SpendeOnline.org Security & Risk Analysis

wordpress.org/plugins/spendeonline

Das Plugin ermöglicht den Zugriff auf SpendeOnline.org, die Internet-Plattform zum Sammeln von Spenden.

10 active installs v3.0.2 PHP + WP 3.0.1+ Updated Dec 1, 2025
fundraisingspendespenden
99
A · Safe
CVEs total1
Unpatched0
Last CVEOct 24, 2025
Safety Verdict

Is SpendeOnline.org Safe to Use in 2026?

Generally Safe

Score 99/100

SpendeOnline.org has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 24, 2025Updated 4mo ago
Risk Assessment

The spendeonline v3.0.2 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices, with 100% of SQL queries utilizing prepared statements, all output being properly escaped, and no dangerous functions or file operations detected. Furthermore, the attack surface appears minimal, with no unprotected AJAX handlers or REST API routes, and no cron events. However, a significant concern arises from the vulnerability history. The plugin has a known medium severity CVE related to Cross-site Scripting (XSS), which is concerning despite it being currently patched. The absence of nonce checks and capability checks on entry points is a notable weakness, especially given the XSS history, as it could allow for unauthorized actions if an attacker can trigger the shortcode or other entry points without proper validation. The single external HTTP request also warrants attention for potential supply chain risks or vulnerabilities in the external service.

Key Concerns

  • Known medium severity CVE present
  • Missing nonce checks
  • Missing capability checks
  • External HTTP request present
Vulnerabilities
1

SpendeOnline.org Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-11875medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SpendeOnline.org <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 24, 2025 Patched in 3.0.2 (1d)
Code Analysis
Analyzed Mar 16, 2026

SpendeOnline.org Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

SpendeOnline.org Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[spendeonline] spendeonline.php:14
WordPress Hooks 2
actionwp_enqueue_scriptsspendeonline.php:15
actionwp_enqueue_scriptsspendeonline.php:16
Maintenance & Trust

SpendeOnline.org Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

SpendeOnline.org Developer Profile

Dr. Thomas Fuessl

2 plugins · 210 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect SpendeOnline.org

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://spendeonline.org/admin/webservices/spendeonline/spendeonline.js

HTML / DOM Fingerprints

CSS Classes
spendeonline
Data Attributes
id="spendeonline"
Shortcode Output
<DIV id="spendeonline"
FAQ

Frequently Asked Questions about SpendeOnline.org