
Donations via PayPal Security & Risk Analysis
wordpress.org/plugins/paypal-donationsEasy, simple setup to add a PayPal Donation button as a Widget or with a shortcode.
Is Donations via PayPal Safe to Use in 2026?
Generally Safe
Score 100/100Donations via PayPal has a strong security track record. Known vulnerabilities have been patched promptly.
The paypal-donations plugin v1.9.11 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, exclusively using prepared statements, and its static analysis shows no critical or high severity taint flows. The limited attack surface, with only one shortcode and no unprotected entry points, is also encouraging. However, a significant concern is the low percentage of properly escaped output (28%), which suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks, particularly for the shortcode which represents the sole entry point, further exacerbates this risk, as it implies any authenticated user could potentially trigger unintended actions or inject malicious scripts.
The plugin's vulnerability history reveals a past medium-severity XSS vulnerability, which aligns with the output escaping concerns identified in the static analysis. While there are no currently unpatched CVEs, the recurring nature of XSS vulnerabilities and the lack of robust input validation (nonces and capability checks) on its primary entry point indicate an ongoing risk. The plugin appears to rely on external sanitization or WordPress's default protections for its output, which is insufficient for robust security. The presence of file operations and external HTTP requests, while not flagged as problematic in this analysis, warrants attention in a broader security review due to their potential for exploitation if not handled securely.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
- Past medium XSS vulnerability
Donations via PayPal Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Donations via PayPal <= 1.9.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
Donations via PayPal Code Analysis
Output Escaping
Donations via PayPal Attack Surface
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Donations via PayPal Maintenance & Trust
Maintenance Signals
Community Trust
Donations via PayPal Alternatives
Donations Widget
donations
Accept donations from your readers via AlertPay, Moneybookers and/or PayPal.
Paypal Target Meter
paypal-target-meter
display a progress meter of donations towards a monthly or yearly goal
GiveWP Donation Widgets for Elementor
givewp-donation-widgets-for-elementor
A GiveWP add-on which allows you to embed any GiveWP shortcode into your Elementor-powered pages.
Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More
better-payment
Better Payment allows you to automate payment transactions to manage payments, donations, subscriptions, sell products, etc on your Elementor website.
Cryptocurrency Widgets For Elementor
cryptocurrency-widgets-for-elementor
Easily display cryptocurrency prices and generate customizable widgets for 250+ coins, including Bitcoin, Ethereum, and more in Elementor.
Donations via PayPal Developer Profile
15 plugins · 210K total installs
How We Detect Donations via PayPal
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/paypal-donations/js/donate.js/wp-content/plugins/paypal-donations/css/donate.css/wp-content/plugins/paypal-donations/js/donate.jspaypal-donations/css/donate.css?ver=paypal-donations/js/donate.js?ver=HTML / DOM Fingerprints
paypal-donationsPayPalDonations[paypal-donation]