MYFUNDBOX – Recurring payments for Donation Form Security & Risk Analysis

wordpress.org/plugins/myfundbox-recurring-payments-for-donation-form

Reliable and secure donation Management plugin.With MYFUNDBOX you can transform the way you accept online donations.

10 active installs v1.0 PHP + WP + Updated Nov 13, 2020
donationformfundraising-crmmultiple-payment-providersone-timerecurring
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MYFUNDBOX – Recurring payments for Donation Form Safe to Use in 2026?

Generally Safe

Score 85/100

MYFUNDBOX – Recurring payments for Donation Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "myfundbox-recurring-payments-for-donation-form" plugin v1.0 exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and a high percentage of properly escaped output, there are significant concerns regarding its attack surface. The presence of two AJAX handlers without authentication checks represents a direct pathway for potential unauthorized actions or information disclosure. The taint analysis, although revealing no critical or high-severity issues, did identify flows with unsanitized paths, which, when combined with the unprotected AJAX endpoints, could lead to vulnerabilities if malicious data is passed through these entry points.

The plugin's vulnerability history is a strong positive, with no recorded CVEs, suggesting a generally secure development history. However, the absence of vulnerabilities in the past does not guarantee future security. The identified unprotected entry points are the primary concern in this analysis. The lack of nonce and capability checks on these AJAX handlers is particularly worrying and could be exploited by attackers to perform actions on behalf of logged-in users or to inject malicious data.

In conclusion, while the plugin has strengths in its SQL handling and output escaping, the unprotected AJAX endpoints present a clear and present risk. The taint analysis further highlights the potential for issues arising from unsanitized data entering these unprotected points. Addressing these unprotected entry points should be the highest priority for improving the plugin's security.

Key Concerns

  • AJAX handlers without auth checks
  • Unsanitized paths in taint analysis
  • Lack of nonce checks on AJAX
  • Lack of capability checks
Vulnerabilities
None known

MYFUNDBOX – Recurring payments for Donation Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

MYFUNDBOX – Recurring payments for Donation Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
40 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

74% escaped54 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
myfundbox_settings_fn (myfundbox-recurring-payments-for-donation-form.php:238)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

MYFUNDBOX – Recurring payments for Donation Form Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_myfundbox_ajax_shortcodemyfundbox-recurring-payments-for-donation-form.php:369
noprivwp_ajax_myfundbox_ajax_shortcodemyfundbox-recurring-payments-for-donation-form.php:370

Shortcodes 1

[MYFUNDBOX_cause_status] myfundbox-recurring-payments-for-donation-form.php:541
WordPress Hooks 11
actionplugins_loadedmyfundbox-recurring-payments-for-donation-form.php:16
actionadmin_menumyfundbox-recurring-payments-for-donation-form.php:25
filtermanage_project_posts_columnsmyfundbox-recurring-payments-for-donation-form.php:32
actionmanage_project_posts_custom_columnmyfundbox-recurring-payments-for-donation-form.php:51
actioninitmyfundbox-recurring-payments-for-donation-form.php:64
actionadmin_initmyfundbox-recurring-payments-for-donation-form.php:88
actionadmin_enqueue_scriptsmyfundbox-recurring-payments-for-donation-form.php:155
actionsave_postmyfundbox-recurring-payments-for-donation-form.php:209
actionwp_enqueue_scriptsmyfundbox-recurring-payments-for-donation-form.php:222
actionadmin_enqueue_scriptsmyfundbox-recurring-payments-for-donation-form.php:236
actioninitmyfundbox-recurring-payments-for-donation-form.php:594
Maintenance & Trust

MYFUNDBOX – Recurring payments for Donation Form Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedNov 13, 2020
PHP min version
Downloads965

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

MYFUNDBOX – Recurring payments for Donation Form Developer Profile

myfundbox

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MYFUNDBOX – Recurring payments for Donation Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/bootstrap/bootstrap.min.css/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/css/myfunbox_style.css/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/js/myfundbox-admin.js
Script Paths
/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/js/myfundbox-admin.js
Version Parameters
/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/bootstrap/bootstrap.min.css?ver=/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/css/myfunbox_style.css?ver=/wp-content/plugins/myfundbox-recurring-payments-for-donation-form/js/myfundbox-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
myfundbox_upload_image_buttonmyfundbox_remove_image_button
Data Attributes
name="web_hook"name="project_s_id"name="s_project_id"id="my_fav_team_id"id="my_project_causes_id"
Shortcode Output
[MYFUNDBOX_cause_status post_id=
FAQ

Frequently Asked Questions about MYFUNDBOX – Recurring payments for Donation Form