
Send Your Prayers Security & Risk Analysis
wordpress.org/plugins/send-your-prayersA prayer submission system with one-time payments.
Is Send Your Prayers Safe to Use in 2026?
Generally Safe
Score 100/100Send Your Prayers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "send-your-prayers" v1.6.2 plugin exhibits a mixed security posture. While the absence of known vulnerabilities and a relatively low percentage of SQL queries without prepared statements are positive indicators, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers without authentication checks, creating a direct attack vector for unauthorized actions. Furthermore, the taint analysis reveals four high-severity flows with unsanitized paths, suggesting potential for cross-site scripting (XSS) or other injection vulnerabilities if user-supplied data is not properly handled. The high percentage of unsanitized paths in taint flows (7 out of 7 analyzed) is particularly worrying and points to a systemic issue in data validation or sanitization within the plugin's code.
Despite the lack of a documented vulnerability history, the presence of critical security signals in the static and taint analysis should not be overlooked. The absence of CVEs could indicate a lack of prior security auditing or that these vulnerabilities have simply not been discovered or publicly disclosed yet. The plugin demonstrates some good practices, such as a decent number of nonce and capability checks, and a majority of its SQL queries using prepared statements. However, the identified unprotected entry points and high-severity taint flows represent significant weaknesses that require immediate attention.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows with unsanitized paths
- All taint flows have unsanitized paths
- Output escaping is not fully implemented
Send Your Prayers Security Vulnerabilities
Send Your Prayers Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Send Your Prayers Attack Surface
AJAX Handlers 6
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
Send Your Prayers Maintenance & Trust
Maintenance Signals
Community Trust
Send Your Prayers Alternatives
Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More
better-payment
Better Payment allows you to automate payment transactions to manage payments, donations, subscriptions, sell products, etc on your Elementor website.
Contact Form 7 – PayPal & Stripe Add-on
contact-form-7-paypal-add-on
Easily add PayPal and Stripe to Contact Form 7. Accept credit card payments with Stripe & PayPal on your site today. Offical PayPal & Stripe Partner.
Payment forms, Buy now buttons, and Invoicing System | GetPaid
invoicing
Payments & Invoicing plugin for WordPress to quickly and easily sell online. Create Buy Now buttons or inline checkout forms in seconds to accept …
PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net)
peachpay-for-woocommerce
Connect and manage all your payment methods, offer shoppers a beautiful Express Checkout, and reduce cart abandonment.
Church Tithe WP
churchtithewp
Smoothly, easily, and quickly accepting online tithes and donations is an important thing for every church today. Church Tithe WP makes it simple for …
Send Your Prayers Developer Profile
20 plugins · 140K total installs
How We Detect Send Your Prayers
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/send-your-prayers/assets/css/style.css/wp-content/plugins/send-your-prayers/assets/js/script.jshttps://js.stripe.com/v3/send-your-prayers/assets/css/style.css?ver=send-your-prayers/assets/js/script.js?ver=HTML / DOM Fingerprints
data-syprayer-paypal-button-idsyprayer_ajax[send_your_prayers][syprayer_thank_you]