
Easy Digital Downloads payment plugin – Novalnet AG Security & Risk Analysis
wordpress.org/plugins/easy-digital-downloads-payment-gateway-by-novalnetNovalnet payment plugin provides all popular online payment methods for your Easy Digital Downloads webshop.
Is Easy Digital Downloads payment plugin – Novalnet AG Safe to Use in 2026?
Generally Safe
Score 100/100Easy Digital Downloads payment plugin – Novalnet AG has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "easy-digital-downloads-payment-gateway-by-novalnet" plugin v2.4.0 exhibits a mixed security posture, with some strong points but also significant areas of concern. On the positive side, the plugin demonstrates good practices in SQL query preparation and output escaping, with a very high percentage of queries using prepared statements and almost all outputs being properly escaped. The absence of known vulnerabilities in its history is also a positive indicator of past development focus on security.
However, the static analysis reveals critical weaknesses. The presence of a single unprotected AJAX handler represents a significant attack surface that could be exploited without proper authentication. Furthermore, the taint analysis indicates four high-severity flows with unsanitized paths, suggesting potential vulnerabilities where user-controlled data could be manipulated or lead to unintended code execution. The use of the `unserialize` function, while not explicitly flagged as a vulnerability in the taint analysis, is a known risky function that often requires careful sanitization of its input, especially when dealing with data from external sources. The complete lack of nonce checks on the identified AJAX entry point is a direct contributing factor to its insecurity.
Key Concerns
- Unprotected AJAX handler
- High severity unsanitized taint flows
- Dangerous function: unserialize used
- Missing nonce checks on AJAX
Easy Digital Downloads payment plugin – Novalnet AG Security Vulnerabilities
Easy Digital Downloads payment plugin – Novalnet AG Release Timeline
Easy Digital Downloads payment plugin – Novalnet AG Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Easy Digital Downloads payment plugin – Novalnet AG Attack Surface
AJAX Handlers 1
WordPress Hooks 106
Maintenance & Trust
Easy Digital Downloads payment plugin – Novalnet AG Maintenance & Trust
Maintenance Signals
Community Trust
Easy Digital Downloads payment plugin – Novalnet AG Alternatives
Novalnet Payment Gateway for WooCommerce
woocommerce-novalnet-gateway
Novalnet payment plugin provides all popular online payment methods for your WooCommerce webshop.
Gravity Forms payment plugin – Novalnet AG
novalnet-payment-add-on-for-gravity-forms
Novalnet payment addon provides all popular online payment methods for your Gravity Forms webshop.
MemberPress payment addon – Novalnet AG
novalnet-payment-addon-memberpress
Novalnet payment addon provides all popular online payment methods for your MemberPress webshop.
Payment Plugins for PayPal WooCommerce
pymntpl-paypal-woocommerce
Developed exclusively between Payment Plugins and PayPal, PayPal for WooCommerce integrates with PayPal's newest API's.
Payment Gateway for PayPal on WooCommerce
woo-paypal-gateway
PayPal, Credit/Debit Cards, Google Pay, Apple Pay, Pay Later, Venmo, SEPA, iDEAL, Mercado Pago, Bancontact & more - by an official PayPal Partner
Easy Digital Downloads payment plugin – Novalnet AG Developer Profile
4 plugins · 1K total installs
How We Detect Easy Digital Downloads payment plugin – Novalnet AG
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-digital-downloads-payment-gateway-by-novalnet/assets/js/novalnet-admin.min.js/wp-content/plugins/easy-digital-downloads-payment-gateway-by-novalnet/assets/css/novalnet-admin.css/wp-content/plugins/easy-digital-downloads-payment-gateway-by-novalnet/assets/js/novalnet-admin.min.js/wp-content/plugins/easy-digital-downloads-payment-gateway-by-novalnet/assets/js/novalnet-admin.min.js?ver=/wp-content/plugins/easy-digital-downloads-payment-gateway-by-novalnet/assets/css/novalnet-admin.css?ver=HTML / DOM Fingerprints
novalnet-admin-wrappernovalnet-global-settingsnovalnet-global-gatewaynovalnet-payment-fields<!-- Novalnet Global Configurations --><!-- Global configuration settings --><!-- Adding admin script --><!-- Enqueue script -->data-novalnet-account-numberdata-novalnet-mandate-referencedata-novalnet-api-keydata-novalnet-payment-methodnovalnet_admin_paramsNovalnetAdmin/wp-json/novalnet/v1/get_apiconfig