
Saphali LiqPay for donate Security & Risk Analysis
wordpress.org/plugins/saphali-liqpay-for-donateКнопка для приема пожертвований с помощью LiqPay (v 3.0). Работа заключается в добавлении шорткода на страницу при ее редактировании (добавляется нажа …
Is Saphali LiqPay for donate Safe to Use in 2026?
Generally Safe
Score 99/100Saphali LiqPay for donate has a strong security track record. Known vulnerabilities have been patched promptly.
The "saphali-liqpay-for-donate" plugin v1.0.3 exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and having a single nonce check, significant concerns arise from its attack surface. Specifically, two AJAX handlers lack authentication checks, presenting a clear entry point for unauthorized actions. The plugin also has a history of medium severity vulnerabilities, with a past Cross-Site Scripting (XSS) issue, indicating a recurring tendency for input sanitization and output escaping to be potential weak points.
Despite the absence of critical or high severity issues in the current static analysis and a lack of currently unpatched CVEs, the unprotected AJAX handlers are a serious risk. The 74% output escaping rate, while not critically low, suggests that some outputs may still be vulnerable to XSS if certain conditions are met. The presence of an external HTTP request, while not inherently dangerous, warrants attention in conjunction with other identified weaknesses. Overall, the plugin's strengths in SQL handling are overshadowed by its unprotected entry points and a history of vulnerabilities that require careful consideration and ongoing monitoring.
Key Concerns
- Unprotected AJAX handlers found
- Partial output escaping (74%)
- History of medium severity CVEs (XSS)
Saphali LiqPay for donate Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Saphali LiqPay for donate <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Saphali LiqPay for donate Code Analysis
Output Escaping
Data Flow Analysis
Saphali LiqPay for donate Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Saphali LiqPay for donate Maintenance & Trust
Maintenance Signals
Community Trust
Saphali LiqPay for donate Alternatives
Potent Donations for WooCommerce
donations-for-woocommerce
Easily accept donations of varying amounts through your WooCommerce store.
Payment Gateway for LiqPay for Woocommerce
wc-liqpay
Plugin for paying for products through the LiqPay service. Works in conjunction with the Woocommerce plugin
WebPlus Gateway for LiqPay on WooCommerce
webplus-liqpay-woocommerce
Плагин LiqPay для WooCommerce
LiqPay payment gateway for WooCommerce
wc-liqpay-payments
Plugin that adds supporting of LiqPay payment gateway to your WooCommerce store.
Easy LiqPay
easy-liqpay
Adding a form for receive donations use the LiqPay
Saphali LiqPay for donate Developer Profile
3 plugins · 10K total installs
How We Detect Saphali LiqPay for donate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
saphali-liqpay-for-donate/style.css?ver=HTML / DOM Fingerprints
form__input__newdata-amountdata-order_iddata-signature<form id="liqpayform" method="POST" action="https://www.liqpay.ua/api/checkout" accept-charset="utf-8"><input type="hidden" name="data" value="<input type="text" class="form__input__new" name="amount" value="