
MYFUNDBOX – Recurring payments for Donation Form Security & Risk Analysis
wordpress.org/plugins/myfundbox-recurring-payments-for-donation-formReliable and secure donation Management plugin.With MYFUNDBOX you can transform the way you accept online donations.
Is MYFUNDBOX – Recurring payments for Donation Form Safe to Use in 2026?
Generally Safe
Score 85/100MYFUNDBOX – Recurring payments for Donation Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "myfundbox-recurring-payments-for-donation-form" plugin v1.0 exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and a high percentage of properly escaped output, there are significant concerns regarding its attack surface. The presence of two AJAX handlers without authentication checks represents a direct pathway for potential unauthorized actions or information disclosure. The taint analysis, although revealing no critical or high-severity issues, did identify flows with unsanitized paths, which, when combined with the unprotected AJAX endpoints, could lead to vulnerabilities if malicious data is passed through these entry points.
The plugin's vulnerability history is a strong positive, with no recorded CVEs, suggesting a generally secure development history. However, the absence of vulnerabilities in the past does not guarantee future security. The identified unprotected entry points are the primary concern in this analysis. The lack of nonce and capability checks on these AJAX handlers is particularly worrying and could be exploited by attackers to perform actions on behalf of logged-in users or to inject malicious data.
In conclusion, while the plugin has strengths in its SQL handling and output escaping, the unprotected AJAX endpoints present a clear and present risk. The taint analysis further highlights the potential for issues arising from unsanitized data entering these unprotected points. Addressing these unprotected entry points should be the highest priority for improving the plugin's security.
Key Concerns
- AJAX handlers without auth checks
- Unsanitized paths in taint analysis
- Lack of nonce checks on AJAX
- Lack of capability checks
MYFUNDBOX – Recurring payments for Donation Form Security Vulnerabilities
MYFUNDBOX – Recurring payments for Donation Form Code Analysis
Output Escaping
Data Flow Analysis
MYFUNDBOX – Recurring payments for Donation Form Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
MYFUNDBOX – Recurring payments for Donation Form Maintenance & Trust
Maintenance Signals
Community Trust
MYFUNDBOX – Recurring payments for Donation Form Alternatives
Zoho Billing – Embed Payment Form
zoho-subscriptions
Embed payment forms on your WordPress pages/posts without any coding.
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce
hurrytimer
Create unlimited urgency and scarcity countdown timers for WordPress and WooCommerce to boost conversions and sales instantly.
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
charitable
The best WordPress donation plugin. Create fundraising donation forms, accept recurring donations, easy donor management, add crowdfunding, and more.
Donation Platform for WooCommerce: Fundraising & Donation Management
wc-donation-platform
Open source donation system for your fundraising that supports recurring donations and more
MYFUNDBOX – Recurring payments for Donation Form Developer Profile
1 plugin · 10 total installs
How We Detect MYFUNDBOX – Recurring payments for Donation Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/bootstrap/bootstrap.min.css/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/css/myfunbox_style.css/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/js/myfundbox-admin.js/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/js/myfundbox-admin.js/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/bootstrap/bootstrap.min.css?ver=/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/css/myfunbox_style.css?ver=/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/js/myfundbox-admin.js?ver=HTML / DOM Fingerprints
myfundbox_upload_image_buttonmyfundbox_remove_image_buttonname="web_hook"name="project_s_id"name="s_project_id"id="my_fav_team_id"id="my_project_causes_id"[MYFUNDBOX_cause_status post_id=