donate for GiveWP by Jovvie Code Analysis
Output Escaping
Tap To Donate for GiveWP by Jovvie Attack Surface
AJAX Handlers 6
WordPress Hooks 79
Maintenance & Trust
Tap To Donate for GiveWP by Jovvie Maintenance & Trust
Maintenance Signals
Community Trust
Tap To Donate for GiveWP by Jovvie Alternatives
WooCommerce Stripe Payment Gateway
woocommerce-gateway-stripe
Accept debit and credit cards in 135+ currencies, many local methods like Alipay, ACH, and SEPA, and express checkout with Apple Pay and Google Pay.
PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin
pretty-link
🌠 The best WordPress link management, branding, tracking, sharing and payments plugin. Easily make pretty & trackable shortlinks. 🔗
Payment Plugins for Stripe WooCommerce
woo-stripe-payment
Accept Credit Cards, Google Pay, ApplePay, Afterpay, Affirm, ACH, Klarna, iDEAL and more all in one plugin for free!
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments
surecart
Make ecommerce easy with a simple to use, all-in-one platform, that anyone can set up in just a few minutes!
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
easy-digital-downloads
The #1 eCommerce plugin to sell digital products & subscriptions. Accept credit card payments with Stripe & PayPal and start your store today.
Tap To Donate for GiveWP by Jovvie Developer Profile
7 plugins · 3K total installs
How We Detect Tap To Donate for GiveWP by Jovvie
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jovvie-in-person-payments-givewp/assets/js/gateway.js/wp-content/plugins/jovvie-in-person-payments-givewp/assets/js/gateway.jsjovvie-in-person-payments-givewp/assets/js/gateway.js?ver=