GiveWP – Donation Plugin and Fundraising Platform
by Nexcess · Uncategorized
Also makes 22 other plugins · 2.6M+ installs across the portfolio →
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
97 health vs 56 average across 16,378 Uncategorized plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
251.5K
now · peak 349.0K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
29
releases in the last 12 months
1mo ago
latest release · v4.16.4
244
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 46% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “100K+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2015-05-27 · 1,441 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ banannah2mo ago
Apparently this plugin has been bought by Liquid Web and along with other plugins they have bought there are issues with license activation. My client purchased a license weeks ago and we’re still struggling. Support is useless, giving instructions for things that don’t exist. All of the documentation is out of date so there’s no way to find out how this new process is supposed to work. I am going to recommend my client gets a refund.
Read on wp.org ↗ - ★★★★★ stellr2mo ago
Everything I don’t understand I ask and receive very detailed responses. Also, they include video demonstrations of solutions, which is very helpful.
Read on wp.org ↗ - ★★★★★ apra20214mo ago
Thanks a lot for your great and immediate support that fixed the problem in my website.
Read on wp.org ↗ - ★★★★★ crisascunce4mo ago
When you’re in a crunch for time and everything seems to be going wrong, that’s when you want fast and hassle-free support! That’s what GiveWP gives you!
Read on wp.org ↗ - ★★★★★ singletrackgrunt4mo ago
Amazing support. Totally worth it!
Read on wp.org ↗ - ★★★★★ gmzephi4mo ago
We have used GiveWP on a couple of client sites now. It is not often that we encounter issues with the plugin, it runs well and offers some great features. However, if and when their is an issue, I have always found their support to be first class. They are quick to respond, thorough in their investigations, and communicative throughout the resolution process.
Read on wp.org ↗ - ★★★★★ jms10175mo ago
Great support, stuck with the problem through completion.
Read on wp.org ↗ - ★★★★★ carlamurray5mo ago
Alex C is the best support tech ever. He is kind, patient and knowledgeable. He made sure to follow through all the way until the end which is rare and exceptional. Thanks Alex!!
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 4.16.5 Fix: Resolved an issue where selecting a donation amount level would also select other levels with the same value. Fix: Resolved an issue where extra separators could render in the donation confirmation page header when 4.16.5
- — Version 4.16.4 Security: Added additional validation to the core settings importer. Security: Added additional escaping to donor information displayed in the admin. Security: Added additional escaping to the Sequoia (Multi-Step Form) t 4.16.4
- — Version 4.16.3 Security: Added additional validation to ensure donation gateway selection respects the enabled payment gateway settings. Security: Improved escaping of donation form template output. Security: Improved the security of t 4.16.3
- — Version 4.16.2 Security: Added additional escaping and sanitization to the Sequoia (Multi-Step Form) template settings and donation form markup (CVE-2026-13704). 4.16.2
- — Version 4.16.1 Security: Standardized email access confirmation AJAX responses to prevent distinguishable server responses. Security: Added additional escaping and sanitization to the Campaign Comments block and shortcode attributes (C 4.16.1
- — Version 4.16.0 Feature: Added an optional donation ID parameter to gateway webhook event handlers, allowing gateways to locate donations when the transaction ID is only available in the webhook payload. Fix: Resolved an issue where mul 4.16.0
Known vulnerabilities
via Wordfence Intelligence87 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 6.4 GiveWP – Donation Plugin and Fundraising Platform < 4.16.6 - Authenticated (Donor+) Stored Cross-Site Scripting ↗2026-08-12 CVE-2026-73357 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.16.6 Patched in 4.16.6
- 2026-07-31 CVE-2026-66690 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.5 Patched in 4.16.5.1
- 2026-07-30 CVE-2026-14318 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.16.3 Patched in 4.16.3
- 2026-07-27 CVE-2026-65441 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.3 Patched in 4.16.4
- 2026-07-15 CVE-2026-14987 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.3 Patched in 4.16.4
- 2026-07-13 CVE-2026-14319 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 4.16.2 Patched in 4.16.3
- Medium · 6.4 GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form ↗2026-07-01 CVE-2026-13704 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.1 Patched in 4.16.2
- Medium · 4.3 GiveWP <= 4.15.3 - Cross-Site Request Forgery ↗
- Medium · 6.4 GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute ↗2026-06-30 CVE-2026-13246 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.16.0 Patched in 4.16.1
- 2026-05-16 CVE-2026-42678 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.14.5 Patched in 4.14.6
- Medium · 6.1 GiveWP – Donation Plugin and Fundraising Platform <= 4.14.2 - Reflected Cross-Site Scripting ↗2026-04-21 CVE-2026-34900 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.14.2 Patched in 4.14.3
- Medium · 5.3 GiveWP <= 4.14.5 - Missing Authorization ↗
- 2026-01-08 CVE-2025-66533 Improper Control of Generation of Code ('Code Injection') Affects <= 4.13.1 Patched in 4.13.2
- Medium · 4.3 GiveWP <= 4.13.1 - Cross-Site Request Forgery ↗
- 2025-11-18 CVE-2025-13206 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.13.0 Patched in 4.13.1
- Medium · 5.3 GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure ↗2025-08-05 CVE-2025-8620 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 4.6.0 Patched in 4.6.1
- 2025-07-30 CVE-2025-7205 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.5.0 Patched in 4.6.0
- 2025-03-21 CVE-2025-2331 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.22.1 Patched in 3.22.2
- Medium · 6.1 GiveWP – Donation Plugin and Fundraising Platform <= 3.18.0 - Reflected Cross-Site Scripting ↗2024-12-06 CVE-2024-11921 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.18.0 Patched in 3.19.0
- 2024-09-26 CVE-2024-9130 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.16.1 Patched in 3.16.2
- Medium · 4.3 GiveWP <= 3.15.1 - Cross-Site Request Forgery ↗
- 2024-08-28 CVE-2024-6551 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.15.1 Patched in 3.16.0
- 2024-07-18 CVE-2024-5977 Authorization Bypass Through User-Controlled Key Affects <= 3.13.0 Patched in 3.14.0
- Medium · 6.1 GiveWP – Donation Plugin and Fundraising Platform <= 3.12.0 - Reflected Cross-Site Scripting ↗2024-06-06 CVE-2024-35679 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.12.0 Patched in 3.12.1
- 2024-05-17 CVE-2024-3714 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.10.0 Patched in 3.11.0
- 2024-04-12 CVE-2024-1957 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.6.1 Patched in 3.7.0
- 2024-03-19 CVE-2024-1424 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.5.1 Patched in 3.6.0
- Medium · 6.1 GiveWP <= 3.3.1 - Reflected Cross-Site Scripting ↗2024-03-15 CVE-2024-27987 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.1 Patched in 3.4.0
- 2024-01-19 CVE-2023-51415 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.2 Patched in 3.3.0
- Medium · 4.3 GiveWP <= 2.25.2 - Cross-Site Request Forgery ↗2023-03-23 Cross-Site Request Forgery (CSRF) Affects <= 2.25.2 Patched in 2.25.3
- 2023-03-23 Cross-Site Request Forgery (CSRF) Affects <= 2.25.2 Patched in 2.25.3
- 2023-03-23 Cross-Site Request Forgery (CSRF) Affects <= 2.25.2 Patched in 2.25.3
- 2023-03-10 CVE-2022-40211 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.25.1 Patched in 2.25.2
- Medium · 6.1 GiveWP <= 2.25.1 - Cross-Site Request Forgery to Cross-Site Scripting via render_dropdown ↗2023-03-08 Cross-Site Request Forgery (CSRF) Affects <= 2.25.1 Patched in 2.25.2
- 2023-03-08 CVE-2023-22719 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 2.25.1 Patched in 2.25.2
- 2023-03-08 Cross-Site Request Forgery (CSRF) Affects <= 2.25.1 Patched in 2.25.2
- 2023-03-08 Cross-Site Request Forgery (CSRF) Affects <= 2.25.1 Patched in 2.25.2
- Medium · 6.4 GiveWP <= 2.25.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via give_form_grid shortcode ↗2023-03-08 CVE-2023-23668 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.25.1 Patched in 2.25.2
- Critical · 9.8 GiveWP <= 2.23.2 - Unauthenticated SQL Injection ↗2023-01-19 CVE-2023-0224 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.23.2 Patched in 2.24
- Medium · 6.4 GiveWP <= 2.23.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2023-01-19 CVE-2022-4448 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.23.2 Patched in 2.24
- 2022-07-12 CVE-2022-31475 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.20.2 Patched in 2.21.0
- 2022-07-11 CVE-2022-2215 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.21.2 Patched in 2.21.3
- Medium · 5.3 GiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 - Sensitive Information Disclosure ↗2022-06-17 CVE-2022-2117 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.20.2 Patched in 2.21.0
- 2022-01-18 CVE-2022-0252 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.17.3 Patched in 2.17.3
- Medium · 6.1 GiveWP <= 2.17.2 - Reflected Cross-Site Scripting ↗2022-01-18 CVE-2021-25100 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.17.3 Patched in 2.17.3
- Medium · 6.1 GiveWP <= 2.17.2 - Reflected Cross-Site Scripting ↗2022-01-18 CVE-2021-25099 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.17.3 Patched in 2.17.3
- 2021-07-26 CVE-2021-24524 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.12.0 Patched in 2.12.0
- 2021-04-30 CVE-2021-24315 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.10.4 Patched in 2.10.4
- 2021-03-23 CVE-2021-24213 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 2.4.0 - 2.10.0 Patched in 2.10.0
- High · 7.5 GiveWP <= 2.5.4 - Authorization Bypass ↗
- 2019-08-12 CVE-2019-13578 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.5.0 Patched in 2.5.1
- Medium · 5.4 GiveWP <= 2.4.6 - Cross-Site Scripting ↗2019-05-15 CVE-2019-15317 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.4.7 Patched in 2.4.7
- Medium · 6.1 GiveWP <= 2.3.0 - Cross-Site Scripting ↗2019-02-05 CVE-2019-9909 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.3.1 Patched in 2.3.1
- Medium · 6.1 GiveWP – Donation Plugin and Fundraising Platform < 0.8.5 - Reflected Cross-Site Scripting ↗2015-04-20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 0.8.5 Patched in 0.8.5
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 113 languages, 9 at 90% or more
Plus 89 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
No tier crossings observed yet.
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) 10K+ installs · 4.8★ · 5 shared tags A -
FundEngine – Donation and Crowdfunding Platform 1K+ installs · 4.1★ · 5 shared tags B -
Mission – Donation Plugin for WordPress – Fundraising & Recurring Donations 80+ installs · 4.1★ · 5 shared tags B -
Fundrizer Lite – Donation Plugin for Transparent Fundraising 10+ installs · 3.6★ · 4 shared tags B -
Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More 5K+ installs · 4.3★ · 3 shared tags A -
Donation Thermometer 2K+ installs · 4.2★ · 3 shared tags A
Embed this report card
Drop a live Pulse card for GiveWP – Donation Plugin and Fundraising Platform into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/give" width="480" height="300" style="border:0" loading="lazy" title="GiveWP – Donation Plugin and Fundraising Platform — Plugin Pulse"></iframe> GiveWP – Donation Plugin and Fundraising Platform: 100K+ active installs, 4.6★ (705 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/give