
Nonprofit Manager Security & Risk Analysis
wordpress.org/plugins/nonprofit-managerComprehensive nonprofit management solution for memberships, donations, newsletters, and events.
Is Nonprofit Manager Safe to Use in 2026?
Generally Safe
Score 100/100Nonprofit Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The nonprofit-manager plugin exhibits a generally good security posture, with a notable lack of known historical vulnerabilities and a strong implementation of nonces and capability checks. The static analysis reveals a moderate attack surface, with a few potential concerns. Specifically, two AJAX handlers are identified as lacking authentication checks, which presents a direct risk of unauthorized execution of functions. While the taint analysis did not identify critical or high-severity issues, the presence of flows with unsanitized paths, though not explicitly categorized as vulnerabilities in the provided data, warrants attention as a potential precursor to more serious issues if user input is not handled with utmost care.
The plugin's vulnerability history is a significant strength, indicating a proactive approach to security or a lack of exploitable flaws to date. However, the presence of unprotected AJAX endpoints, even without a documented exploit history, represents a tangible weakness. The static analysis also shows a reasonably high percentage of properly escaped output, which is positive, but the remaining percentage could still lead to XSS vulnerabilities. Overall, while the plugin is not riddled with critical flaws, the unprotected AJAX handlers are the most immediate concern requiring mitigation.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Output escaping not fully proper
Nonprofit Manager Security Vulnerabilities
Nonprofit Manager Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Nonprofit Manager Attack Surface
AJAX Handlers 8
Shortcodes 9
WordPress Hooks 58
Scheduled Events 1
Maintenance & Trust
Nonprofit Manager Maintenance & Trust
Maintenance Signals
Community Trust
Nonprofit Manager Alternatives
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages
convertkit
Build your email subscriber lists, send email marketing newsletters, sell more products and build your membership site with Kit (formerly ConvertKit).
Donorbox – Free Recurring Donation Plugin and Fundraising Platform
donorbox-donation-form
Donorbox is a powerful and secure donation management plugin for WordPress. We are the only donation plugin for WordPress that offers a fast feature-f …
Wild Apricot Login
wild-apricot-login
Provides single sign-on service for Wild Apricot members to provide access to restricted Wild Apricot content.
Birthday Emails
birthday-emails
Automatically send an email to WordPress or BuddyPress users on their birthday.
CiviEvent Widget
civievent-widget
Display widgets for CiviCRM events: the next public event or a whole list. Embed widgets as shortcodes, too!
Nonprofit Manager Developer Profile
2 plugins · 10 total installs
How We Detect Nonprofit Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nonprofit-manager/js/npmp-settings.js/wp-content/plugins/nonprofit-manager/js/npmp-dashboard.js/wp-content/plugins/nonprofit-manager/js/npmp-forms.js/wp-content/plugins/nonprofit-manager/js/npmp-members.js/wp-content/plugins/nonprofit-manager/js/npmp-calendar.js/wp-content/plugins/nonprofit-manager/css/npmp-admin.css/wp-content/plugins/nonprofit-manager/css/npmp-dashboard.css/wp-content/plugins/nonprofit-manager/css/npmp-calendar.css/wp-content/plugins/nonprofit-manager/js/npmp-settings.js/wp-content/plugins/nonprofit-manager/js/npmp-dashboard.js/wp-content/plugins/nonprofit-manager/js/npmp-forms.js/wp-content/plugins/nonprofit-manager/js/npmp-members.js/wp-content/plugins/nonprofit-manager/js/npmp-calendar.jsnonprofit-manager/js/npmp-settings.js?ver=nonprofit-manager/js/npmp-dashboard.js?ver=nonprofit-manager/js/npmp-forms.js?ver=nonprofit-manager/js/npmp-members.js?ver=nonprofit-manager/js/npmp-calendar.js?ver=nonprofit-manager/css/npmp-admin.css?ver=nonprofit-manager/css/npmp-dashboard.css?ver=nonprofit-manager/css/npmp-calendar.css?ver=HTML / DOM Fingerprints
npmp-settings-sectionnpmp-dashboard-widgetnpmp-form-fieldnpmp-member-rownpmp-calendar-event<!-- Main hub --><!-- General Settings - Always available --><!-- Membership --><!-- Newsletters -->+4 moredata-npmp-featuredata-npmp-iddata-npmp-typenpmp_settings_datanpmp_dashboard_datanpmp_members_datanpmp_calendar_data/wp-json/nonprofit-manager/v1/settings/wp-json/nonprofit-manager/v1/members/wp-json/nonprofit-manager/v1/donations[nonprofit_manager_membership_form][nonprofit_manager_donation_form][nonprofit_manager_event_calendar]