
SpendeOnline.org Security & Risk Analysis
wordpress.org/plugins/spendeonlineDas Plugin ermöglicht den Zugriff auf SpendeOnline.org, die Internet-Plattform zum Sammeln von Spenden.
Is SpendeOnline.org Safe to Use in 2026?
Generally Safe
Score 99/100SpendeOnline.org has a strong security track record. Known vulnerabilities have been patched promptly.
The spendeonline v3.0.2 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices, with 100% of SQL queries utilizing prepared statements, all output being properly escaped, and no dangerous functions or file operations detected. Furthermore, the attack surface appears minimal, with no unprotected AJAX handlers or REST API routes, and no cron events. However, a significant concern arises from the vulnerability history. The plugin has a known medium severity CVE related to Cross-site Scripting (XSS), which is concerning despite it being currently patched. The absence of nonce checks and capability checks on entry points is a notable weakness, especially given the XSS history, as it could allow for unauthorized actions if an attacker can trigger the shortcode or other entry points without proper validation. The single external HTTP request also warrants attention for potential supply chain risks or vulnerabilities in the external service.
Key Concerns
- Known medium severity CVE present
- Missing nonce checks
- Missing capability checks
- External HTTP request present
SpendeOnline.org Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SpendeOnline.org <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
SpendeOnline.org Code Analysis
Output Escaping
SpendeOnline.org Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
SpendeOnline.org Maintenance & Trust
Maintenance Signals
Community Trust
SpendeOnline.org Alternatives
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
charitable
The best WordPress donation plugin. Create fundraising donation forms, accept recurring donations, easy donor management, add crowdfunding, and more.
Donorbox – Free Recurring Donation Plugin and Fundraising Platform
donorbox-donation-form
Donorbox is a powerful and secure donation management plugin for WordPress. We are the only donation plugin for WordPress that offers a fast feature-f …
GiveWP Donation Widgets for Elementor
givewp-donation-widgets-for-elementor
A GiveWP add-on which allows you to embed any GiveWP shortcode into your Elementor-powered pages.
Donation Platform for WooCommerce: Fundraising & Donation Management
wc-donation-platform
Open source donation system for your fundraising that supports recurring donations and more
SpendeOnline.org Developer Profile
2 plugins · 210 total installs
How We Detect SpendeOnline.org
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://spendeonline.org/admin/webservices/spendeonline/spendeonline.jsHTML / DOM Fingerprints
spendeonlineid="spendeonline"<DIV id="spendeonline"