Customer Details – Easy Digital Downloads Security & Risk Analysis

wordpress.org/plugins/customer-details-easy-digital-downloads

Customer Details - Easy Digital Downloads is a solution to see customer history in detail for selling digital products on WordPress.

0 active installs v1.0 PHP 7.2+ WP 5.2+ Updated Nov 4, 2021
customer-historycustomer-detailseddedd-customer-info
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Customer Details – Easy Digital Downloads Safe to Use in 2026?

Generally Safe

Score 85/100

Customer Details – Easy Digital Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "customer-details-easy-digital-downloads" v1.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly commendable. Furthermore, the near-perfect output escaping and the lack of any reported vulnerabilities in its history suggest a development process that prioritizes security. The limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, further minimizes potential entry points for attackers.

However, a critical area of concern lies in the complete absence of nonce and capability checks. While the current analysis shows no unprotected entry points, this absence represents a significant oversight. Without these checks, even if no immediate vulnerabilities are present, the plugin is susceptible to various attacks if new entry points are added or if existing ones are inadvertently exposed in future updates or through interactions with other plugins. The lack of historical vulnerability data is positive, but it should not be interpreted as a guarantee of future safety, especially given the missing fundamental security mechanisms.

In conclusion, while the plugin demonstrates good practices in areas like SQL sanitization and output escaping, the lack of nonce and capability checks is a substantial weakness that elevates its risk profile. This oversight could lead to privilege escalation or unauthorized actions if exploited, despite the current clean bill of health from static analysis and vulnerability history. Addressing this gap is crucial for a robust security implementation.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Customer Details – Easy Digital Downloads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Customer Details – Easy Digital Downloads Release Timeline

v1.0Current
Code Analysis
Analyzed Apr 16, 2026

Customer Details – Easy Digital Downloads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped23 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
search_box (includes/customer-list.php:82)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Customer Details – Easy Digital Downloads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedcustom-details.php:34
actionplugins_loadedcustom-details.php:35
actionadmin_enqueue_scriptsincludes/assets.php:23
actionadmin_enqueue_scriptsincludes/assets.php:24
actionadmin_menuincludes/menu.php:22
Maintenance & Trust

Customer Details – Easy Digital Downloads Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedNov 4, 2021
PHP min version7.2
Downloads873

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Customer Details – Easy Digital Downloads Developer Profile

Nazmul Hasan

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Customer Details – Easy Digital Downloads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/customer-details-easy-digital-downloads/assets/css/main.css/wp-content/plugins/customer-details-easy-digital-downloads/assets/js/main.js
Script Paths
customer-details-stylecustomer-details-script
Version Parameters
customer-details-easy-digital-downloads/assets/css/main.css?ver=customer-details-easy-digital-downloads/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
payment-idpurchased-itemcountrystate
FAQ

Frequently Asked Questions about Customer Details – Easy Digital Downloads