
UncommonGood Donation Widget Security & Risk Analysis
wordpress.org/plugins/uncommongood-donation-widgetAccept donations and begin fundraising with the UncommonGood Donation Widget. The settings are very simple: one input box for the donation Widget Embe …
Is UncommonGood Donation Widget Safe to Use in 2026?
Generally Safe
Score 85/100UncommonGood Donation Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The uncommongood-donation-widget v1.3 plugin exhibits a generally strong security posture based on the static analysis and vulnerability history provided. The complete absence of dangerous functions, SQL queries without prepared statements, and unsanitized output flows are excellent indicators of secure coding practices. The plugin also benefits from a clean vulnerability history, with no known CVEs, suggesting a history of responsible development and maintenance. However, the analysis does highlight potential areas for improvement. The presence of a shortcode without any apparent authorization or capability checks represents a potential attack vector, albeit a limited one given the other security measures in place. The complete lack of nonce checks across all entry points, including the shortcode, is a notable weakness that could be exploited if other input validation or sanitization were to fail. Despite these minor concerns, the overall security of this plugin appears to be good, with developers demonstrating awareness of fundamental security principles.
Key Concerns
- Shortcode without auth checks
- Missing nonce checks
UncommonGood Donation Widget Security Vulnerabilities
UncommonGood Donation Widget Release Timeline
UncommonGood Donation Widget Code Analysis
Output Escaping
UncommonGood Donation Widget Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
UncommonGood Donation Widget Maintenance & Trust
Maintenance Signals
Community Trust
UncommonGood Donation Widget Alternatives
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
charitable
The best WordPress donation plugin. Create fundraising donation forms, accept recurring donations, easy donor management, add crowdfunding, and more.
Zeffy Donate Button
zeffy-donate-button
Embed Zeffy donation forms on your WordPress site with customizable popup buttons. Simple setup with no coding required.
Fundraising Bar – A Sticky Customizable Donation Bar for WordPress
fundraising-bar
A WordPress plugin that displays a donation bar for PayPal donations (one-time or recurring), with sandbox mode, custom amounts, fee coverage, and a l …
Donorbox – Free Recurring Donation Plugin and Fundraising Platform
donorbox-donation-form
Donorbox is a powerful and secure donation management plugin for WordPress. We are the only donation plugin for WordPress that offers a fast feature-f …
UncommonGood Donation Widget Developer Profile
1 plugin · 0 total installs
How We Detect UncommonGood Donation Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/uncommongood-donation-widget/public/css/ugdw-public.css/wp-content/plugins/uncommongood-donation-widget/public/js/ugdw-public.js/wp-content/plugins/uncommongood-donation-widget/public/js/ugdw-public.jsuncommongood-donation-widget/public/css/ugdw-public.css?ver=uncommongood-donation-widget/public/js/ugdw-public.js?ver=HTML / DOM Fingerprints
ugdw-uncommongood-widget-iconugdw-uncommongood-widget-icon-logowp-block-buttonwp-block-button__linkbtnorganization-widget<div class="wp-block-button">
<a class="wp-block-button__link btn" href="#https://uncommongood.io/widget">Donate</a>
</div>