Cryptocurrency Payment Gateway for Easy Digital Downloads (EDD) by CryptoPay Security & Risk Analysis

wordpress.org/plugins/cryptopay-gateway-for-easy-digital-downloads-edd

Cryptocurrency Payment Gateway for Easy Digital Downloads (EDD), Bitcoin payments, Ethereum, Solana, Payments, Crypto payments, USDT, BTC, ETH, SOL

0 active installs v1.0.4 PHP 8.1+ WP 5.0+ Updated May 22, 2025
bitcoincryptoeasy-digital-downloads-eddethereumpayments
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cryptocurrency Payment Gateway for Easy Digital Downloads (EDD) by CryptoPay Safe to Use in 2026?

Generally Safe

Score 100/100

Cryptocurrency Payment Gateway for Easy Digital Downloads (EDD) by CryptoPay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

Based on the provided static analysis, this plugin appears to have a strong security posture. The absence of any identified dangerous functions, direct SQL queries without prepared statements, unescaped output, file operations, or external HTTP requests is highly commendable. Furthermore, the zero-count for critical and high-severity taint flows suggests a well-sanitized codebase. The vulnerability history is also clean, with no recorded CVEs, which indicates a lack of known exploitable flaws. This suggests the developers have followed secure coding practices.

However, the complete lack of AJAX handlers, REST API routes, shortcodes, cron events, and critically, any nonce or capability checks across all these potential entry points is a significant concern. While the static analysis didn't find any direct vulnerabilities, the absence of these fundamental security mechanisms leaves the plugin vulnerable to various attacks, such as Cross-Site Request Forgery (CSRF) if any sensitive actions were to be introduced without proper checks. The zero entry points might indicate a very simple plugin, but it's unusual for a gateway plugin not to have any interaction points.

In conclusion, while the current code is remarkably free of common vulnerabilities detected by static analysis, the lack of essential security controls on any potential (even if currently non-existent) entry points is a notable weakness. The plugin's strength lies in its clean code, but its weakness is the absence of protective measures that would be standard for any WordPress plugin handling user interactions or data.

Key Concerns

  • No nonce checks on AJAX handlers
  • No capability checks on AJAX handlers
  • No permission callbacks on REST API routes
  • No nonce checks on shortcodes
  • No capability checks on shortcodes
  • No nonce checks on cron events
  • No capability checks on cron events
Vulnerabilities
None known

Cryptocurrency Payment Gateway for Easy Digital Downloads (EDD) by CryptoPay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Cryptocurrency Payment Gateway for Easy Digital Downloads (EDD) by CryptoPay Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Cryptocurrency Payment Gateway for Easy Digital Downloads (EDD) by CryptoPay Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filteredd_payment_gatewaysapp\Gateways\AbstractGateway.php:19
actionedd_pre_process_purchaseapp\Gateways\AbstractGateway.php:20
filteredd_accepted_payment_iconsapp\Gateways\AbstractGateway.php:22
actionedd_order_receipt_after_tableapp\Gateways\AbstractGateway.php:23
actioninitapp\Loader.php:27
actionplugins_loadedcryptopay-gateway-for-edd.php:43
Maintenance & Trust

Cryptocurrency Payment Gateway for Easy Digital Downloads (EDD) by CryptoPay Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 22, 2025
PHP min version8.1
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Cryptocurrency Payment Gateway for Easy Digital Downloads (EDD) by CryptoPay Developer Profile

BeycanPress LLC

16 plugins · 260 total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
85 days
View full developer profile
Detection Fingerprints

How We Detect Cryptocurrency Payment Gateway for Easy Digital Downloads (EDD) by CryptoPay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cryptopay-gateway-for-easy-digital-downloads-edd/src/BeycanPress/CryptoPay/EDD/Assets/CSS/edd-cryptopay.css/wp-content/plugins/cryptopay-gateway-for-easy-digital-downloads-edd/src/BeycanPress/CryptoPay/EDD/Assets/JS/edd-cryptopay.js
Script Paths
/wp-content/plugins/cryptopay-gateway-for-easy-digital-downloads-edd/src/BeycanPress/CryptoPay/EDD/Assets/JS/edd-cryptopay.js
Version Parameters
cryptopay-gateway-for-easy-digital-downloads-edd/src/BeycanPress/CryptoPay/EDD/Assets/CSS/edd-cryptopay.css?ver=cryptopay-gateway-for-easy-digital-downloads-edd/src/BeycanPress/CryptoPay/EDD/Assets/JS/edd-cryptopay.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Cryptocurrency Payment Gateway for Easy Digital Downloads (EDD) by CryptoPay