
AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Security & Risk Analysis
wordpress.org/plugins/aurpay-crypto-payment-for-easy-digital-downloadsAccept ETH, USDC, USDT, DAI, BTC & Lightning in EDD. Non-custodial, low fees, no card chargebacks.
Is AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Safe to Use in 2026?
Generally Safe
Score 100/100AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'aurpay-crypto-payment-for-easy-digital-downloads' plugin, version 1.2.6, exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of identified dangerous functions, SQL queries not using prepared statements, and a lack of unsanitized taint flows are all positive indicators. The plugin also demonstrates good practices in output escaping, with a high percentage of outputs being properly escaped, and the presence of nonce checks is a welcome sign of basic security awareness.
However, there are areas for improvement that prevent a perfect score. The complete lack of capability checks on any entry points (AJAX, REST API, shortcodes, cron) is a significant concern. While the static analysis reports zero unprotected entry points, this is likely due to the absence of these specific entry points rather than explicit authorization. If these features were to be added or expanded, the lack of built-in capability checks would expose them to potential privilege escalation or unauthorized access.
Furthermore, the plugin makes two external HTTP requests, which, while not inherently a vulnerability, warrants careful review to ensure these requests are secure and do not expose sensitive data or introduce supply chain risks. The vulnerability history being completely clean is an excellent sign, suggesting a well-maintained and secure plugin. Overall, the plugin is well-coded with good basic security measures, but the absence of capability checks on potential entry points is a notable weakness that needs to be addressed proactively.
Key Concerns
- No capability checks on entry points
- External HTTP requests present
- Minor output escaping gaps (15% unescaped)
AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Security Vulnerabilities
AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Code Analysis
Output Escaping
AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Attack Surface
WordPress Hooks 13
Maintenance & Trust
AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Alternatives
Cryptocurrency Payment Gateway
cryptocurrency-payment-gateway
Digital Currency Payment Gateway for WooCommerce. Easily accept Bitcoin, Bitcoin Cash, Litecoin, Dogecoin, and more in your store.
Easy Digital Downloads – Empty Cart
easy-digital-downloads-empty-cart
Easily add content to the empty cart display in Easy Digital Downloads.
Easy Digital Downloads – Continue Shopping
easy-digital-downloads-continue-shopping
Adds a Continue Shopping link to the Easy Digital Downloads checkout cart.
ATLOS Crypto Payments for WooCommerce
atlos-payments
ATLOS is a permissionless non-custodial crypto payment gateway with recurring billing support. One-click signup. No KYC. No paperwork. No middleman.
Paymento – Non-Custodial Crypto Payment Gateway for WooCommerce
paymento-crypto-gateway
Accept Bitcoin, Ethereum, and USDT in WooCommerce with Paymento – a secure, non-custodial crypto payment gateway.
AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway Developer Profile
2 plugins · 50 total installs
How We Detect AURPAY Easy Digital Downloads (EDD) – Bitcoin Crypto Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aurpay-crypto-payment-for-easy-digital-downloads/assets/images/ap-logo.pngHTML / DOM Fingerprints
id="aurpay"