
Easy Digital Downloads – Blocks Security & Risk Analysis
wordpress.org/plugins/edd-blocksEDD Blocks adds a "Downloads" block to the new WordPress editor, also known as Gutenberg.
Is Easy Digital Downloads – Blocks Safe to Use in 2026?
Generally Safe
Score 85/100Easy Digital Downloads – Blocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "edd-blocks" v1.0.1 exhibits a generally strong security posture based on the provided static analysis. There are no detected dangerous functions, SQL queries use prepared statements exclusively, and the taint analysis shows no concerning unsanitized flows. The absence of file operations and external HTTP requests further contributes to a reduced attack surface. The high percentage of properly escaped output is also a positive indicator. However, the lack of nonce checks and capability checks on its entry points, which include two shortcodes, presents a notable area of concern. While the attack surface is small and there are no unauthenticated AJAX handlers or REST API routes, these checks are fundamental for preventing various forms of attacks, such as Cross-Site Request Forgery (CSRF) and privilege escalation, especially if the shortcodes handle any user-supplied data or interact with sensitive functionalities. The vulnerability history being clear of any known CVEs is a positive sign, suggesting a well-maintained codebase in the past. Nevertheless, the absence of these critical security checks on shortcodes creates a potential weakness that could be exploited in conjunction with other vulnerabilities or specific user contexts. Therefore, while the plugin has many strengths, the missing authentication and authorization checks on its entry points require attention.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Output escaping not fully implemented (25% unescaped)
Easy Digital Downloads – Blocks Security Vulnerabilities
Easy Digital Downloads – Blocks Code Analysis
Output Escaping
Data Flow Analysis
Easy Digital Downloads – Blocks Attack Surface
Shortcodes 2
WordPress Hooks 33
Maintenance & Trust
Easy Digital Downloads – Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Easy Digital Downloads – Blocks Alternatives
EDD Auto Register
edd-auto-register
Automatically creates a WP user account at checkout, based on customer's email address.
Easy Digital Downloads Featured Downloads
edd-featured-downloads
Easily feature your downloads
EDD Downloads As Services
edd-downloads-as-services
Mark Downloads As Services in Easy Digital Downloads
Easy Digital Downloads – Coming Soon
edd-coming-soon
Allows Coming Soon or Custom Status text instead of normal pricing for downloads in Easy Digital Downloads.
EDD Download Images
edd-download-images
Easily add extra download images and display them.
Easy Digital Downloads – Blocks Developer Profile
17 plugins · 3K total installs
How We Detect Easy Digital Downloads – Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/edd-blocks/dist/styles.css/wp-content/plugins/edd-blocks/dist/editor.css/wp-content/plugins/edd-blocks/dist/blocks.style.build.css/wp-content/plugins/edd-blocks/dist/blocks.editor.build.css/wp-content/plugins/edd-blocks/src/frontend.js/wp-content/plugins/edd-blocks/src/editor.js/wp-content/plugins/edd-blocks/dist/frontend.js/wp-content/plugins/edd-blocks/dist/editor.js/wp-content/plugins/edd-blocks/dist/blocks.editor.build.jsedd-blocks/dist/styles.css?ver=edd-blocks/dist/editor.css?ver=edd-blocks/dist/blocks.style.build.css?ver=edd-blocks/dist/blocks.editor.build.css?ver=edd-blocks/src/frontend.js?ver=edd-blocks/src/editor.js?ver=edd-blocks/dist/frontend.js?ver=edd-blocks/dist/editor.js?ver=edd-blocks/dist/blocks.editor.build.js?ver=HTML / DOM Fingerprints
wp-block-edd-blocks-downloadswp-block-edd-blocks-download-categorieswp-block-edd-blocks-download-tagsdata-block="edd-blocks/downloads"data-block="edd-blocks/download-categories"data-block="edd-blocks/download-tags"wp.blocks.registerBlockTypeedd_blocks_editor_settingswp.element.createElementwp.components.registerBlockType/wp-json/wp/v2/download_category/wp-json/wp/v2/download_tag