MG – Instamojo for GiveWP Security & Risk Analysis

wordpress.org/plugins/mg-instamojo-for-give

Accept donations with GiveWP using Instamojo payment gateway in India.

10 active installs v1.0.0 PHP 5.6+ WP 4.8+ Updated Mar 28, 2023
donationsfundraisinggivewpinstamojo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MG – Instamojo for GiveWP Safe to Use in 2026?

Generally Safe

Score 85/100

MG – Instamojo for GiveWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'mg-instamojo-for-give' plugin version 1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of any detected attack surface points, dangerous functions, or taint flows with unsanitized paths suggests a robust development approach to secure coding. Furthermore, the plugin demonstrates good practices by exclusively using prepared statements for its SQL queries and properly escaping all output, minimizing common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The lack of any historical vulnerabilities or known CVEs further reinforces this positive assessment, indicating a history of secure development and maintenance.

However, a key area of concern is the complete absence of nonce checks and capability checks. While the static analysis shows no unprotected entry points, the lack of these fundamental security mechanisms means that if any new entry points were introduced or if the current ones are not as thoroughly secured as the analysis suggests, there would be no inherent protection against CSRF attacks or unauthorized actions by less privileged users. The presence of two external HTTP requests also warrants careful examination to ensure they are implemented securely and do not introduce risks related to data exposure or injection.

In conclusion, 'mg-instamojo-for-give' v1.0.0 appears to be a secure plugin with sound coding practices for SQL and output handling. Its vulnerability history is excellent. The primary weakness lies in the oversight of implementing nonce and capability checks, which are crucial for comprehensive WordPress security. A thorough review of the external HTTP requests is also recommended.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

MG – Instamojo for GiveWP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

MG – Instamojo for GiveWP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped3 total outputs
Attack Surface

MG – Instamojo for GiveWP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actiongive_payment_view_detailssrc\Admin\Actions.php:25
actiongive_admin_field_cta_noticesrc\Admin\Settings.php:29
filtergive_get_sections_gatewayssrc\Admin\Settings.php:30
filtergive_get_settings_gatewayssrc\Admin\Settings.php:31
actiongive_gateway_instamojo_checkoutsrc\Includes\Actions.php:27
actiongive_instamojo_checkout_cc_formsrc\Includes\Actions.php:28
actiongive_donation_form_after_emailsrc\Includes\Actions.php:29
filtergive_donation_form_required_fieldssrc\Includes\Actions.php:30
actionwp_enqueue_scriptssrc\Includes\Actions.php:31
actioninitsrc\Includes\Actions.php:32
filtergive_payment_gatewayssrc\Includes\Filters.php:25
actionplugins_loadedsrc\Plugin.php:33
actioninitsrc\Plugin.php:36
Maintenance & Trust

MG – Instamojo for GiveWP Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMar 28, 2023
PHP min version5.6
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

MG – Instamojo for GiveWP Developer Profile

Mehul Gohil

5 plugins · 220 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MG – Instamojo for GiveWP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mg-instamojo-for-give/dist/css/frontend.css/wp-content/plugins/mg-instamojo-for-give/dist/js/frontend.js
Version Parameters
mg-instamojo-for-give/dist/css/frontend.css?ver=mg-instamojo-for-give/dist/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
give-labelgive-required-indicatorgive-tooltipgive-icongive-icon-questiongive-inputrequired
Data Attributes
data-tooltip
Shortcode Output
<p id="give-phone-wrap" class="form-row form-row-wide"><label class="give-label" for="give-phone"><span class="give-required-indicator">*</span><span class="give-tooltip give-icon give-icon-question" data-tooltip="
FAQ

Frequently Asked Questions about MG – Instamojo for GiveWP