
OrgHunter Security & Risk Analysis
wordpress.org/plugins/orghunterCharity Search and Charity Donation Plugin. Add 2.1 million US charities to your WordPress site instantly. America’s most trusted charity resource!
Is OrgHunter Safe to Use in 2026?
Generally Safe
Score 85/100OrgHunter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The orghunter plugin v1.1.1 exhibits a mixed security posture. On the positive side, the plugin has a notably small attack surface with no registered AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all identified SQL queries are properly prepared, indicating good database hygiene. The plugin also shows no history of reported vulnerabilities, which is a strong indicator of past security diligence.
However, there are significant areas of concern highlighted by the static analysis. The most critical finding is the presence of two taint flows with unsanitized paths, even though they are not classified as critical or high severity. This suggests potential for local file inclusion or other path-based vulnerabilities that could be exploited if these flows are triggered by user input. Additionally, a low percentage (22%) of output is properly escaped, indicating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, especially since no nonce checks or capability checks are implemented on any potential entry points, which don't appear to exist based on the provided attack surface data.
In conclusion, while the plugin's minimal attack surface and secure SQL practices are commendable, the high rate of unescaped output and the presence of unsanitized path flows represent significant security weaknesses. The lack of any historical vulnerabilities should be viewed cautiously, as it might be a reflection of limited security auditing rather than proven invulnerability. Further investigation into the taint flows and output escaping is strongly recommended.
Key Concerns
- Unsanitized path taint flows
- Low percentage of properly escaped output
- No nonce checks implemented
- No capability checks implemented
OrgHunter Security Vulnerabilities
OrgHunter Code Analysis
Output Escaping
Data Flow Analysis
OrgHunter Attack Surface
WordPress Hooks 6
Maintenance & Trust
OrgHunter Maintenance & Trust
Maintenance Signals
Community Trust
OrgHunter Alternatives
Make My Donation – In Memory Of Platform
makemydonation-imo
Integrate your funeral home site with our Make My Donation - In Memory Of Platform and allow donations to over 1.5 million eligible US charities.
Accept Donations with PayPal & Stripe
easy-paypal-donation
Add a PayPal or Stripe Donation Button to your website and start collecting donations today. No Coding Required. Official PayPal & Stripe Partner.
Donation Platform for WooCommerce: Fundraising & Donation Management
wc-donation-platform
Open source donation system for your fundraising that supports recurring donations and more
Charity Addon for Elementor
charity-addon-for-elementor
Charity Addon for Elementor is an Elementor Addons for Charity Websites.
ActBlue Contributions
actblue-contributions
Easily embed your ActBlue contribution forms on any WordPress page. Designed and built by Upstatement.
OrgHunter Developer Profile
2 plugins · 30 total installs
How We Detect OrgHunter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/orghunter/orghunter-charity-search.cssorghunter-charity-search.css?ver=HTML / DOM Fingerprints
orghunter-charity-search-resultsdata-orghunter-charity-search-idwindow.orghunter_charity_search