
Project Donations Security & Risk Analysis
wordpress.org/plugins/project-donationsHave some projects you'd like to fund? This plugin allows you to publish projects that accept donations from paypal. It even includes enough feat …
Is Project Donations Safe to Use in 2026?
Generally Safe
Score 85/100Project Donations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "project-donations" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. The plugin has a minimal attack surface, with only one shortcode identified as an entry point, and importantly, no unprotected AJAX handlers or REST API routes. The absence of known CVEs in its history further contributes to this positive assessment. However, there are critical areas for improvement. The plugin entirely lacks nonce and capability checks, meaning that even its single entry point is not protected against common WordPress attack vectors like Cross-Site Request Forgery (CSRF) or unauthorized access. Additionally, the sole SQL query is not using prepared statements, which introduces a significant risk of SQL injection vulnerabilities. While the taint analysis shows no current flows with unsanitized paths, the presence of raw SQL and the absence of capability/nonce checks mean that introducing such a flow in a future update would be highly dangerous.
Key Concerns
- SQL query without prepared statements
- No nonce checks
- No capability checks
- Half of outputs not properly escaped
Project Donations Security Vulnerabilities
Project Donations Release Timeline
Project Donations Code Analysis
SQL Query Safety
Output Escaping
Project Donations Attack Surface
Shortcodes 1
WordPress Hooks 21
Maintenance & Trust
Project Donations Maintenance & Trust
Maintenance Signals
Community Trust
Project Donations Alternatives
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
Donations via PayPal
paypal-donations
Easy, simple setup to add a PayPal Donation button as a Widget or with a shortcode.
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
charitable
The best WordPress donation plugin. Create fundraising donation forms, accept recurring donations, easy donor management, add crowdfunding, and more.
Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More
better-payment
Better Payment allows you to automate payment transactions to manage payments, donations, subscriptions, sell products, etc on your Elementor website.
Leyka
leyka
Leyka is a plugin for crowdfunding and donations collection via WordPress website.
Project Donations Developer Profile
4 plugins · 630 total installs
How We Detect Project Donations
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/project-donations/css/project-donations-admin.css/wp-content/plugins/project-donations/js/project-donations-admin.js/wp-content/plugins/project-donations/js/project-donations-admin.jsproject-donations-admin.css?ver=project-donations-admin.js?ver=