
FundEngine – Donation and Crowdfunding Platform Security & Risk Analysis
wordpress.org/plugins/wp-fundraising-donationFundEngine - Fundraising Donation plugin and Crowdfunding Platform comes with Single donation and crowdfunding solution. You can use our plugin Either …
Is FundEngine – Donation and Crowdfunding Platform Safe to Use in 2026?
Generally Safe
Score 88/100FundEngine – Donation and Crowdfunding Platform has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-fundraising-donation plugin v1.7.5 exhibits a mixed security posture, with some strong practices offset by significant vulnerabilities. While the plugin demonstrates good use of prepared statements for SQL queries (99%) and a high percentage of properly escaped output (87%), the presence of 3 'unserialize' function calls is a red flag, as this function is notoriously prone to deserialization vulnerabilities if not handled with extreme caution and proper input validation. Furthermore, the plugin has a considerable attack surface with 32 entry points, of which a concerning 21 are unprotected, including 2 AJAX handlers and all 19 REST API routes lacking permission callbacks. The taint analysis reveals 4 high-severity flows with unsanitized paths, indicating potential for exploitation.
Key Concerns
- High severity taint flows found
- Significant number of unprotected entry points
- AJAX handlers without authentication
- REST API routes without permission callbacks
- Presence of 'unserialize' function
- Vulnerability history: 1 critical CVE
- Vulnerability history: 2 high CVEs
- Vulnerability history: 2 medium CVEs
- Common vulnerability types: RFI, CSRF, Auth issues, SQLi
- Bundled libraries (Stripe PHP, Select2) may be outdated
FundEngine – Donation and Crowdfunding Platform Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
FundEngine <= 1.7.4 - Authenticated (Subscriber+) Local File Inclusion
WP Fundraising Donation and Crowdfunding Platform <= 1.7.3 - Cross-Site Request Forgery
FundEngine – Donation and Crowdfunding Platform <= 1.7.0 - Authenticated (Subscriber+) Privilege Escalation
WP Fundraising Donation and Crowdfunding Platform <= 1.6.4 - Missing Authorization
WP Fundraising Donation and Crowdfunding Platform <= 1.4.2 - Unauthenticated SQL Injection
FundEngine – Donation and Crowdfunding Platform Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
FundEngine – Donation and Crowdfunding Platform Attack Surface
AJAX Handlers 4
REST API Routes 19
Shortcodes 9
WordPress Hooks 64
Maintenance & Trust
FundEngine – Donation and Crowdfunding Platform Maintenance & Trust
Maintenance Signals
Community Trust
FundEngine – Donation and Crowdfunding Platform Alternatives
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
charitable
The best WordPress donation plugin. Create fundraising donation forms, accept recurring donations, easy donor management, add crowdfunding, and more.
Leyka
leyka
Leyka is a plugin for crowdfunding and donations collection via WordPress website.
Crowded Collect — Dues & Fundraising
crowded-collect-dues-fundraising
Embed your Crowded collection directly into your WordPress site with no coding required!
Project World Impact
project-world-impact
Integrate PWI Crowdfund, PWI GroupGive, and PWI Storyteller features into your WordPress site with our powerful plugin for nonprofit partners.
FundEngine – Donation and Crowdfunding Platform Developer Profile
15 plugins · 3.0M total installs
How We Detect FundEngine – Donation and Crowdfunding Platform
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-fundraising-donation/assets/css/wfp-donation-public.css/wp-content/plugins/wp-fundraising-donation/assets/css/wfp-donation-admin.css/wp-content/plugins/wp-fundraising-donation/assets/css/wfp-donation-elementor.css/wp-content/plugins/wp-fundraising-donation/assets/js/wfp-donation-public.js/wp-content/plugins/wp-fundraising-donation/assets/js/wfp-donation-admin.js/wp-content/plugins/wp-fundraising-donation/assets/js/wfp-donation-elementor.js/wp-content/plugins/wp-fundraising-donation/assets/js/wfp-donation-map.js/wp-content/plugins/wp-fundraising-donation/assets/js/wfp-donation-chart.js/wp-content/plugins/wp-fundraising-donation/assets/js/wfp-donation-public.js/wp-content/plugins/wp-fundraising-donation/assets/js/wfp-donation-admin.js/wp-content/plugins/wp-fundraising-donation/assets/js/wfp-donation-elementor.js/wp-content/plugins/wp-fundraising-donation/assets/js/wfp-donation-map.js/wp-content/plugins/wp-fundraising-donation/assets/js/wfp-donation-chart.jswp-fundraising-donation/assets/css/wfp-donation-public.css?ver=wp-fundraising-donation/assets/css/wfp-donation-admin.css?ver=wp-fundraising-donation/assets/css/wfp-donation-elementor.css?ver=wp-fundraising-donation/assets/js/wfp-donation-public.js?ver=wp-fundraising-donation/assets/js/wfp-donation-admin.js?ver=wp-fundraising-donation/assets/js/wfp-donation-elementor.js?ver=wp-fundraising-donation/assets/js/wfp-donation-map.js?ver=wp-fundraising-donation/assets/js/wfp-donation-chart.js?ver=HTML / DOM Fingerprints
wfp-fundraising-donationwfp-donation-single-campaignwfp-donation-form-wrapperwfp-donate-buttonwfp-campaign-list-itemwfp-donation-progress-barwfp-donation-goalwfp-donation-amount+1 more<!-- Sample short code for login-registration --><!-- giving legacy support ; this line should be deleted after another one or two version later -->data-plugin='wp-fundraising-donation'wfp_donation_paramsWfpFundraisingPublicWfpFundraisingAdmin/wp-json/wp-fundraising-donation/v1/donate/wp-json/wp-fundraising-donation/v1/campaigns/wp-json/wp-fundraising-donation/v1/backers[wfp-forms][wfp_fundraising_form][wfp-auth-form][wfp-dashboard]