
Zedna eBook download Security & Risk Analysis
wordpress.org/plugins/ebook-downloadAllow user to download your ebook custom file when insert an email.
Is Zedna eBook download Safe to Use in 2026?
Mostly Safe
Score 84/100Zedna eBook download is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The ebook-download plugin version 1.5 exhibits a mixed security posture. While the static analysis shows a commendable lack of direct attack surface entry points like AJAX handlers, REST API routes, and shortcodes, indicating good design in preventing common web attacks, there are significant underlying concerns. The taint analysis reveals flows with unsanitized paths, including one of high severity. This suggests a potential for directory traversal or similar path manipulation vulnerabilities, even if not directly exposed through typical entry points. The plugin's vulnerability history, with one known high-severity CVE for 'Improper Limitation of a Pathname to a Restricted Directory' from 2016, strongly corroborates these taint analysis findings. Although the CVE is currently patched, the pattern of path-related vulnerabilities is a red flag. Furthermore, the moderate percentage of SQL queries not using prepared statements and a significant portion of output not being properly escaped present further risks of SQL injection and Cross-Site Scripting (XSS) respectively. The presence of nonce checks is positive, but the complete absence of capability checks on potential entry points is a weakness. In conclusion, while the plugin has mitigated some common attack vectors, the lingering risks from unsanitized paths and less-than-ideal handling of SQL and output present notable security weaknesses that warrant careful consideration.
Key Concerns
- High severity taint flow with unsanitized paths
- Moderate percentage of SQL queries not prepared
- Significant percentage of outputs not escaped
- Path Traversal vulnerability history
- No capability checks found
Zedna eBook download Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Zedna eBook download < 1.2 - Directory Traversal
Zedna eBook download Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Zedna eBook download Attack Surface
WordPress Hooks 14
Maintenance & Trust
Zedna eBook download Maintenance & Trust
Maintenance Signals
Community Trust
Zedna eBook download Alternatives
Download Manager
download-manager
This File Management & Digital Store plugin will help you to control file downloads & sell digital products from your WP site.
File Manager Pro – Filester
filester
Advanced File Manager and Code Editor. Best WordPress file manager without FTP access. No need to upgrade because this is PRO version.
Download Monitor
download-monitor
Powerful Download Manager Plugin for WordPress
Download Attachments
download-attachments
Download Attachments is a new approach to managing downloads in WordPress. It allows you to easily add and display download links in any post or page.
Download Manager Addons for Elementor
wpdm-elementor
Download Manager Addons for Elementor
Zedna eBook download Developer Profile
15 plugins · 570 total installs
How We Detect Zedna eBook download
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ebook-download/style.cssHTML / DOM Fingerprints
<!-- Load language file --><!-- # Load language file --><!-- PART 1. Defining Custom Database Table --><!-- ============================================================================ -->+34 more