AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Security & Risk Analysis

wordpress.org/plugins/aurpay-crypto-payment-for-easy-digital-downloads

Accept ETH, USDC, USDT, DAI, BTC & Lightning in EDD. Non-custodial, low fees, no card chargebacks.

10 active installs v1.2.6 PHP 7.2+ WP 5.8+ Updated Oct 17, 2025
bitcoin-lighting-networkcrypto-paymentecommerceeddethereum
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The 'aurpay-crypto-payment-for-easy-digital-downloads' plugin, version 1.2.6, exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of identified dangerous functions, SQL queries not using prepared statements, and a lack of unsanitized taint flows are all positive indicators. The plugin also demonstrates good practices in output escaping, with a high percentage of outputs being properly escaped, and the presence of nonce checks is a welcome sign of basic security awareness.

However, there are areas for improvement that prevent a perfect score. The complete lack of capability checks on any entry points (AJAX, REST API, shortcodes, cron) is a significant concern. While the static analysis reports zero unprotected entry points, this is likely due to the absence of these specific entry points rather than explicit authorization. If these features were to be added or expanded, the lack of built-in capability checks would expose them to potential privilege escalation or unauthorized access.

Furthermore, the plugin makes two external HTTP requests, which, while not inherently a vulnerability, warrants careful review to ensure these requests are secure and do not expose sensitive data or introduce supply chain risks. The vulnerability history being completely clean is an excellent sign, suggesting a well-maintained and secure plugin. Overall, the plugin is well-coded with good basic security measures, but the absence of capability checks on potential entry points is a notable weakness that needs to be addressed proactively.

Key Concerns

  • No capability checks on entry points
  • External HTTP requests present
  • Minor output escaping gaps (15% unescaped)
Vulnerabilities
None known

AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
29 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

85% escaped34 total outputs
Attack Surface

AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
filteredd_payment_gatewaysaurpay-edd.php:35
filteredd_settings_sections_gatewaysaurpay-edd.php:43
filteredd_settings_gatewaysaurpay-edd.php:108
actionadmin_noticesaurpay-edd.php:151
actionadmin_noticesaurpay-edd.php:152
actionedd_order_receipt_before_tableaurpay-edd.php:341
actionparse_requestaurpay-edd.php:356
actioninitaurpay-edd.php:366
filteredd_accepted_payment_iconsaurpay-edd.php:375
actionadmin_noticesaurpay-edd.php:449
actionplugins_loadedaurpay-edd.php:453
filterplugin_action_linksaurpay-edd.php:472
filterplugin_row_metaaurpay-edd.php:494
Maintenance & Trust

AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 17, 2025
PHP min version7.2
Downloads7K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Developer Profile

aurtech01

2 plugins · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aurpay-crypto-payment-for-easy-digital-downloads/assets/images/ap-logo.png

HTML / DOM Fingerprints

Data Attributes
id="aurpay"
FAQ

Frequently Asked Questions about AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway