Plugin Pulse
← Pulse

GiveWP – Donation Plugin and Fundraising Platform

by Nexcess · Uncategorized

Also makes 22 other plugins · 2.6M+ installs across the portfolio →

Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.

How scoring works →
97 Health · A
Maintenance 100/100
Rating quality 92/100
Support 100/100

97 health vs 56 average across 16,378 Uncategorized plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

98 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 91/100
Listing tuning 100/100
Support resolution 100/100

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

-13% vs prior 30d
4.1KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

251.5K

now · peak 349.0K

251.5K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

GiveWP · #363 you Charitable · #1606 FundEngine · #6657 Mission · #17994

Rating trend

Star average over time · dips mark rough releases

4.6Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

2.5Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

29

releases in the last 12 months

1mo ago

latest release · v4.16.4

244

tagged releases on record

Recent releases

4.16.4 · 1mo ago4.16.3 · 2mo ago4.16.2 · 2mo ago4.16.1 · 2mo ago4.16.0 · 2mo ago4.15.5 · 2mo ago4.15.4 · 2mo ago4.15.3 · 3mo ago4.15.2 · 3mo ago4.15.1 · 3mo ago4.15.0 · 4mo ago4.14.6 · 4mo ago4.14.5 · 5mo ago4.14.4 · 5mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 46% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v4.16 46%
v4.14 9.3%
v4.15 9.1%
Older / other versions 36%

Estimated active installs

The public count shows “100K+”. Our estimate pins where the real number sits.

modeled estimate
100K–200K ≈160K

Modeled within the band wp.org reports; tightens as we track daily.

Install history · since 2015-05-27 · 1,441 observations

100KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.

Details

Version
4.16.7.1
Last updated
yesterday
Added
2015-04-07 · 11 yrs old
Requires WP
6.6
Tested up to
7.0.4
Requires PHP
7.4

Recent reviews

All reviews on wp.org ↗
  1. banannah
    2mo ago

    Apparently this plugin has been bought by Liquid Web and along with other plugins they have bought there are issues with license activation. My client purchased a license weeks ago and we’re still struggling. Support is useless, giving instructions for things that don’t exist. All of the documentation is out of date so there’s no way to find out how this new process is supposed to work. I am going to recommend my client gets a refund.

    Read on wp.org ↗
  2. stellr
    2mo ago

    Everything I don’t understand I ask and receive very detailed responses. Also, they include video demonstrations of solutions, which is very helpful.

    Read on wp.org ↗
  3. apra2021
    4mo ago

    Thanks a lot for your great and immediate support that fixed the problem in my website.

    Read on wp.org ↗
  4. crisascunce
    4mo ago

    When you’re in a crunch for time and everything seems to be going wrong, that’s when you want fast and hassle-free support! That’s what GiveWP gives you!

    Read on wp.org ↗
  5. singletrackgrunt
    4mo ago

    Amazing support. Totally worth it!

    Read on wp.org ↗
  6. gmzephi
    4mo ago

    We have used GiveWP on a couple of client sites now. It is not often that we encounter issues with the plugin, it runs well and offers some great features. However, if and when their is an issue, I have always found their support to be first class. They are quick to respond, thorough in their investigations, and communicative throughout the resolution process.

    Read on wp.org ↗
  7. jms1017
    5mo ago

    Great support, stuck with the problem through completion.

    Read on wp.org ↗
  8. carlamurray
    5mo ago

    Alex C is the best support tech ever. He is kind, patient and knowledgeable. He made sure to follow through all the way until the end which is rare and exceptional. Thanks Alex!!

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 4.16.5 Fix: Resolved an issue where selecting a donation amount level would also select other levels with the same value. Fix: Resolved an issue where extra separators could render in the donation confirmation page header when 4.16.5
  2. Version 4.16.4 Security: Added additional validation to the core settings importer. Security: Added additional escaping to donor information displayed in the admin. Security: Added additional escaping to the Sequoia (Multi-Step Form) t 4.16.4
  3. Version 4.16.3 Security: Added additional validation to ensure donation gateway selection respects the enabled payment gateway settings. Security: Improved escaping of donation form template output. Security: Improved the security of t 4.16.3
  4. Version 4.16.2 Security: Added additional escaping and sanitization to the Sequoia (Multi-Step Form) template settings and donation form markup (CVE-2026-13704). 4.16.2
  5. Version 4.16.1 Security: Standardized email access confirmation AJAX responses to prevent distinguishable server responses. Security: Added additional escaping and sanitization to the Campaign Comments block and shortcode attributes (C 4.16.1
  6. Version 4.16.0 Feature: Added an optional donation ID parameter to gateway webhook event handlers, allowing gateways to locate donations when the transaction ID is only available in the webhook payload. Fix: Resolved an issue where mul 4.16.0

Known vulnerabilities

via Wordfence Intelligence

87 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-08-14 CVE-2026-73348 Missing Authorization Affects < 4.16.6 Patched in 4.16.6
  2. 2026-08-14 CVE-2026-73352 Missing Authorization Affects <= 4.16.5.1 Patched in 4.16.6
  3. 2026-08-12 CVE-2026-73349 Missing Authorization Affects < 4.16.6 Patched in 4.16.6
  4. 2026-08-12 CVE-2026-73357 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.16.6 Patched in 4.16.6
  5. 2026-08-04 CVE-2026-14317 Missing Authorization Affects < 4.16.3 Patched in 4.16.3
  6. 2026-07-31 CVE-2026-66690 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.5 Patched in 4.16.5.1
  7. 2026-07-30 CVE-2026-14318 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.16.3 Patched in 4.16.3
  8. 2026-07-27 CVE-2026-65441 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.3 Patched in 4.16.4
  9. 2026-07-22 CVE-2026-65464 Cross-Site Request Forgery (CSRF) Affects <= 4.16.3 Patched in 4.16.4
  10. 2026-07-15 CVE-2026-14987 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.3 Patched in 4.16.4
  11. 2026-07-13 CVE-2026-14319 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 4.16.2 Patched in 4.16.3
  12. 2026-07-01 CVE-2026-13704 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.1 Patched in 4.16.2
  13. 2026-06-30 CVE-2026-11981 Cross-Site Request Forgery (CSRF) Affects <= 4.15.3 Patched in 4.15.4
  14. 2026-06-30 CVE-2026-13246 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.0 Patched in 4.16.1
  15. 2026-05-16 CVE-2026-42678 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.14.5 Patched in 4.14.6
  16. 2026-04-21 CVE-2026-34900 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.14.2 Patched in 4.14.3
  17. 2026-03-02 CVE-2026-42642 Missing Authorization Affects <= 4.14.5 Patched in 4.14.6
  18. 2026-01-08 CVE-2025-66533 Improper Control of Generation of Code ('Code Injection') Affects <= 4.13.1 Patched in 4.13.2
  19. 2025-12-23 CVE-2025-67467 Cross-Site Request Forgery (CSRF) Affects <= 4.13.1 Patched in 4.13.2
  20. 2025-11-18 CVE-2025-13206 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.13.0 Patched in 4.13.1
  21. 2025-10-03 CVE-2025-11227 Improper Authorization Affects <= 4.10.0 Patched in 4.10.1
  22. 2025-10-03 CVE-2025-11228 Missing Authorization Affects <= 4.10.0 Patched in 4.10.1
  23. 2025-08-20 CVE-2025-7221 Improper Authorization Affects <= 4.5.0 Patched in 4.6.1
  24. 2025-08-05 CVE-2025-8620 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 4.6.0 Patched in 4.6.1
  25. 2025-07-30 CVE-2025-7205 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.0 Patched in 4.6.0
  26. 2025-06-18 CVE-2025-4571 Missing Authorization Affects <= 4.3.0 Patched in 4.3.1
  27. 2025-03-21 CVE-2025-2331 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.22.1 Patched in 3.22.2
  28. 2025-03-14 CVE-2025-2025 Missing Authorization Affects <= 3.22.0 Patched in 3.22.1
  29. 2025-03-03 CVE-2025-0912 Deserialization of Untrusted Data Affects <= 3.19.4 Patched in 3.20.0
  30. 2025-01-10 CVE-2025-22777 Deserialization of Untrusted Data Affects <= 3.19.3 Patched in 3.19.4
  31. 2025-01-10 CVE-2024-12877 Deserialization of Untrusted Data Affects <= 3.19.2 Patched in 3.19.3
  32. 2024-12-06 CVE-2024-11921 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.18.0 Patched in 3.19.0
  33. 2024-10-15 CVE-2024-9634 Deserialization of Untrusted Data Affects <= 3.16.3 Patched in 3.16.4
  34. 2024-09-27 CVE-2024-8353 Deserialization of Untrusted Data Affects <= 3.16.1 Patched in 3.16.2
  35. 2024-09-26 CVE-2024-9130 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.16.1 Patched in 3.16.2
  36. 2024-09-25 CVE-2024-47315 Cross-Site Request Forgery (CSRF) Affects <= 3.15.1 Patched in 3.16.0
  37. 2024-08-28 CVE-2024-6551 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.15.1 Patched in 3.16.0
  38. 2024-08-19 CVE-2024-5932 Deserialization of Untrusted Data Affects <= 3.14.1 Patched in 3.14.2
  39. 2024-08-19 CVE-2024-5941 Missing Authorization Affects <= 3.14.1 Patched in 3.14.2
  40. 2024-08-19 CVE-2024-5939 Missing Authorization Affects <= 3.13.0 Patched in 3.14.0
  41. 2024-08-19 CVE-2024-5940 Missing Authorization Affects <= 3.13.0 Patched in 3.14.0
  42. 2024-08-09 CVE-2024-37099 Deserialization of Untrusted Data Affects <= 3.14.1 Patched in 3.14.2
  43. 2024-07-18 CVE-2024-5977 Authorization Bypass Through User-Controlled Key Affects <= 3.13.0 Patched in 3.14.0
  44. 2024-06-06 CVE-2024-35679 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.12.0 Patched in 3.12.1
  45. 2024-05-17 CVE-2024-3714 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.10.0 Patched in 3.11.0
  46. 2024-04-26 CVE-2024-30229 Deserialization of Untrusted Data Affects <= 3.4.2 Patched in 3.5.0
  47. 2024-04-12 CVE-2024-1957 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.6.1 Patched in 3.7.0
  48. 2024-03-19 CVE-2024-1424 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.5.1 Patched in 3.6.0
  49. 2024-03-15 CVE-2024-27987 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.1 Patched in 3.4.0
  50. 2024-01-19 CVE-2023-51415 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.2 Patched in 3.3.0
  51. 2023-10-31 CVE-2023-4248 Cross-Site Request Forgery (CSRF) Affects <= 2.33.3 Patched in 2.33.4
  52. 2023-10-31 CVE-2023-47183 Missing Authorization Affects <= 2.33.1 Patched in 2.33.2
  53. 2023-10-31 CVE-2023-4246 Cross-Site Request Forgery (CSRF) Affects <= 2.33.3 Patched in 2.33.4
  54. 2023-10-31 CVE-2023-4247 Cross-Site Request Forgery (CSRF) Affects <= 2.33.3 Patched in 2.33.4
  55. 2023-08-31 CVE-2023-41665 Improper Input Validation Affects < 2.33.1 Patched in 2.33.1
  56. 2023-05-10 CVE-2023-32513 Deserialization of Untrusted Data Affects <= 2.25.3 Patched in 2.26.0
  57. 2023-03-23 Cross-Site Request Forgery (CSRF) Affects <= 2.25.2 Patched in 2.25.3
  58. 2023-03-23 Cross-Site Request Forgery (CSRF) Affects <= 2.25.2 Patched in 2.25.3
  59. 2023-03-23 Cross-Site Request Forgery (CSRF) Affects <= 2.25.2 Patched in 2.25.3
  60. 2023-03-10 CVE-2023-23672 Improper Authorization Affects <= 2.25.1 Patched in 2.25.2
  61. 2023-03-10 CVE-2022-40211 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.25.1 Patched in 2.25.2
  62. 2023-03-08 CVE-2022-40312 Server-Side Request Forgery (SSRF) Affects <= 2.25.1 Patched in 2.25.2
  63. 2023-03-08 Cross-Site Request Forgery (CSRF) Affects <= 2.25.1 Patched in 2.25.2
  64. 2023-03-08 CVE-2023-22719 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 2.25.1 Patched in 2.25.2
  65. 2023-03-08 Cross-Site Request Forgery (CSRF) Affects <= 2.25.1 Patched in 2.25.2
  66. 2023-03-08 CVE-2023-25450 Cross-Site Request Forgery (CSRF) Affects <= 2.25.1 Patched in 2.25.2
  67. 2023-03-08 Cross-Site Request Forgery (CSRF) Affects <= 2.25.1 Patched in 2.25.2
  68. 2023-03-08 CVE-2023-23668 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.25.1 Patched in 2.25.2
  69. 2023-01-19 CVE-2023-0224 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.23.2 Patched in 2.24
  70. 2023-01-19 CVE-2022-4448 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.23.2 Patched in 2.24
  71. 2022-07-12 CVE-2022-31475 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.20.2 Patched in 2.21.0
  72. 2022-07-12 CVE-2022-28700 Improper Authorization Affects <= 2.20.2 Patched in 2.21.0
  73. 2022-07-11 CVE-2022-2215 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.21.2 Patched in 2.21.3
  74. 2022-07-08 CVE-2022-2260 Cross-Site Request Forgery (CSRF) Affects <= 2.21.2 Patched in 2.21.3
  75. 2022-06-17 CVE-2022-2117 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.20.2 Patched in 2.21.0
  76. 2022-01-18 CVE-2022-0252 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.17.3 Patched in 2.17.3
  77. 2022-01-18 CVE-2021-25100 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.17.3 Patched in 2.17.3
  78. 2022-01-18 CVE-2021-25099 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.17.3 Patched in 2.17.3
  79. 2021-07-26 CVE-2021-24524 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.12.0 Patched in 2.12.0
  80. 2021-04-30 CVE-2021-24315 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.10.4 Patched in 2.10.4
  81. 2021-03-23 CVE-2021-24213 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 2.4.0 - 2.10.0 Patched in 2.10.0
  82. 2019-10-30 CVE-2020-20627 Missing Authorization Affects < 2.5.10 Patched in 2.5.10
  83. 2019-09-26 CVE-2019-20360 Improper Authorization Affects <= 2.5.4 Patched in 2.5.5
  84. 2019-08-12 CVE-2019-13578 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.5.0 Patched in 2.5.1
  85. 2019-05-15 CVE-2019-15317 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.4.7 Patched in 2.4.7
  86. 2019-02-05 CVE-2019-9909 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.3.1 Patched in 2.3.1
  87. 2015-04-20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 0.8.5 Patched in 0.8.5

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 113 languages, 9 at 90% or more

Dutch 100%
Dutch (Formal) 100%
Persian 100%
Czech 99%
Korean 99%
Lao 99%
Polish 99%
Italian 91%
French (France) 90%
Spanish (Chile) 88%
Spanish (Spain) 87%
Portuguese (Brazil) 71%
English (Australia) 66%
English (New Zealand) 66%
German 66%
English (Canada) 65%
Spanish (Mexico) 65%
Ukrainian 64%
English (UK) 62%
Spanish (Colombia) 62%
Russian 61%
Spanish (Ecuador) 61%
Spanish (Venezuela) 61%
Dutch (Belgium) 60%

Plus 89 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

No tier crossings observed yet.

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for GiveWP – Donation Plugin and Fundraising Platform into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/give" width="480" height="300" style="border:0" loading="lazy" title="GiveWP – Donation Plugin and Fundraising Platform — Plugin Pulse"></iframe>
Preview card ↗

GiveWP – Donation Plugin and Fundraising Platform: 100K+ active installs, 4.6★ (705 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/give