
Easy Digital Downloads Affiliate Banners Security & Risk Analysis
wordpress.org/plugins/easy-digital-download-affiliate-bannersTested up to 3.4 Stable Tag: 1.0 With this plugin you'll be able to easily display nice Easy Digital Downloads banners using the affiliate syste …
Is Easy Digital Downloads Affiliate Banners Safe to Use in 2026?
Generally Safe
Score 85/100Easy Digital Downloads Affiliate Banners has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "easy-digital-download-affiliate-banners" plugin v1.0 exhibits a mixed security posture. On the positive side, the absence of known CVEs and the complete use of prepared statements for SQL queries are strong indicators of good development practices regarding data sanitization and historical security awareness. The plugin also has a seemingly zero attack surface from a technical standpoint based on the provided data, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. However, the static analysis reveals significant concerns, most notably the presence of the `create_function` dangerous function. Furthermore, a concerningly low percentage (17%) of output escaping suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The lack of any recorded vulnerability history, while seemingly positive, could also indicate that the plugin has not undergone extensive security scrutiny or that its limited functionality might have escaped detection of past flaws.
The primary risks stem from the unescaped output and the `create_function` usage. The low rate of output escaping directly translates to a high probability of stored or reflected XSS, allowing attackers to inject malicious scripts into the WordPress environment. The `create_function` function is deprecated and inherently risky due to its ability to execute arbitrary code, and its presence without clear sanitization context is a red flag. Coupled with the lack of any capability checks or nonce checks on the identified entry points (though there are none listed, the absence of checks on potentially implicit entry points is a concern), the plugin is susceptible to privilege escalation or unauthorized actions if any hidden entry points exist or if the `create_function` is used in a vulnerable manner. The zero taint flows are positive, but this is likely due to the limited scope of analysis or the plugin's architecture, and doesn't mitigate the direct risks identified.
Key Concerns
- Dangerous function detected (create_function)
- Low output escaping (17%)
- No capability checks found
- No nonce checks found
Easy Digital Downloads Affiliate Banners Security Vulnerabilities
Easy Digital Downloads Affiliate Banners Release Timeline
Easy Digital Downloads Affiliate Banners Code Analysis
Dangerous Functions Found
Output Escaping
Easy Digital Downloads Affiliate Banners Attack Surface
WordPress Hooks 2
Maintenance & Trust
Easy Digital Downloads Affiliate Banners Maintenance & Trust
Maintenance Signals
Community Trust
Easy Digital Downloads Affiliate Banners Alternatives
Easy Digital Downloads – Terms Per Product
edd-terms-per-product
Allow terms of use to be specified on a per-product basis
Easy Digital Downloads – Keep AddToCart
easy-digital-downloads-keep-add-to-cart
Keep the "Add To Cart" ajax button on the screen instead of switching to a "Checkout" button. This way, multiples can be added to …
Easy Digital Downloads – Location Export
easy-digital-downloads-location-export
Export payment history by location and date. Useful for tax logs.
Bulk Edit Posts and Products in Spreadsheet
wp-sheet-editor-bulk-spreadsheet-editor-for-posts-and-pages
Modern Bulk Editor for Posts and Pages, create and edit hundreds of posts at once in a spreadsheet inside wp-admin. Search and quick edits.
AffiliateWP – Affiliate Product Rates
affiliatewp-affiliate-product-rates
Allows you to set product referral rates on a per-affiliate level in AffiliateWP.
Easy Digital Downloads Affiliate Banners Developer Profile
11 plugins · 790 total installs
How We Detect Easy Digital Downloads Affiliate Banners
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-digital-download-affiliate-banners/assets/css/style.css/wp-content/plugins/easy-digital-download-affiliate-banners/assets/js/main.js/wp-content/plugins/easy-digital-download-affiliate-banners/assets/js/main.jseasy-digital-download-affiliate-banners/assets/css/style.css?ver=easy-digital-download-affiliate-banners/assets/js/main.js?ver=HTML / DOM Fingerprints
eddab-widget