
Philantro – Donations and Donor Management Security & Risk Analysis
wordpress.org/plugins/philantroSecurely accept one-time and recurring donations with automated donor records, analytics and fundraising campaign tracking.
Is Philantro – Donations and Donor Management Safe to Use in 2026?
Generally Safe
Score 99/100Philantro – Donations and Donor Management has a strong security track record. Known vulnerabilities have been patched promptly.
The "philantro" plugin version 5.4.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a lack of dangerous functions, no file operations, no external HTTP requests, and all SQL queries are properly prepared, indicating good practices in these areas. However, there are significant concerns regarding output escaping, with only 60% of outputs being properly escaped, leaving the remaining 40% potentially vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the plugin has a history of two medium-severity Cross-Site Scripting vulnerabilities, with the most recent occurring in early 2025. Although currently patched, this history suggests a recurring weakness in input sanitization and output encoding practices, which aligns with the observed partial output escaping.
The plugin's attack surface is primarily driven by 14 shortcodes, none of which are explicitly flagged as unprotected in the static analysis. However, the absence of explicit nonce and capability checks for these entry points is a significant concern, as it implies that any user, regardless of their role or authentication status, could potentially trigger actions via these shortcodes. This lack of access control, combined with the potential for unescaped output, creates a notable risk profile. While the absence of critical taint flows is reassuring, the documented history of XSS vulnerabilities and the observed lack of comprehensive output escaping and access control on shortcodes indicate that the plugin requires further security hardening to mitigate these risks effectively.
Key Concerns
- Medium severity XSS vulnerabilities in history
- Incomplete output escaping (40% unescaped)
- No nonce checks on entry points (shortcodes)
- No capability checks on entry points (shortcodes)
Philantro – Donations and Donor Management Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Philantro – Donations and Donor Management <= 5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via donate Shortcode
Philantro – Donations and Donor Management <= 5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Philantro – Donations and Donor Management Code Analysis
Output Escaping
Philantro – Donations and Donor Management Attack Surface
Shortcodes 14
WordPress Hooks 11
Maintenance & Trust
Philantro – Donations and Donor Management Maintenance & Trust
Maintenance Signals
Community Trust
Philantro – Donations and Donor Management Alternatives
FundCollector – Donations Plugin and Fundraising Platform for WordPress
fundcollector
Easily receive donations on your website. Accept payments made with PayPal. For bank transfers, it automatically sends payment instructions via email.
Donorbox – Free Recurring Donation Plugin and Fundraising Platform
donorbox-donation-form
Donorbox is a powerful and secure donation management plugin for WordPress. We are the only donation plugin for WordPress that offers a fast feature-f …
FundPress – WordPress Donation Plugin
fundpress
Easily build your own crowdfunding platform like Kickstarter with this free WordPress donation plugin in just a few clicks. No coding required.
Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms
kudos-donations
Add a donation button to any page on your website. Easy & fast setup. Works with Mollie payments.
Mightycause Donation Forms and Embeds
mightycause-widgets
Easily embed Mightycause donation buttons, widgets, or forms on your WordPress website with no coding required.
Philantro – Donations and Donor Management Developer Profile
1 plugin · 60 total installs
How We Detect Philantro – Donations and Donor Management
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/philantro/css/philantro.css/wp-content/plugins/philantro/css/philantro-editor.cssHTML / DOM Fingerprints
philantro-btnphilantro-lovephilantro-progressdata-campaigndata-formdata-colordata-affiliatedata-eventdata-button<a data-campaign=<div id="ph-root" data-form=<div id="ph-root" data-campaign=<div class="philantro-love"><a href="#_givealways"