Easy Digital Downloads – Lock Downloads to IP Security & Risk Analysis

wordpress.org/plugins/easy-digital-downloads-lock-downloads-to-ip

Lock file download access to the original purchase IP for Easy Digital Downloads

20 active installs v1.0.1 PHP + WP 3.3+ Updated Mar 18, 2021
downloadseasy-digital-downloadseddfile-downloadip-address
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Digital Downloads – Lock Downloads to IP Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Digital Downloads – Lock Downloads to IP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of the 'easy-digital-downloads-lock-downloads-to-ip' plugin v1.0.1 reveals a strong adherence to secure coding practices. There are no identified dangerous functions, all SQL queries are prepared, and all output is properly escaped. Furthermore, the plugin has no recorded vulnerabilities, including no known CVEs or past security incidents. This indicates a very low risk profile based on the provided data.

However, the complete absence of any identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual. While this contributes to a reduced attack surface, it could also suggest that the plugin might not have any active functionality that requires user interaction or scheduled tasks, or that the analysis might have missed these entry points if they are implemented in a non-standard way. The lack of nonce and capability checks is concerning, as even with a minimal attack surface, any future expansion or indirect interaction could expose vulnerabilities.

In conclusion, the plugin exhibits excellent security hygiene in its current state, with no exploitable flaws detected in the static analysis or historical data. The primary area of minor concern is the lack of explicit security checks like nonces and capability checks, which, while not presenting an immediate risk due to the absence of an attack surface, represents a missed opportunity for defense-in-depth. This plugin is currently assessed as having a very high security posture.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Easy Digital Downloads – Lock Downloads to IP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Easy Digital Downloads – Lock Downloads to IP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Easy Digital Downloads – Lock Downloads to IP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitedd-lock-downloads-to-ip.php:18
actionedd_process_verified_downloadedd-lock-downloads-to-ip.php:21
Maintenance & Trust

Easy Digital Downloads – Lock Downloads to IP Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 18, 2021
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Easy Digital Downloads – Lock Downloads to IP Developer Profile

Syed Balkhi

94 plugins · 23.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
795 days
View full developer profile
Detection Fingerprints

How We Detect Easy Digital Downloads – Lock Downloads to IP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Easy Digital Downloads – Lock Downloads to IP