DC EDD bKash Payment Security & Risk Analysis

wordpress.org/plugins/dc-edd-bkash-payment

bKash payment gateway for Easy Digital Downloads.

10 active installs v1.0.1 PHP 5.6+ WP 4.0+ Updated Jun 27, 2020
bangladeshbd-payment-gatewaybdtbkashedd
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DC EDD bKash Payment Safe to Use in 2026?

Generally Safe

Score 85/100

DC EDD bKash Payment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "dc-edd-bkash-payment" plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of direct SQL injection risks due to a high percentage of prepared statements and the robust output escaping (94%) are positive indicators. Furthermore, the lack of file operations, external HTTP requests, and critical or high-severity taint flows suggest careful coding practices. The plugin also demonstrates awareness of security best practices by including a sufficient number of nonce checks.

However, a notable concern is the complete absence of capability checks for its two AJAX entry points. While the static analysis reports no unprotected AJAX handlers, this likely refers to the presence of nonces. Without proper capability checks, an attacker might be able to trigger these AJAX actions if they can bypass or spoof the nonce, especially if the actions themselves perform sensitive operations. The vulnerability history being entirely clear is a positive sign, indicating a history of secure development or a lack of past exploitation. The plugin's strengths lie in its sanitization and input handling, but the lack of explicit authorization checks on its AJAX endpoints is a weakness that needs addressing.

Key Concerns

  • Missing capability checks on AJAX handlers
Vulnerabilities
None known

DC EDD bKash Payment Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

DC EDD bKash Payment Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
4 prepared
Unescaped Output
1
17 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

67% prepared6 total queries

Output Escaping

94% escaped18 total outputs
Attack Surface

DC EDD bKash Payment Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_dc-edd-bkash-create-payment-requestincludes\Frontend\Ajax.php:18
authwp_ajax_dc-edd-bkash-execute-payment-requestincludes\Frontend\Ajax.php:19
WordPress Hooks 14
actionplugins_loadeddc-edd-bkash-payment.php:85
actioninitdc-edd-bkash-payment.php:203
actioninitdc-edd-bkash-payment.php:206
actionedd_dc_bkash_cc_formdc-edd-bkash-payment.php:209
filteredd_payment_gatewaysdc-edd-bkash-payment.php:218
actionadmin_menuincludes\Admin\Menu.php:16
actionadmin_enqueue_scriptsincludes\Admin\Menu.php:39
actionrest_api_initincludes\Api.php:14
actionadmin_enqueue_scriptsincludes\Assets.php:14
actionwp_enqueue_scriptsincludes\Assets.php:16
filteredd_settings_sections_gatewaysincludes\EasyDigitalDownloads\Bkash_Gateway.php:23
filteredd_settings_gatewaysincludes\EasyDigitalDownloads\Bkash_Gateway.php:24
actionedd_gateway_dc_bkashincludes\EasyDigitalDownloads\Bkash_Gateway.php:26
actionwp_enqueue_scriptsincludes\EasyDigitalDownloads\Bkash_Gateway.php:27
Maintenance & Trust

DC EDD bKash Payment Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 27, 2020
PHP min version5.6
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

DC EDD bKash Payment Developer Profile

Kapil Paul

4 plugins · 1K total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DC EDD bKash Payment

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dc-edd-bkash-payment/assets/css/admin.css/wp-content/plugins/dc-edd-bkash-payment/assets/js/admin.js
Script Paths
/wp-content/plugins/dc-edd-bkash-payment/assets/js/admin.js
Version Parameters
dc-edd-bkash-payment/assets/css/admin.css?ver=dc-edd-bkash-payment/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
dc-edd-bkash-admin-wrap
HTML Comments
Copyright (c) 2020 Kapil Paul (email: kapilpaul007@gmail.com). All rights reserved.Released under the GPL licenseThis is an add-on for WordPress**********************************************************************+45 more
Data Attributes
data-bkash-payment-id
JS Globals
window.dc_edd_bkash_params
FAQ

Frequently Asked Questions about DC EDD bKash Payment