{eac}SoftwareRegistry Distribution SDK Security & Risk Analysis

wordpress.org/plugins/eacsoftwareregistry-distribution-sdk

{eac}SoftwareRegistry Distribution SDK for the Software Registration Server - Implementing the Software Registry SDK Package.

0 active installs v1.1.3 PHP 7.4+ WP 5.8+ Updated Jul 25, 2025
license-managerregistration-apisoftware-licensesoftware-registrationsoftware-registry
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is {eac}SoftwareRegistry Distribution SDK Safe to Use in 2026?

Generally Safe

Score 100/100

{eac}SoftwareRegistry Distribution SDK has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The plugin "eacsoftwareregistry-distribution-sdk" v1.1.3 exhibits a strong security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are exposed to attackers. The code signals also indicate good security practices, with no dangerous functions, all SQL queries using prepared statements, and all output being properly escaped. File operations are present, but without further context, their security implication is neutral. The absence of external HTTP requests and the lack of recorded vulnerabilities further bolster its security profile.

However, a significant concern is the complete absence of nonce and capability checks. This implies that any functionality accessible through the identified file operations might be exploitable by unauthenticated or unauthorized users if these operations perform sensitive actions. While the static analysis didn't reveal any direct paths for exploitation through taint analysis, the lack of robust access control mechanisms remains a critical weakness. The vulnerability history being clean is a positive sign, suggesting a history of secure development, but it does not mitigate the risks posed by the current lack of authorization checks.

In conclusion, while the plugin demonstrates sound practices in areas like SQL and output handling, the complete omission of nonce and capability checks presents a notable security risk. The plugin's attack surface is technically zero in terms of traditional WordPress entry points, but the potential for privilege escalation or unauthorized actions through the file operations, without any access controls, needs to be addressed. Addressing these missing checks is crucial for a truly secure plugin.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

{eac}SoftwareRegistry Distribution SDK Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

{eac}SoftwareRegistry Distribution SDK Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0
Attack Surface

{eac}SoftwareRegistry Distribution SDK Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtereacSoftwareRegistry_load_extensionseacSoftwareRegistry_Distribution_SDK.php:51
actionoptions_settings_pageExtensions\class.eacSoftwareRegistry_SDK.extension.php:40
filteroptions_form_post__create_distributionExtensions\class.eacSoftwareRegistry_SDK.extension.php:127
Maintenance & Trust

{eac}SoftwareRegistry Distribution SDK Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 25, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

{eac}SoftwareRegistry Distribution SDK Developer Profile

Kevin Burkholder

6 plugins · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect {eac}SoftwareRegistry Distribution SDK

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
dashiconsdashicons-info-outline
Data Attributes
required=requiredpattern='[a-zA-Z0-9_\x7f-\xff]*'
FAQ

Frequently Asked Questions about {eac}SoftwareRegistry Distribution SDK