Saphali LiqPay for donate Security & Risk Analysis

wordpress.org/plugins/saphali-liqpay-for-donate

Кнопка для приема пожертвований с помощью LiqPay (v 3.0). Работа заключается в добавлении шорткода на страницу при ее редактировании (добавляется нажа …

30 active installs v1.0.3 PHP + WP 3.3+ Updated Nov 6, 2025
donateliqpaysaphaliwoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 7, 2025
Safety Verdict

Is Saphali LiqPay for donate Safe to Use in 2026?

Generally Safe

Score 99/100

Saphali LiqPay for donate has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 7, 2025Updated 4mo ago
Risk Assessment

The "saphali-liqpay-for-donate" plugin v1.0.3 exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and having a single nonce check, significant concerns arise from its attack surface. Specifically, two AJAX handlers lack authentication checks, presenting a clear entry point for unauthorized actions. The plugin also has a history of medium severity vulnerabilities, with a past Cross-Site Scripting (XSS) issue, indicating a recurring tendency for input sanitization and output escaping to be potential weak points.

Despite the absence of critical or high severity issues in the current static analysis and a lack of currently unpatched CVEs, the unprotected AJAX handlers are a serious risk. The 74% output escaping rate, while not critically low, suggests that some outputs may still be vulnerable to XSS if certain conditions are met. The presence of an external HTTP request, while not inherently dangerous, warrants attention in conjunction with other identified weaknesses. Overall, the plugin's strengths in SQL handling are overshadowed by its unprotected entry points and a history of vulnerabilities that require careful consideration and ongoing monitoring.

Key Concerns

  • Unprotected AJAX handlers found
  • Partial output escaping (74%)
  • History of medium severity CVEs (XSS)
Vulnerabilities
1

Saphali LiqPay for donate Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-12643medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Saphali LiqPay for donate <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Nov 7, 2025 Patched in 1.0.3 (1d)
Code Analysis
Analyzed Mar 16, 2026

Saphali LiqPay for donate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
17 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

74% escaped23 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<liqpay-d> (liqpay-d.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Saphali LiqPay for donate Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_liqpay_signliqpay-d.php:27
noprivwp_ajax_liqpay_signliqpay-d.php:28

Shortcodes 1

[saphali_liqpay] liqpay-d.php:24
WordPress Hooks 7
actioninitliqpay-d.php:23
actionwp_enqueue_scriptsliqpay-d.php:25
actionadmin_enqueue_scriptsliqpay-d.php:26
actionadmin_menuliqpay-d.php:38
actionadmin_initliqpay-d.php:39
filtermce_external_pluginsliqpay-d.php:300
filtermce_buttonsliqpay-d.php:301
Maintenance & Trust

Saphali LiqPay for donate Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 6, 2025
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Saphali LiqPay for donate Developer Profile

Saphali

3 plugins · 10K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
91 days
View full developer profile
Detection Fingerprints

How We Detect Saphali LiqPay for donate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
saphali-liqpay-for-donate/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
form__input__new
Data Attributes
data-amountdata-order_iddata-signature
Shortcode Output
<form id="liqpayform" method="POST" action="https://www.liqpay.ua/api/checkout" accept-charset="utf-8"><input type="hidden" name="data" value="<input type="text" class="form__input__new" name="amount" value="
FAQ

Frequently Asked Questions about Saphali LiqPay for donate