
Easy Digital Downloads – Checkout Notes Security & Risk Analysis
wordpress.org/plugins/edd-checkout-notesAdd a textarea to the checkout form where customers can leave notes about their order.
Is Easy Digital Downloads – Checkout Notes Safe to Use in 2026?
Generally Safe
Score 85/100Easy Digital Downloads – Checkout Notes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'edd-checkout-notes' v1.0 presents a strong initial security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate good practices in several key areas: no dangerous functions were detected, all SQL queries utilize prepared statements, no file operations or external HTTP requests were found, and there are no recorded vulnerabilities in its history. This suggests a diligent approach to secure coding and maintenance by the developers.
However, a notable concern arises from the output escaping analysis. With 15 total outputs and only 60% properly escaped, a significant portion (40%) of outputs may be vulnerable to Cross-Site Scripting (XSS) attacks. This is a critical area of weakness that could allow attackers to inject malicious scripts into the user interface. Additionally, the complete lack of nonce checks and capability checks, coupled with zero identified flows in taint analysis, could be interpreted in two ways: either the plugin is extremely simple and inherently secure, or these checks are missing due to the lack of complex functionalities that would typically require them. While the absence of vulnerabilities in its history is positive, the potential for XSS due to insufficient output escaping remains a significant risk that warrants immediate attention.
Key Concerns
- Significant portion of outputs not properly escaped
- No nonce checks implemented
- No capability checks implemented
Easy Digital Downloads – Checkout Notes Security Vulnerabilities
Easy Digital Downloads – Checkout Notes Release Timeline
Easy Digital Downloads – Checkout Notes Code Analysis
Output Escaping
Easy Digital Downloads – Checkout Notes Attack Surface
WordPress Hooks 6
Maintenance & Trust
Easy Digital Downloads – Checkout Notes Maintenance & Trust
Maintenance Signals
Community Trust
Easy Digital Downloads – Checkout Notes Alternatives
Custom checkout fields for EDD
edd-custom-checkout-fields
Add custom fields to the edd checkout form
Easy Digital Downloads – Empty Cart
easy-digital-downloads-empty-cart
Easily add content to the empty cart display in Easy Digital Downloads.
Easy Digital Downloads – Continue Shopping
easy-digital-downloads-continue-shopping
Adds a Continue Shopping link to the Easy Digital Downloads checkout cart.
Easy Digital Downloads – Clear Cart
easy-digital-downloads-clear-cart
Adds a Clear Cart link to the Easy Digital Downloads checkout cart.
Cardinity Payment Gateway for Easy Digital Downloads
cardinity-gateway-for-easy-digital-downloads
Add Cardinity checkout form to your Easy Digital Downloads site and start accepting payments.
Easy Digital Downloads – Checkout Notes Developer Profile
3 plugins · 30 total installs
How We Detect Easy Digital Downloads – Checkout Notes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
edd-acnatcf-edd-address-1-wrapname="edd_acn"class="edd-input"<fieldset class="edd-acn"><p id="atcf-edd-address-1-wrap">