Klaive – Integrates Klaviyo with Give Security & Risk Analysis

wordpress.org/plugins/klaive

This plugin will be used to integrate Klaviyo with GiveWP WordPress donation plugin.

0 active installs v1.0.1 PHP 7.0+ WP 5.2+ Updated Unknown
donationdonationsgivegivewpklaviyo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Klaive – Integrates Klaviyo with Give Safe to Use in 2026?

Generally Safe

Score 100/100

Klaive – Integrates Klaviyo with Give has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The klaive plugin version 1.0.1 demonstrates a generally positive security posture, with no known historical vulnerabilities and a code base that appears to largely follow good security practices. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong indicator of secure coding. The plugin also has a single entry point (AJAX handler) that is protected by a capability check, further mitigating risks.

However, there are a few areas that warrant attention. The 0% proper escaping for over half of its output points to a potential risk of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis found no unsanitized flows, the lack of comprehensive output escaping in a significant portion of the code could still allow for reflected or stored XSS if user-supplied data is not properly sanitized before being displayed. The plugin also makes two external HTTP requests, which, while not explicitly flagged as dangerous here, can sometimes introduce vulnerabilities if the external endpoints are compromised or if the requests are not handled securely.

Overall, klaive v1.0.1 is in a strong security position due to its lack of known vulnerabilities and good handling of critical security areas like SQL and file operations. The primary concern lies with the insufficient output escaping, which could lead to XSS issues. The presence of external HTTP requests also suggests a minor area for review to ensure they are implemented with robust security measures.

Key Concerns

  • High percentage of unescaped output
  • External HTTP requests present
Vulnerabilities
None known

Klaive – Integrates Klaviyo with Give Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Klaive – Integrates Klaviyo with Give Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
17 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

61% escaped28 total outputs
Attack Surface

Klaive – Integrates Klaviyo with Give Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_klaive_refresh_listssrc\Admin\Actions.php:36
WordPress Hooks 10
actionadmin_enqueue_scriptssrc\Admin\Actions.php:34
actiongive_admin_field_klaviyo_select_listsrc\Admin\Actions.php:35
filtergive_metabox_form_data_settingssrc\Admin\Filters.php:36
filtergive_get_field_callbacksrc\Admin\Filters.php:38
filtergive_get_sections_addonssrc\Admin\Settings.php:33
filtergive_get_settings_addonssrc\Admin\Settings.php:34
actiongive_donation_form_before_submitsrc\Includes\Actions.php:34
actiongive_insert_paymentsrc\Includes\Actions.php:35
actionplugins_loadedsrc\Plugin.php:35
actioninitsrc\Plugin.php:38
Maintenance & Trust

Klaive – Integrates Klaviyo with Give Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedUnknown
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Klaive – Integrates Klaviyo with Give Developer Profile

Mehul Gohil

5 plugins · 220 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Klaive – Integrates Klaviyo with Give

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/klaive/assets/dist/css/admin.css/wp-content/plugins/klaive/assets/dist/js/admin.js
Script Paths
assets/dist/js/admin.js
Version Parameters
klaive-admin

HTML / DOM Fingerprints

CSS Classes
klaive-wrapped-fieldsklaive-wrapped-fields give-hidden
REST Endpoints
/wp-admin/admin-ajax.php?action=klaive_refresh_lists
FAQ

Frequently Asked Questions about Klaive – Integrates Klaviyo with Give