
Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms Security & Risk Analysis
wordpress.org/plugins/kudos-donationsAdd a donation button to any page on your website. Easy & fast setup. Works with Mollie payments.
Is Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms Safe to Use in 2026?
Generally Safe
Score 97/100Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms has a strong security track record. Known vulnerabilities have been patched promptly.
The 'kudos-donations' v4.1.6 plugin exhibits a generally positive security posture, with a strong emphasis on secure coding practices. The static analysis reveals a very small attack surface consisting of a single shortcode, with no unprotected entry points identified. The code demonstrates good utilization of prepared statements for SQL queries (80%) and excellent output escaping (98%). The presence of numerous nonce and capability checks further indicates a commitment to security. However, the plugin does have a history of known vulnerabilities, including one high and two medium severity issues, primarily related to Cross-Site Scripting and Cross-Site Request Forgery. While there are currently no unpatched vulnerabilities, this history suggests a recurring pattern of susceptibility to input manipulation and unauthorized action, necessitating ongoing vigilance. The presence of 'dompdf' as a bundled library, while potentially useful, could represent a risk if not kept up-to-date, though no specific outdated library issues were flagged in the static analysis.
Key Concerns
- High severity known CVE history
- Medium severity known CVE history (x2)
- Bundled library (dompdf) potential risk
- Taint analysis shows unsanitized paths
Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Kudos Donations – Easy donations and payments with Mollie <= 3.2.9 - Reflected Cross-Site Scripting via 'add_query_arg'
Kudos Donations – Easy donations and payments with Mollie <= 3.2.9 - Reflected Cross-Site Scripting
Kudos Donations – Easy donations and payments with Mollie < 3.1.2 - Cross-Site Request Forgery
Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms Attack Surface
Shortcodes 1
WordPress Hooks 28
Maintenance & Trust
Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms Maintenance & Trust
Maintenance Signals
Community Trust
Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms Alternatives
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
charitable
The best WordPress donation plugin. Create fundraising donation forms, accept recurring donations, easy donor management, add crowdfunding, and more.
Donation Platform for WooCommerce: Fundraising & Donation Management
wc-donation-platform
Open source donation system for your fundraising that supports recurring donations and more
Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More
better-payment
Better Payment allows you to automate payment transactions to manage payments, donations, subscriptions, sell products, etc on your Elementor website.
Leyka
leyka
Leyka is a plugin for crowdfunding and donations collection via WordPress website.
Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms Developer Profile
1 plugin · 100 total installs
How We Detect Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kudos-donations/assets/css/admin/kudos-admin.css/wp-content/plugins/kudos-donations/assets/js/admin/kudos-admin.js/wp-content/plugins/kudos-donations/assets/css/front/kudos-fonts.css/wp-content/plugins/kudos-donations/assets/js/front/block/kudos-front.js/wp-content/plugins/kudos-donations/assets/js/front/block/index.js/wp-content/plugins/kudos-donations/assets/css/front/block/kudos-front.css/wp-content/plugins/kudos-donations/assets/js/admin/kudos-admin.js/wp-content/plugins/kudos-donations/assets/js/front/block/kudos-front.js/wp-content/plugins/kudos-donations/assets/js/front/block/index.jskudos-donations/assets/css/admin/kudos-admin.css?ver=kudos-donations/assets/js/admin/kudos-admin.js?ver=kudos-donations/assets/css/front/kudos-fonts.css?ver=kudos-donations/assets/js/front/block/kudos-front.js?ver=kudos-donations/assets/js/front/block/index.js?ver=kudos-donations/assets/css/front/block/kudos-front.css?ver=HTML / DOM Fingerprints
kudos-admin-pagedata-titledata-viewkudos