
WP Donate Security & Risk Analysis
wordpress.org/plugins/wp-donateWP-Donate provides a payment form and recent donor by utilizing Stripe.
Is WP Donate Safe to Use in 2026?
Use With Caution
Score 55/100WP Donate has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wp-donate v2.0 plugin exhibits a concerning security posture, despite having a limited attack surface and no critical taint flows flagged in static analysis. The primary concerns stem from significant weaknesses in output escaping and a history of critical vulnerabilities, including an unpatched critical CVE. The fact that 0% of outputs are properly escaped is a major red flag, indicating a high likelihood of cross-site scripting (XSS) vulnerabilities. Furthermore, the presence of raw SQL queries, with only 36% using prepared statements, alongside a known history of SQL injection, amplifies this risk. The plugin's reliance on bundled libraries, without clear versioning information, also presents a potential avenue for exploitation if these libraries are outdated. While the plugin demonstrates some good practices like limited file operations and external HTTP requests, these are overshadowed by the critical lack of output sanitization and the persistent threat of unpatched vulnerabilities.
Key Concerns
- Unpatched critical CVE exists
- 0% of outputs properly escaped
- SQL queries not always prepared
- No nonce checks
- No capability checks
- High severity taint flows found
WP Donate Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Donate <= 2.0 - Unauthenticated Stored Cross-Site Scripting
WP Donate <= 1.4 - Unauthenticated SQL Injection in donate-display.php
WP Donate Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Donate Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
WP Donate Maintenance & Trust
Maintenance Signals
Community Trust
WP Donate Alternatives
WooCommerce Stripe Payment Gateway
woocommerce-gateway-stripe
Accept debit and credit cards in 135+ currencies, many local methods like Alipay, ACH, and SEPA, and express checkout with Apple Pay and Google Pay.
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions
wp-full-stripe-free
🚀 Create Stripe payment forms for WordPress. Accept credit cards, Apple Pay, donations, subscriptions & more. Easy setup, no coding needed!
Payment Gateway of Stripe for WooCommerce
payment-gateway-stripe-and-woocommerce-integration
Integrate Stripe Payment Gateway in WooCommerce and accept cards, Google Pay, Apple Pay, Klarna, Alipay, and more with seamless, secure checkout.
Stripe Payment Forms by WP Simple Pay – Accept Credit Card Payments + Subscriptions with Stripe
stripe
🤩 Accept Stripe payments and recurring subscriptions on your WordPress using WP Simple Pay, the best Stripe payments plugin! 🚀
Contact Form 7 – PayPal & Stripe Add-on
contact-form-7-paypal-add-on
Easily add PayPal and Stripe to Contact Form 7. Accept credit card payments with Stripe & PayPal on your site today. Offical PayPal & Stripe Partner.
WP Donate Developer Profile
2 plugins · 230 total installs
How We Detect WP Donate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-donate/css/wp-donate-display.css/wp-content/plugins/wp-donate/css/wp-donate-widget.css/wp-content/plugins/wp-donate/css/wp-donate-admin.css/wp-content/plugins/wp-donate/js/paymentmethods.js/wp-content/plugins/wp-donate/js/jquery.validate.js/wp-content/plugins/wp-donate/js/paymentmethods.js/wp-content/plugins/wp-donate/js/jquery.validate.jsHTML / DOM Fingerprints
wp_donate_formdata-donate-noncewp_donate_obj[Display_Donate]