Easy Digital Downloads – Pantheon Compat Security & Risk Analysis

wordpress.org/plugins/easy-digital-downloads-pantheon-compat

Compatibility plugin for Easy Digital Downloads on Pantheon

10 active installs v1.0.1 PHP + WP 3.6+ Updated Feb 3, 2026
compatibilityeasy-digital-downloadseddnginxpantheon
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Digital Downloads – Pantheon Compat Safe to Use in 2026?

Generally Safe

Score 100/100

Easy Digital Downloads – Pantheon Compat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The security posture of the easy-digital-downloads-pantheon-compat plugin v1.0.1 appears strong based on the provided static analysis and vulnerability history. The absence of any identified attack surface points, dangerous functions, unsanitized taint flows, or known CVEs is a significant positive indicator. The use of prepared statements for all SQL queries further demonstrates good security practices regarding database interactions.

However, a critical concern arises from the output escaping. With 3 total outputs and 0% properly escaped, this presents a clear risk. If any of these outputs contain user-supplied or dynamic data, it could lead to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user's browser.

In conclusion, while the plugin excels in areas like SQL security and avoiding known vulnerabilities, the lack of output escaping is a significant weakness that requires immediate attention. Addressing this single issue would substantially improve the plugin's overall security.

Key Concerns

  • Output escaping is not implemented
Vulnerabilities
None known

Easy Digital Downloads – Pantheon Compat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy Digital Downloads – Pantheon Compat Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Easy Digital Downloads – Pantheon Compat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Easy Digital Downloads – Pantheon Compat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initedd-pantheon-compat.php:102
actionadmin_initedd-pantheon-compat.php:104
filterupload_diredd-pantheon-compat.php:121
actionplugins_loadededd-pantheon-compat.php:231
actionadmin_noticesincludes/class.s214-edd-activation.php:64
Maintenance & Trust

Easy Digital Downloads – Pantheon Compat Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 3, 2026
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Easy Digital Downloads – Pantheon Compat Developer Profile

DigitalME

25 plugins · 150K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
689 days
View full developer profile
Detection Fingerprints

How We Detect Easy Digital Downloads – Pantheon Compat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-digital-downloads-pantheon-compat/includes/class.s214-edd-activation.php

HTML / DOM Fingerprints

Shortcode Output
<div class="error"><p>This plugin is intended for use only on EDD sites hosted on Pantheon. Use on other hosts will cause system instability.</p></div>
FAQ

Frequently Asked Questions about Easy Digital Downloads – Pantheon Compat