SKT Donation – Charity and Fundraising Plugin Security & Risk Analysis

wordpress.org/plugins/skt-donation

SKT Donation plugin has been created to facilitate donations for NGO, non profit, charity, charitable organizations, crowdfunding, fundraisers via pay …

200 active installs v2.2 PHP 7.4+ WP 5.6+ Updated Jul 12, 2025
donatefundraisingpaypalwordpress-donation-plugin
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 15, 2024
Download
Safety Verdict

Is SKT Donation – Charity and Fundraising Plugin Safe to Use in 2026?

Generally Safe

Score 99/100

SKT Donation – Charity and Fundraising Plugin has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 15, 2024Updated 8mo ago
Risk Assessment

The skt-donation plugin v2.2 demonstrates a generally strong security posture with a low attack surface and a high percentage of properly escaped outputs and nonce checks. The static analysis reveals no critical or high-severity taint flows, indicating good input sanitization practices. The plugin also incorporates capability checks and uses prepared statements for a significant portion of its SQL queries, which are positive indicators of secure coding. However, the presence of one medium-severity vulnerability in its history, specifically Cross-site Scripting, warrants attention. While currently patched, this historical pattern suggests that input validation, especially in how user-submitted data is displayed, could be a recurring area of concern that requires ongoing vigilance. The plugin's strengths lie in its controlled entry points and robust output escaping, but the past XSS vulnerability suggests a need for continued scrutiny in handling user-generated content.

Key Concerns

  • One medium CVE in vulnerability history
Vulnerabilities
1

SKT Donation – Charity and Fundraising Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-24535medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SKT Donation – Charity and Fundraising Plugin <= 1.9 - Reflected Cross-Site Scripting

Nov 15, 2024 Patched in 2.0 (98d)
Code Analysis
Analyzed Mar 16, 2026

SKT Donation – Charity and Fundraising Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
10
3 prepared
Unescaped Output
8
493 escaped
Nonce Checks
8
Capability Checks
2
File Operations
1
External Requests
5
Bundled Libraries
2

Bundled Libraries

DataTablesjQuery

SQL Query Safety

23% prepared13 total queries

Output Escaping

98% escaped501 total outputs
Data Flows
All sanitized

Data Flow Analysis

13 flows
skt_donation_add_paypalexpresssubscription_function (includes\addupdate_paypalexpress.php:2)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SKT Donation – Charity and Fundraising Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[skt-donation] includes\shortcodes.php:289
WordPress Hooks 11
actionadmin_menuincludes\delete-donation.php:6
actionadmin_initincludes\delete-donation.php:11
actionadmin_menuincludes\manage_currency.php:3
actionadmin_initincludes\manage_currency.php:8
actionadmin_menuincludes\settings-donation.php:6
actionadmin_initincludes\settings-donation.php:11
actionadmin_menuincludes\settings.php:6
actionadmin_initincludes\settings.php:11
actionwp_enqueue_scriptsskt-donation.php:242
actionadmin_enqueue_scriptsskt-donation.php:256
actionadmin_enqueue_scriptsskt-donation.php:266
Maintenance & Trust

SKT Donation – Charity and Fundraising Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 12, 2025
PHP min version7.4
Downloads10K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

SKT Donation – Charity and Fundraising Plugin Developer Profile

sonalsinha21

153 plugins · 54K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
26 days
View full developer profile
Detection Fingerprints

How We Detect SKT Donation – Charity and Fundraising Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/skt-donation/assets/css/bootstrap.min.css/wp-content/plugins/skt-donation/assets/css/datepicker.css/wp-content/plugins/skt-donation/assets/css/donate-style.css/wp-content/plugins/skt-donation/assets/css/font-awesome.min.css/wp-content/plugins/skt-donation/assets/css/jquery.ccpicker.css/wp-content/plugins/skt-donation/assets/css/magnific-popup.css/wp-content/plugins/skt-donation/assets/css/owl.carousel.css/wp-content/plugins/skt-donation/assets/css/style.css+11 more
Script Paths
/wp-content/plugins/skt-donation/assets/js/jquery.min.js/wp-content/plugins/skt-donation/assets/js/bootstrap.min.js/wp-content/plugins/skt-donation/assets/js/owl.carousel.js/wp-content/plugins/skt-donation/assets/js/owl.transitions.js/wp-content/plugins/skt-donation/assets/js/jquery.magnific-popup.min.js/wp-content/plugins/skt-donation/assets/js/bootstrap-datepicker.js+5 more
Version Parameters
/wp-content/plugins/skt-donation/assets/css/donate-style.css?ver=/wp-content/plugins/skt-donation/assets/css/bootstrap.min.css?ver=/wp-content/plugins/skt-donation/assets/css/font-awesome.min.css?ver=/wp-content/plugins/skt-donation/assets/css/datepicker.css?ver=/wp-content/plugins/skt-donation/assets/css/owl.carousel.css?ver=/wp-content/plugins/skt-donation/assets/css/style.css?ver=/wp-content/plugins/skt-donation/assets/css/magnific-popup.css?ver=/wp-content/plugins/skt-donation/assets/css/jquery.ccpicker.css?ver=/wp-content/plugins/skt-donation/assets/js/donate-form.js?ver=/wp-content/plugins/skt-donation/assets/js/custom.js?ver=/wp-content/plugins/skt-donation/assets/js/owl.transitions.js?ver=/wp-content/plugins/skt-donation/assets/js/owl.carousel.js?ver=/wp-content/plugins/skt-donation/assets/js/bootstrap-datepicker.js?ver=/wp-content/plugins/skt-donation/assets/js/jquery.magnific-popup.min.js?ver=/wp-content/plugins/skt-donation/assets/js/bootstrap.min.js?ver=/wp-content/plugins/skt-donation/assets/js/jquery.ccpicker.js?ver=/wp-content/plugins/skt-donation/js/skt-donate-admin.js?ver=/wp-content/plugins/skt-donation/js/jquery-ui.js?ver=

HTML / DOM Fingerprints

CSS Classes
skt-donation-wrapskt-donate-formskt-donation-mainskt-donation-titleskt-donation-detailskt-donation-amountskt-donation-pay-methodskt-donation-payment+17 more
HTML Comments
<!-- SKT Donation form --><!-- SKT Donation Form End --><!-- Donate Form Area Start --><!-- Donate Form Area End -->+8 more
Data Attributes
data-donate-iddata-donate-nonce
JS Globals
skt_donation_ajax_objskt_donation_vars
Shortcode Output
[skt_donation_form][skt_donation_list][skt_donation_single]
FAQ

Frequently Asked Questions about SKT Donation – Charity and Fundraising Plugin