Easy Digital Downloads Payment Gateway – CashBill Security & Risk Analysis

wordpress.org/plugins/easy-digital-downloads-payment-gateway-cashbill

CashBill is easy to use electronic payment system. You can integrate our payment package with your website and offer customers secure payments.

10 active installs v1.1.0 PHP + WP 3.0.1+ Updated Mar 18, 2021
easy-digital-downloadeasy-digital-downloadsgatewaypaymentshopping-cart
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Easy Digital Downloads Payment Gateway – CashBill Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Digital Downloads Payment Gateway – CashBill has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of easy-digital-downloads-payment-gateway-cashbill v1.1.0 reveals a plugin with an extremely limited attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which are common entry points for attackers. Furthermore, the code signals indicate a strong adherence to secure coding practices, with no dangerous functions, all SQL queries using prepared statements, and all outputs properly escaped. There are also no file operations or bundled libraries to consider for outdated versions.

Despite the robust code hygiene demonstrated by the static analysis, two flows were flagged in the taint analysis as having unsanitized paths. While the severity of these paths was not classified as critical or high, the presence of unsanitized paths is a significant concern as it indicates potential vulnerabilities if user-supplied data is not handled with extreme care before being processed. The absence of any recorded vulnerability history, including CVEs, suggests that the plugin has historically been secure or not a target for public vulnerability discovery. However, the recent taint findings, coupled with a complete lack of capability checks and nonce checks, present a weakness.

In conclusion, the plugin exhibits excellent fundamental security practices in terms of its attack surface and core code hygiene. However, the two unsanitized path flows identified in the taint analysis, combined with the absence of nonce and capability checks on any potential (though currently non-existent) entry points, represent a notable risk. Future development should focus on sanitizing these identified paths and implementing appropriate checks if new entry points are introduced.

Key Concerns

  • Flows with unsanitized paths (2)
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Easy Digital Downloads Payment Gateway – CashBill Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy Digital Downloads Payment Gateway – CashBill Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Easy Digital Downloads Payment Gateway – CashBill Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
cashbill_callback (edd-cashbill-gateway.php:144)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Easy Digital Downloads Payment Gateway – CashBill Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filteredd_payment_gatewaysedd-cashbill-gateway.php:18
actionedd_cashbill_cc_formedd-cashbill-gateway.php:20
actionedd_gateway_cashbilledd-cashbill-gateway.php:91
filteredd_settings_gatewaysedd-cashbill-gateway.php:142
actioninitedd-cashbill-gateway.php:178
actionadmin_menuedd-cashbill-gateway.php:185
Maintenance & Trust

Easy Digital Downloads Payment Gateway – CashBill Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.0
Last updatedMar 18, 2021
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Easy Digital Downloads Payment Gateway – CashBill Developer Profile

CashBill

2 plugins · 910 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Easy Digital Downloads Payment Gateway – CashBill

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-digital-downloads-payment-gateway-cashbill/img/cashbill_100x39.png/wp-content/plugins/easy-digital-downloads-payment-gateway-cashbill/pdf/Instrukcja instalacji.pdf/wp-content/plugins/easy-digital-downloads-payment-gateway-cashbill/img/pdf-icon.png/wp-content/plugins/easy-digital-downloads-payment-gateway-cashbill/img/cashbill_50x50.png

HTML / DOM Fingerprints

REST Endpoints
/ws/rest//testws/rest/
FAQ

Frequently Asked Questions about Easy Digital Downloads Payment Gateway – CashBill