Easy Digital Downloads Affiliate Banners Security & Risk Analysis

wordpress.org/plugins/easy-digital-download-affiliate-banners

Tested up to 3.4 Stable Tag: 1.0 With this plugin you'll be able to easily display nice Easy Digital Downloads banners using the affiliate syste …

10 active installs v1.0 PHP + WP + Updated Oct 11, 2012
downloaddownloadse-storeeasy-digital-downloadseshop
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Easy Digital Downloads Affiliate Banners Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Digital Downloads Affiliate Banners has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "easy-digital-download-affiliate-banners" plugin v1.0 exhibits a mixed security posture. On the positive side, the absence of known CVEs and the complete use of prepared statements for SQL queries are strong indicators of good development practices regarding data sanitization and historical security awareness. The plugin also has a seemingly zero attack surface from a technical standpoint based on the provided data, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. However, the static analysis reveals significant concerns, most notably the presence of the `create_function` dangerous function. Furthermore, a concerningly low percentage (17%) of output escaping suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The lack of any recorded vulnerability history, while seemingly positive, could also indicate that the plugin has not undergone extensive security scrutiny or that its limited functionality might have escaped detection of past flaws.

The primary risks stem from the unescaped output and the `create_function` usage. The low rate of output escaping directly translates to a high probability of stored or reflected XSS, allowing attackers to inject malicious scripts into the WordPress environment. The `create_function` function is deprecated and inherently risky due to its ability to execute arbitrary code, and its presence without clear sanitization context is a red flag. Coupled with the lack of any capability checks or nonce checks on the identified entry points (though there are none listed, the absence of checks on potentially implicit entry points is a concern), the plugin is susceptible to privilege escalation or unauthorized actions if any hidden entry points exist or if the `create_function` is used in a vulnerable manner. The zero taint flows are positive, but this is likely due to the limited scope of analysis or the plugin's architecture, and doesn't mitigate the direct risks identified.

Key Concerns

  • Dangerous function detected (create_function)
  • Low output escaping (17%)
  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Easy Digital Downloads Affiliate Banners Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy Digital Downloads Affiliate Banners Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Easy Digital Downloads Affiliate Banners Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
20
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'return register_widget("eddab_affiliate_banners");')includes\widgets.php:96

Output Escaping

17% escaped24 total outputs
Attack Surface

Easy Digital Downloads Affiliate Banners Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitedd-affiliate-banners.php:46
actionwidgets_initincludes\widgets.php:96
Maintenance & Trust

Easy Digital Downloads Affiliate Banners Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedOct 11, 2012
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Easy Digital Downloads Affiliate Banners Developer Profile

Remi Corson

11 plugins · 790 total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Digital Downloads Affiliate Banners

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-digital-download-affiliate-banners/assets/css/style.css/wp-content/plugins/easy-digital-download-affiliate-banners/assets/js/main.js
Script Paths
/wp-content/plugins/easy-digital-download-affiliate-banners/assets/js/main.js
Version Parameters
easy-digital-download-affiliate-banners/assets/css/style.css?ver=easy-digital-download-affiliate-banners/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
eddab-widget
FAQ

Frequently Asked Questions about Easy Digital Downloads Affiliate Banners