
WooMinecraft-WP Security & Risk Analysis
wordpress.org/plugins/woominecraftA FREE Minecraft Donation plugin which works in conjunction with my WooMinecraft java plugin for Minecraft to provide a self-hosted donation platform.
Is WooMinecraft-WP Safe to Use in 2026?
Generally Safe
Score 85/100WooMinecraft-WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woominecraft" plugin v1.4.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively. It also shows a relatively high percentage of properly escaped outputs, minimizing the risk of certain cross-site scripting (XSS) vulnerabilities. The absence of known CVEs and any recorded vulnerability history suggests a generally stable codebase in the past. However, significant concerns arise from the static analysis. The presence of a single AJAX handler without authentication checks presents a clear attack vector. The taint analysis, while limited in scope, identified one flow with an unsanitized path, which could potentially lead to vulnerabilities depending on its context and the data processed. The lack of nonce checks on the exposed AJAX endpoint is also a notable oversight. While the overall attack surface is small, the critical weakness of an unprotected AJAX entry point, combined with the unsanitized path flow, elevates the risk. In conclusion, while the plugin benefits from secure SQL handling and good output escaping, the unprotected AJAX endpoint and the identified unsanitized path flow are serious vulnerabilities that need immediate attention. The clean vulnerability history is positive, but it doesn't negate the immediate risks present in the current codebase.
Key Concerns
- AJAX handler without auth checks
- Flow with unsanitized paths
- No nonce checks
- Less than 100% output escaping
WooMinecraft-WP Security Vulnerabilities
WooMinecraft-WP Release Timeline
WooMinecraft-WP Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WooMinecraft-WP Attack Surface
AJAX Handlers 1
WordPress Hooks 22
Maintenance & Trust
WooMinecraft-WP Maintenance & Trust
Maintenance Signals
Community Trust
WooMinecraft-WP Alternatives
Potent Donations for WooCommerce
donations-for-woocommerce
Easily accept donations of varying amounts through your WooCommerce store.
WPC Order Tip for WooCommerce
wpc-order-tip
WPC Order Tip is a plugin that enables customers to add extra amounts to their order as a tip or donation to the seller or specified recipients.
StoreLink for Minecraft by MrDino
storelinkformc
Connect your WooCommerce store with a Minecraft server. Deliver in-game items when an order is completed, using a secure and customizable REST API.
Simple checkout page donations/tips for WooCommerce
simple-checkout-page-donationstips-for-woocommerce
This plugin lets you add custom tips for display in the checkout page. These tips are optional for the customer to add to the cart fee.
Donation Amount Tracker
donation-amount-tracker
Track and display donation amounts from WooCommerce orders with customizable progress bars and displays for fundraising campaigns.
WooMinecraft-WP Developer Profile
2 plugins · 70 total installs
How We Detect WooMinecraft-WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woominecraft/assets/css/admin-style.css/wp-content/plugins/woominecraft/assets/js/admin-script.js/wp-content/plugins/woominecraft/assets/css/woocommerce-admin-style.css/wp-content/plugins/woominecraft/assets/js/woocommerce-admin-script.js/wp-content/plugins/woominecraft/assets/js/admin-script.js/wp-content/plugins/woominecraft/assets/js/woocommerce-admin-script.jswoominecraft/assets/css/admin-style.css?ver=woominecraft/assets/js/admin-script.js?ver=woominecraft/assets/css/woocommerce-admin-style.css?ver=woominecraft/assets/js/woocommerce-admin-script.js?ver=HTML / DOM Fingerprints
wmc-orders-deliveredwmc-player-namewmc-servers-section<!-- Ni Hijan -->data-servers-optionsWooMinecraftAdminWooMinecraftWooCommerceAdmin/wp-json/woominecraft/v1/send_command/wp-json/woominecraft/v1/get_servers